d4rksystem / VBoxCloakLinks
A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade analysis. Guaranteed to bring down your pafish ratings by at least a few points ;)
☆394Updated 6 months ago
Alternatives and similar repositories for VBoxCloak
Users that are interested in VBoxCloak are comparing it to the libraries listed below
Sorting:
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆424Updated 11 months ago
- A GUI and CLI tool for removing bloat from executables☆438Updated 6 months ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆211Updated this week
- Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.☆165Updated 3 years ago
- Dynamic unpacker based on PE-sieve☆793Updated 4 months ago
- Somes tools and scripts☆154Updated 4 years ago
- A ProcessMonitor visualization application written in rust.☆184Updated 2 years ago
- ☆517Updated 2 years ago
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆251Updated last year
- Repository of Yara Rules☆138Updated this week
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆228Updated last year
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆202Updated 4 months ago
- This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or …☆287Updated last year
- Code snips and notes☆140Updated 3 years ago
- $MFT directory tree reconstruction & FILE record info☆323Updated last year
- Living Off The Land Drivers☆1,365Updated 2 weeks ago
- Parses $MFT from NTFS file systems☆291Updated 8 months ago
- Memory acquisition for Linux that makes sense.☆217Updated 2 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆798Updated last year
- ☆213Updated last month
- Assortment of hashing algorithms used in malware☆387Updated last week
- The multi-platform memory acquisition tool.☆930Updated 3 months ago
- An automatic unpacker and logger for DotNet Framework targeting files☆267Updated 2 years ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆692Updated 2 months ago
- A list of useful tools for Malware Analysis (will be updated regularly)☆157Updated 5 months ago
- baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability☆345Updated 2 years ago
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆450Updated last year
- ☆380Updated this week
- Encyclopedia for Executables☆465Updated 4 years ago
- Lnk Explorer Command line edition!!☆334Updated last year