d4rksystem / VBoxCloak
A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade analysis. Guaranteed to bring down your pafish ratings by at least a few points ;)
☆287Updated last year
Alternatives and similar repositories for VBoxCloak:
Users that are interested in VBoxCloak are comparing it to the libraries listed below
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆341Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆717Updated 2 weeks ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆158Updated last month
- A ProcessMonitor visualization application written in rust.☆177Updated last year
- Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.☆157Updated 2 years ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆171Updated this week
- An automatic unpacker and logger for DotNet Framework targeting files☆252Updated last year
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆214Updated 9 months ago
- Assortment of hashing algorithms used in malware☆351Updated 3 weeks ago
- Living Off The Land Drivers☆1,137Updated 3 weeks ago
- Signtool for expired certificates☆473Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆736Updated last year
- Important notes and topics on my journey towards mastering Windows Internals☆371Updated 10 months ago
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆397Updated 8 months ago
- PoCs and tools for investigation of Windows process execution techniques☆912Updated 2 weeks ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆177Updated 2 months ago
- Research notes☆121Updated 3 months ago
- ☆490Updated last year
- Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.☆637Updated last year
- Some of my publicly available Malware analysis and Reverse engineering.☆803Updated 9 months ago
- The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.☆163Updated 3 weeks ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆633Updated 2 years ago
- Fileless attack with persistence☆348Updated 4 months ago
- Code snips and notes☆135Updated 3 years ago
- ☆570Updated 4 months ago
- Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)☆526Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆609Updated 2 weeks ago
- My notes while studying Windows exploitation☆186Updated last year
- A list of useful tools for Malware Analysis (will be updated regularly)☆140Updated 6 months ago
- Repository of Yara Rules☆103Updated last month