d4rksystem / VBoxCloakLinks
A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade analysis. Guaranteed to bring down your pafish ratings by at least a few points ;)
☆308Updated 2 months ago
Alternatives and similar repositories for VBoxCloak
Users that are interested in VBoxCloak are comparing it to the libraries listed below
Sorting:
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆385Updated 7 months ago
- A GUI and CLI tool for removing bloat from executables☆421Updated 2 months ago
- A ProcessMonitor visualization application written in rust.☆184Updated 2 years ago
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆195Updated last week
- Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.☆161Updated 2 years ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆173Updated 5 months ago
- Dynamic unpacker based on PE-sieve☆754Updated this week
- Repository of Yara Rules☆118Updated this week
- An automatic unpacker and logger for DotNet Framework targeting files☆256Updated 2 years ago
- ☆507Updated last year
- Somes tools and scripts☆151Updated 3 years ago
- ☆374Updated this week
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆207Updated last year
- ☆204Updated 10 months ago
- The Windows Malware Analysis Reversing Core Tools☆96Updated 4 years ago
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆234Updated last year
- Assortment of hashing algorithms used in malware☆373Updated 2 weeks ago
- Memory acquisition for Linux that makes sense.☆206Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆773Updated last year
- Code snips and notes☆136Updated 3 years ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆181Updated 2 months ago
- $MFT directory tree reconstruction & FILE record info☆311Updated 11 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆248Updated 5 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆674Updated last month
- Dump quarantined files from Windows Defender☆67Updated 3 years ago
- Living Off The Land Drivers☆1,281Updated 2 weeks ago
- Parses $MFT from NTFS file systems☆262Updated 4 months ago
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆433Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆418Updated 2 months ago
- Fileless attack with persistence☆361Updated 2 months ago