d4rksystem / VMwareCloak
A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.
☆269Updated 6 months ago
Related projects: ⓘ
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆271Updated last year
- Repository to publish your evasion techniques and contribute to the project☆128Updated 2 weeks ago
- A GUI and CLI tool for removing bloat from executables☆332Updated 3 weeks ago
- Dynamic unpacker based on PE-sieve☆650Updated 6 months ago
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆147Updated 4 months ago
- A ProcessMonitor visualization application written in rust.☆175Updated last year
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆138Updated this week
- ☆458Updated 9 months ago
- Living Off The Land Drivers☆981Updated last week
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆659Updated 6 months ago
- Signtool for expired certificates☆441Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆334Updated this week
- Important notes and topics on my journey towards mastering Windows Internals☆330Updated 4 months ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆163Updated 3 weeks ago
- ☆559Updated 2 months ago
- ☆296Updated this week
- Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.☆606Updated 10 months ago
- Assortment of hashing algorithms used in malware☆323Updated 3 months ago
- Research notes☆108Updated this week
- Code snips and notes☆129Updated 2 years ago
- A small x64 library to load dll's into memory.☆422Updated 10 months ago
- A list of useful tools for Malware Analysis (will be updated regularly)☆122Updated 2 weeks ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆612Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆485Updated this week
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆376Updated 2 months ago
- An automatic unpacker and logger for DotNet Framework targeting files☆248Updated last year
- Patching "signtool.exe" to accept expired certificates for code-signing.☆264Updated 2 months ago
- PoC Implementation of a fully dynamic call stack spoofer☆677Updated 2 months ago
- The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.☆278Updated 8 months ago
- Performing Indirect Clean Syscalls☆451Updated last year