d4rksystem / VMwareCloakLinks
A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.
☆360Updated 5 months ago
Alternatives and similar repositories for VMwareCloak
Users that are interested in VMwareCloak are comparing it to the libraries listed below
Sorting:
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆298Updated 2 years ago
- Living Off The Land Drivers☆1,206Updated last month
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆165Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆736Updated last month
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆755Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆396Updated this week
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆185Updated this week
- A ProcessMonitor visualization application written in rust.☆181Updated last year
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆193Updated last year
- Repository of Yara Rules☆111Updated 2 months ago
- A set of fully-undetectable process injection techniques abusing Windows Thread Pools☆1,127Updated last year
- A GUI and CLI tool for removing bloat from executables☆406Updated 2 months ago
- Signtool for expired certificates☆481Updated 2 years ago
- DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.☆496Updated 2 years ago
- Assortment of hashing algorithms used in malware☆364Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆635Updated this week
- Sleep Obfuscation☆765Updated last year
- Centralized resource for listing and organizing known injection techniques and POCs☆583Updated last month
- ☆494Updated last year
- ☆575Updated 3 weeks ago
- Analyse your malware to surgically obfuscate it☆477Updated 3 weeks ago
- A utility for playing with cryptography, geared towards ransomware analysis.☆297Updated 4 months ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆740Updated 3 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆395Updated last year
- A list of useful tools for Malware Analysis (will be updated regularly)☆142Updated 9 months ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆645Updated 2 years ago
- An automatic unpacker and logger for DotNet Framework targeting files☆253Updated last year
- Patching "signtool.exe" to accept expired certificates for code-signing.☆282Updated 11 months ago
- PoC Implementation of a fully dynamic call stack spoofer☆795Updated 11 months ago
- A collection of various vulnerable (mostly physical memory exposing) drivers.☆393Updated 3 years ago