d4rksystem / VMwareCloak
A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.
☆279Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for VMwareCloak
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆278Updated last year
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆139Updated this week
- A GUI and CLI tool for removing bloat from executables☆342Updated last week
- A ProcessMonitor visualization application written in rust.☆176Updated last year
- ☆467Updated 11 months ago
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆161Updated 6 months ago
- Dynamic unpacker based on PE-sieve☆658Updated 8 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆686Updated 8 months ago
- Living Off The Land Drivers☆1,039Updated last month
- Signtool for expired certificates☆455Updated last year
- Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.☆146Updated this week
- Assortment of hashing algorithms used in malware☆334Updated 5 months ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆165Updated 2 months ago
- Research notes☆115Updated last month
- Code snips and notes☆132Updated 2 years ago
- A list of useful tools for Malware Analysis (will be updated regularly)☆128Updated 2 months ago
- Important notes and topics on my journey towards mastering Windows Internals☆341Updated 6 months ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆343Updated 3 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆544Updated 3 weeks ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆724Updated 3 years ago
- The Windows Malware Analysis Reversing Core Tools☆89Updated 3 years ago
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆180Updated 5 months ago
- An automatic unpacker and logger for DotNet Framework targeting files☆249Updated last year
- ☆111Updated last week
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆621Updated last year
- Patching "signtool.exe" to accept expired certificates for code-signing.☆271Updated 4 months ago
- Analyse your malware to surgically obfuscate it☆419Updated last year
- Repository of Yara Rules☆88Updated last month
- A small x64 library to load dll's into memory.☆424Updated last year
- Performing Indirect Clean Syscalls☆483Updated last year