decalage2 / ViperMonkey
A VBA parser and emulation engine to analyze malicious macros.
☆1,085Updated 9 months ago
Alternatives and similar repositories for ViperMonkey:
Users that are interested in ViperMonkey are comparing it to the libraries listed below
- Noriben - Portable, Simple, Malware Analysis Sandbox☆1,149Updated last year
- PowerShell script for deobfuscating encoded PowerShell scripts☆425Updated 4 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆578Updated 11 months ago
- PowerShell Obfuscation Detection Framework☆733Updated last year
- yarGen is a generator for YARA rules☆1,625Updated last week
- Malware Configuration And Payload Extraction☆754Updated 4 months ago
- Utilities for Sysmon☆1,513Updated last month
- ☆428Updated last year
- Yara Rule Analyzer and Statistics☆374Updated 2 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆917Updated last year
- Indicators from Unit 42 Public Reports☆710Updated 2 weeks ago
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆706Updated 2 years ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆573Updated 3 weeks ago
- Volatility plugin for extracts configuration data of known malware☆486Updated last year
- A VBA p-code disassembler☆466Updated 3 years ago
- A static analyzer for PE executables.☆1,056Updated last year
- Volatility plugins developed and maintained by the community☆359Updated 4 years ago
- YARA Rules I come across on the internet☆337Updated last year
- RDP Bitmap Cache parser☆522Updated 2 months ago
- RegRipper3.0☆595Updated 4 months ago
- YARA malware query accelerator (web frontend)☆426Updated 3 weeks ago
- Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)☆1,603Updated 6 years ago
- Online hash checker for Virustotal and other services☆824Updated 3 weeks ago
- A Powershell incident response framework☆1,594Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆589Updated last month
- ☆1,070Updated 5 years ago
- ☆709Updated 2 years ago
- Please no pull requests for this repository. Thanks!☆2,189Updated this week
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆472Updated 6 months ago
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,119Updated this week