f0wl / MalwareLab_VM-SetupLinks
Setup scripts for my Malware Analysis VMs
☆257Updated 3 years ago
Alternatives and similar repositories for MalwareLab_VM-Setup
Users that are interested in MalwareLab_VM-Setup are comparing it to the libraries listed below
Sorting:
- Code and yara rules to detect and analyze Cobalt Strike☆272Updated 4 years ago
- Beta versions of my software☆268Updated 6 months ago
- Exercise writeups from the book Practical Malware Analysis.☆242Updated 2 years ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆752Updated 4 years ago
- Detect and respond to Cobalt Strike beacons using ETW.☆515Updated 3 years ago
- Scan files or process memory for CobaltStrike beacons and parse their configuration☆920Updated 4 years ago
- ☆305Updated 4 years ago
- ☆212Updated 3 weeks ago
- ☆1,124Updated 2 years ago
- Resources About Windows Security. 1100+ Open Source Tools. 3300+ Blog Post and Videos.☆496Updated 5 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆584Updated last year
- Quickly debug shellcode extracted during malware analysis☆621Updated 2 years ago
- Tool based on CobaltStrikeParser from SentinelOne which can be used to spam a CobaltStrike server with fake beacons☆372Updated 3 months ago
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆436Updated last year
- This repo is a collection of Ransomware reports from vendors, researchers, etc.☆120Updated 3 years ago
- Hunts out CobaltStrike beacons and logs operator command output☆951Updated last year
- ☆453Updated 4 years ago
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆721Updated 3 years ago
- We developed GRAT2 Command & Control (C2) project for learning purpose.☆413Updated 5 years ago
- Pull some Malware samples here for other security researchers/malware analyst's to analyze and play with.☆174Updated last year
- Project for identifying executables and DLLs vulnerable to relative path DLL hijacking.☆480Updated last year
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆257Updated 3 years ago
- Evade sysmon and windows event logging☆627Updated 5 years ago
- Threat Intel IoCs + bits and pieces of dark matter☆425Updated last week
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆340Updated 2 years ago
- ☆33Updated 7 years ago
- Emulate and Dissect MSF and *other* attacks☆142Updated last year
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆183Updated 2 months ago
- Community modules for CAPE Sandbox☆107Updated 2 weeks ago
- PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"☆308Updated 3 years ago