fr0gger / unprotect
Unprotect is a python tool for parsing PE malware and extract evasion techniques.
☆115Updated last year
Alternatives and similar repositories for unprotect:
Users that are interested in unprotect are comparing it to the libraries listed below
- Malware Configuration Extraction Modules☆49Updated last year
- Random hunting ordiented yara rules☆96Updated 2 years ago
- Malware similarity platform with modularity in mind.☆78Updated 3 years ago
- Userland API monitor for threat hunting☆58Updated 5 years ago
- A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck☆128Updated last year
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆44Updated 2 years ago
- YARA rule analyzer to improve rule quality and performance☆99Updated last month
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated 2 years ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆104Updated last month
- Automatic YARA rule generation for Malpedia☆160Updated 2 years ago
- A golang CLI tool to download malware from a variety of sources.☆143Updated last year
- Various capabilities for static malware analysis.☆78Updated 8 months ago
- A guide on how to write fast and memory friendly YARA rules☆142Updated 3 months ago
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆137Updated 2 years ago
- JPCERT/CC public YARA rules repository☆106Updated 5 months ago
- Powershell script deobfuscation using AST in Python☆66Updated last year
- ☆105Updated last year
- VSCode extension for the YARA pattern matching language☆64Updated last year
- Collection of YARA signatures from individual research☆44Updated last year
- Capa analysis importer for Ghidra.☆61Updated 4 years ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated last year
- API Logger for Windows Executables☆78Updated 4 years ago
- ☆27Updated 3 years ago
- Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.☆73Updated 4 years ago
- ☆98Updated 4 years ago
- Unpacking and decryption tools for the Emotet malware☆46Updated 3 years ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Updated 2 years ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆176Updated 3 months ago
- Community modules for CAPE Sandbox☆96Updated 3 weeks ago
- Python based CLI for MalwareBazaar☆37Updated 6 months ago