google / maldocaLinks
Malicious Microsoft Office document analyzer
☆66Updated last year
Alternatives and similar repositories for maldoca
Users that are interested in maldoca are comparing it to the libraries listed below
Sorting:
- Parsing of YARA rules into AST and building new rulesets in C++.☆129Updated this week
- Library and tools to access the Windows Prefetch File (SCCA) format.☆81Updated last week
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆32Updated 5 years ago
- Automatically generate AV byte signatures from sets of similar binaries.☆284Updated last year
- Use YARA rules on Time Travel Debugging traces☆96Updated 2 years ago
- Small visualizator for PE files☆70Updated 2 years ago
- Alternative YARA scanning engine☆73Updated 3 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 3 years ago
- Data to test capa's code and rules.☆46Updated last week
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆124Updated 5 years ago
- capemon: CAPE's monitor☆142Updated this week
- Documentation and supporting script sample for Windows Exploit Guard☆161Updated 3 months ago
- Enumerate Windows Defender threat families and dump their names according category☆93Updated 6 years ago
- Library and tools to access the Windows Minidump (MDMP) format☆44Updated last week
- A set of small utilities, helpers for PIN tracers☆35Updated 2 months ago
- ☆63Updated last year
- Windows Event Log Knowledge Base☆28Updated 2 weeks ago
- Rekall Memory Forensic Framework☆33Updated 6 years ago
- Named pipe I/O ETW provider for Windows☆71Updated 5 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago
- Unprotect is a python tool for parsing PE malware and extract evasion techniques.☆119Updated 2 years ago
- Cockroach is your primitive & immortal swiss army knife.☆49Updated 4 years ago
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 2 years ago
- Windows Process Lockdown Tool using Job Objects☆70Updated 12 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆36Updated 4 years ago
- ☆64Updated last year
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆144Updated 5 years ago
- YARA Language Server☆75Updated 3 weeks ago
- Tools for inspecting YARA bytecode☆21Updated 5 years ago