google / maldoca
Malicious Microsoft Office document analyzer
☆65Updated last year
Alternatives and similar repositories for maldoca:
Users that are interested in maldoca are comparing it to the libraries listed below
- Automatically generate AV byte signatures from sets of similar binaries.☆267Updated 3 months ago
- Parsing of YARA rules into AST and building new rulesets in C++.☆123Updated last week
- capemon: CAPE's monitor☆110Updated last week
- Data to test capa's code and rules.☆41Updated 2 weeks ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆120Updated 4 years ago
- Enumerate Windows Defender threat families and dump their names according category☆90Updated 5 years ago
- Cockroach is your primitive & immortal swiss army knife.☆47Updated 3 years ago
- Unprotect is a python tool for parsing PE malware and extract evasion techniques.☆114Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- A small utility to deal with malware embedded hashes.☆49Updated last year
- Set of antianalysis techniques found in malware☆129Updated last year
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆31Updated 4 years ago
- Blocks drivers from loading by using a name collision technique. #nsacyber☆47Updated 7 years ago
- Symbol hash for ELF files☆108Updated 3 years ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- Trigram database written in C++, suited for malware indexing☆124Updated 5 months ago
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated 2 years ago
- Enumerate user mode shared memory mappings on Windows.☆117Updated 4 years ago
- YARI is an interactive debugger for YARA Language.☆88Updated 2 months ago
- ☆43Updated 11 months ago
- A summary about different projects/presentations/tools to test how to evade malware sandbox systems☆50Updated 6 years ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 3 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆156Updated 3 years ago
- ☆61Updated last year
- Scripts to aid analysis of files obfuscated with ScatterBee.☆20Updated 2 years ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆161Updated 3 months ago
- Alternative YARA scanning engine☆70Updated 2 years ago
- Malware Configuration Extraction Modules☆49Updated last year