google / maldocaLinks
Malicious Microsoft Office document analyzer
☆65Updated last year
Alternatives and similar repositories for maldoca
Users that are interested in maldoca are comparing it to the libraries listed below
Sorting:
- Automatically generate AV byte signatures from sets of similar binaries.☆274Updated 6 months ago
- Parsing of YARA rules into AST and building new rulesets in C++.☆124Updated this week
- Library and tools to access the Windows Prefetch File (SCCA) format.☆75Updated 6 months ago
- Cockroach is your primitive & immortal swiss army knife.☆49Updated 3 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆123Updated 4 years ago
- Data to test capa's code and rules.☆42Updated last week
- SentinelOne's KeRnel Exploits Advanced Mitigations☆54Updated 6 years ago
- Symbol hash for ELF files☆111Updated 3 years ago
- capemon: CAPE's monitor☆123Updated this week
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- Utilities for working with vivisect☆25Updated 3 months ago
- This is a simple tool to dump all the reparse points on an NTFS volume.☆33Updated 4 years ago
- Small visualizator for PE files☆69Updated last year
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆31Updated 4 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆73Updated last year
- Yet another rule generator for Yara☆29Updated 3 weeks ago
- Alternative YARA scanning engine☆70Updated 2 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 2 years ago
- FLARE Kernel Shellcode Loader☆178Updated 6 years ago
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- YARI is an interactive debugger for YARA Language.☆88Updated last week
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆58Updated 4 years ago
- Windows Process Lockdown Tool using Job Objects☆69Updated 11 years ago
- Community modules for CAPE Sandbox☆100Updated last week
- Enumerate Windows Defender threat families and dump their names according category☆90Updated 6 years ago
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆63Updated 5 months ago
- Ghidra plugin for https://analyze.intezer.com☆71Updated 2 years ago
- Library and tools to access the Windows Minidump (MDMP) format☆43Updated 11 months ago
- Trigram database written in C++, suited for malware indexing☆125Updated 8 months ago
- ☆62Updated last year