Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
☆3,880Jun 6, 2026Updated 2 months ago
Alternatives and similar repositories for pe-sieve
Users that are interested in pe-sieve are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks,…☆2,403Jun 6, 2026Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆837Apr 14, 2026Updated 4 months ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,387Apr 18, 2026Updated 4 months ago
- Converts PE into a shellcode☆2,794Aug 30, 2025Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆845Mar 16, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Pin Tool for tracing API calls etc☆1,696Jun 2, 2026Updated 3 months ago
- Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.☆7,117Jul 1, 2026Updated 2 months ago
- Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode☆2,548Nov 15, 2023Updated 2 years ago
- Windows kernel and user mode emulation.☆2,040Updated this week
- Converts a DLL into EXE☆816Jul 23, 2023Updated 3 years ago
- AV/EDR evasion via direct system calls.☆2,029Jan 1, 2023Updated 3 years ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…