hfiref0x / MpEnum
Enumerate Windows Defender threat families and dump their names according category
☆88Updated 5 years ago
Alternatives and similar repositories for MpEnum:
Users that are interested in MpEnum are comparing it to the libraries listed below
- Windows Drivers☆97Updated 5 years ago
- a program to detect reflective dll injection on a live machine☆74Updated 9 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆74Updated 10 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 3 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆56Updated 6 years ago
- Process Doppelgänging☆155Updated 7 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆93Updated 3 years ago
- ☆112Updated 8 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆119Updated 4 years ago
- CAPE monitor DLLs☆39Updated 5 years ago
- Driver Initial Reconnaissance Tool☆121Updated 5 years ago
- Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process.☆155Updated 5 years ago
- Simple 32/64-bit PEs loader.☆136Updated 6 years ago
- Sysmon shenanigans☆66Updated 4 years ago
- DLL Injection Library & Tools☆71Updated 8 years ago
- Evil Reflective DLL Injection Finder☆45Updated 6 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆76Updated 9 years ago
- Tool to view and create Microsoft shim database files (SDB).☆112Updated 7 years ago
- A simple API monitor for Windbg☆62Updated 7 years ago
- Named pipe I/O ETW provider for Windows☆69Updated 4 years ago
- Fileless persistence, attacks and anti-forensic capabilties.☆88Updated 6 years ago
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆53Updated 5 years ago
- Telsy CTI Research Team☆57Updated 4 years ago