ignacioj / WhacAMole
Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment variables. Dumps, detects and dissasemble hooks, shellcode, memory regions, modules and processes.
☆39Updated 6 months ago
Alternatives and similar repositories for WhacAMole:
Users that are interested in WhacAMole are comparing it to the libraries listed below
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- ☆45Updated last year
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆37Updated 3 years ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- SharpShareFinder is a minimalistic network share discovery POC designed to enumerate shares in Windows Active Directory networks leveragi…☆27Updated 8 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆61Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 8 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- ☆71Updated 7 months ago
- ☆114Updated last year
- Detect WFP filters blocking EDR communications☆85Updated last year
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆90Updated last year
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆60Updated 3 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated 10 months ago
- ☆69Updated last year
- Docker container for running CobaltStrike 4.10☆36Updated 6 months ago
- ☆59Updated last year
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆62Updated 3 months ago
- quASAR: ASAR manipulation made easy☆34Updated 2 years ago
- ☆103Updated 4 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆79Updated 2 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆55Updated 2 years ago
- ☆17Updated 5 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- Find DLLs with RWX section☆78Updated last year
- a tiny program to consume from ETW providers for research☆46Updated 2 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆47Updated 10 months ago