intezer / MemoryPatchDetectorLinks
Detects code differentials between executables in disk and the corresponding processes/modules in memory
☆115Updated 5 years ago
Alternatives and similar repositories for MemoryPatchDetector
Users that are interested in MemoryPatchDetector are comparing it to the libraries listed below
Sorting:
- Small tool for disassembling shellcode (using objdump)☆149Updated 3 years ago
- Simple shellcode decoder using unicorn-engine☆100Updated 10 years ago
- Bit9 + Carbon Black Threat Intelligence☆81Updated 9 years ago
- Malware Analysis Tool using Function Level Fuzzy Hashing☆191Updated 10 years ago
- hackers-grep is a utility to search for strings in PE executables including imports, exports, and debug symbols☆171Updated 7 years ago
- Scalable Binary Data Extraction in Hadoop☆144Updated 11 years ago
- ☆108Updated 8 years ago
- ☆75Updated 9 years ago
- An environment for comprehensive, automated analysis of web-based exploits, based on Cuckoo sandbox.☆124Updated 10 years ago
- Some tutorials and examples for generic unpacking JAVA, .NET and x86/x64 code☆51Updated 9 years ago
- Sublime Malware Research Tool☆66Updated last year
- IDATACO IDA Pro Plugin☆46Updated 9 years ago
- ripPE - section extractor and profiler for PE file analysis☆33Updated 11 years ago
- Basic command line, text-based, shellcode debugger.☆92Updated 8 years ago
- Automatically exported from code.google.com/p/malware-lu☆57Updated 6 years ago
- Membrane: A Posteriori Detection of Malicious Code Loading by Memory Paging Analysis☆41Updated 9 years ago
- A python implementation of a grep friendly ftrace wrapper☆80Updated 6 years ago
- Your bag of handy codes for malware researchers☆120Updated 5 years ago
- A Rekall interactive document for a Memory Analysis workshop/course.☆43Updated 8 years ago
- Rapid deployment of Windows environment (files, registry keys, mutex etc) to facilitate malware analysis☆41Updated 10 years ago
- swffile.py - SWF file parser module in Python☆28Updated 9 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆34Updated last year
- ☆44Updated 8 years ago
- map file generator for intel x86 binary based on flirt signature☆83Updated 9 years ago
- POLAR☆74Updated 6 years ago
- Volatility Plugins☆22Updated 10 years ago
- zer0m0n driver for cuckoo sandbox☆87Updated 9 years ago
- Scripts for dealing with various ek's☆69Updated 9 years ago
- Yara is awesome, but sometimes you need to manipulate the data streams you're scanning in different ways.☆98Updated 11 years ago
- Malware Control Monitor☆88Updated 10 years ago