kevoreilly / capemon
capemon: CAPE's monitor
☆110Updated last week
Alternatives and similar repositories for capemon:
Users that are interested in capemon are comparing it to the libraries listed below
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆69Updated 10 months ago
- Parse .NET executable files.☆76Updated last month
- ☆104Updated last year
- Use YARA rules on Time Travel Debugging traces☆89Updated last year
- Small tool to convert beteween the PE alignments (raw and virtual).☆85Updated 2 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆60Updated this week
- Simple windows API logger☆100Updated 5 years ago
- IDA python plugin to scan binary with Yara rules☆173Updated last year
- Powershell script deobfuscation using AST in Python☆65Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- Hyper-V Research is trendy now☆177Updated 10 months ago
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆247Updated last year
- Robust Automated Malware Unpacker☆84Updated last year
- Parsing of YARA rules into AST and building new rulesets in C++.☆122Updated last month
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆122Updated 3 years ago
- Generating YARA rules based on binary code☆205Updated 3 years ago
- Automatic YARA rule generation for Malpedia☆158Updated 2 years ago
- MalUnpack companion driver☆92Updated 8 months ago
- Set of antianalysis techniques found in malware☆129Updated last year
- Parsers for custom malware formats ("Funky malware formats")☆93Updated 3 years ago
- Community modules for CAPE Sandbox☆91Updated this week
- List of tools to assist in analyzing samples of ISFB/Gozi/Ursnif☆15Updated 5 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆202Updated 2 years ago
- An IDA Pro extension for easier (malware) reverse engineering☆111Updated 2 years ago
- Bindings for Microsoft WinDBG TTD☆216Updated last year
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆90Updated this week
- HashDB API hash lookup plugin for IDA Pro☆308Updated 4 months ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆197Updated 7 months ago
- UnpacMe IDA Byte Search☆28Updated last year