kevoreilly / capemon
capemon: CAPE's monitor
☆107Updated this week
Alternatives and similar repositories for capemon:
Users that are interested in capemon are comparing it to the libraries listed below
- Use YARA rules on Time Travel Debugging traces☆89Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆68Updated 10 months ago
- Automatically generate AV byte signatures from sets of similar binaries.☆263Updated 2 months ago
- IDA python plugin to scan binary with Yara rules☆172Updated last year
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- Hyper-V Research is trendy now☆177Updated 9 months ago
- Generating YARA rules based on binary code☆205Updated 3 years ago
- Parse .NET executable files.☆75Updated 2 weeks ago
- An IDA Pro extension for easier (malware) reverse engineering☆111Updated 2 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆58Updated last month
- Parsers for custom malware formats ("Funky malware formats")☆93Updated 3 years ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆123Updated 3 years ago
- ☆104Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- Parsing of YARA rules into AST and building new rulesets in C++.☆121Updated 3 weeks ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆119Updated 4 years ago
- Simple windows API logger☆99Updated 5 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆199Updated 2 years ago
- UnpacMe IDA Byte Search☆27Updated last year
- Robust Automated Malware Unpacker☆84Updated last year
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆247Updated last year
- Bindings for Microsoft WinDBG TTD☆215Updated last year
- Automatic YARA rule generation for Malpedia☆157Updated 2 years ago
- Analyses in IDA/Hex-Rays☆80Updated last year
- ☆100Updated 2 years ago
- IDA plugin for quickly copying disassembly as encoded hex bytes☆59Updated 3 years ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆89Updated 8 months ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆85Updated 2 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆63Updated 3 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago