kevoreilly / capemon
capemon: CAPE's monitor
☆102Updated last week
Related projects ⓘ
Alternatives and complementary repositories for capemon
- IDA python plugin to scan binary with Yara rules☆171Updated 9 months ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆196Updated 2 years ago
- ☆100Updated last year
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆122Updated 2 years ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆81Updated last year
- Parse .NET executable files.☆74Updated last week
- Hyper-V Research is trendy now☆172Updated 6 months ago
- Community modules for CAPE Sandbox☆86Updated this week
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- Automatically generate AV byte signatures from sets of similar binaries.☆259Updated 9 months ago
- Robust Automated Malware Unpacker☆84Updated last year
- Use YARA rules on Time Travel Debugging traces☆86Updated last year
- Parsing of YARA rules into AST and building new rulesets in C++.☆120Updated 3 weeks ago
- Set of antianalysis techniques found in malware☆129Updated last year
- Generating YARA rules based on binary code☆203Updated 3 years ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆241Updated last year
- Simple windows API logger☆98Updated 5 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆114Updated last year
- MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. M…☆219Updated 4 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆62Updated 7 months ago
- Automatic YARA rule generation for Malpedia☆155Updated 2 years ago
- List of tools to assist in analyzing samples of ISFB/Gozi/Ursnif☆15Updated 5 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆62Updated 3 years ago
- An IDA Pro extension for easier (malware) reverse engineering☆110Updated 2 years ago
- Analyses in IDA/Hex-Rays☆78Updated last year
- zer0m0n driver for cuckoo sandbox☆356Updated 9 years ago
- Bindings for Microsoft WinDBG TTD☆213Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 3 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago