kevoreilly / capemonLinks
capemon: CAPE's monitor
☆145Updated last week
Alternatives and similar repositories for capemon
Users that are interested in capemon are comparing it to the libraries listed below
Sorting:
- Native Python3 bindings for @horsicq's Detect-It-Easy☆80Updated 8 months ago
- HashDB API hash lookup plugin for IDA Pro☆348Updated 3 months ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆111Updated 3 years ago
- A DTrace on Windows Reimplementation☆369Updated 4 months ago
- ☆113Updated 4 months ago
- Use YARA rules on Time Travel Debugging traces☆96Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- Parse .NET executable files.☆83Updated last week
- ☆116Updated 3 years ago
- Dataset of packed PE samples☆43Updated 2 weeks ago
- The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.☆171Updated last week
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆220Updated 3 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆119Updated 2 years ago
- Powershell script deobfuscation using AST in Python☆73Updated 4 months ago
- Document ETW providers☆267Updated 5 years ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆128Updated 4 years ago
- A simple C# executable that invokes an arbitrary method of an arbitrary C# DLL☆139Updated last year
- Extract AutoIt scripts embedded in PE binaries☆216Updated last year
- IDA plugin for quickly copying disassembly as encoded hex bytes☆65Updated 4 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆83Updated 3 years ago
- Automatically generate AV byte signatures from sets of similar binaries.☆285Updated last year
- IDA python plugin to scan binary with Yara rules☆180Updated 2 years ago
- Simple windows API logger☆109Updated 6 years ago
- Sysmon-Like research tool for ETW☆384Updated 3 years ago
- MalUnpack companion driver☆99Updated last year
- ☆306Updated 4 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆329Updated last year
- Anti-Debug encyclopedia contains methods used by malware to verify if they are executed under debugging. It includes the description of v…☆64Updated 2 years ago
- Hyper-V Research is trendy now☆195Updated last year
- Debug Child Process Tool (auto attach)☆321Updated 2 years ago