kirk-sayre-work / VBASeismograph
A tool for detecting VBA stomping.
☆98Updated 2 years ago
Alternatives and similar repositories for VBASeismograph:
Users that are interested in VBASeismograph are comparing it to the libraries listed below
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Static based decoders for malware samples☆92Updated 4 years ago
- Toolset for research malware and Cobalt Strike beacons☆207Updated 2 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- A tool for de-obfuscating PowerShell scripts☆67Updated 5 years ago
- A repository of example VBA stomped documents☆28Updated 5 years ago
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆132Updated 2 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- An advanced memory forensics framework☆94Updated 5 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆148Updated 3 years ago
- Smart DLL execution for malware analysis in sandbox systems☆143Updated 10 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆85Updated 7 years ago
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated last year
- Collection of YARA signatures from individual research☆42Updated last year
- POSHSPY backdoor code☆43Updated 7 years ago
- A repo to document API functions mapped to security events across diverse platforms☆75Updated 5 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆107Updated 6 years ago
- Random hunting ordiented yara rules☆95Updated last year
- A repository that maps API calls to Sysmon Event ID's.☆117Updated 2 years ago
- Cuckoo running in a nested hypervisor☆128Updated 4 years ago
- A VBA parser and emulation engine to analyze malicious macros.☆95Updated this week
- Log newly created WMI consumers and processes to the Windows Application event log☆124Updated 6 years ago
- ☆134Updated 6 years ago
- A library for fast parse & import of Windows Eventlogs into Elasticsearch.☆85Updated 7 months ago
- ☆78Updated 8 years ago
- Lazy Office Analyzer☆119Updated 8 years ago
- a program to detect reflective dll injection on a live machine☆75Updated 9 years ago
- Malware similarity platform with modularity in mind.☆78Updated 3 years ago
- Community modules for CAPE Sandbox☆89Updated this week
- DLL Password Filter Implant with Exfiltration Capabilities☆135Updated 4 years ago