lfontesm / PEB-Walk
☆12Updated 3 years ago
Alternatives and similar repositories for PEB-Walk:
Users that are interested in PEB-Walk are comparing it to the libraries listed below
- PoC for hiding PE exports☆66Updated 4 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- Go Lang Portable Executable Parser☆39Updated 3 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆40Updated 5 years ago
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆72Updated 3 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- ☆31Updated 2 years ago
- TrashDBG the world's worse debugger☆23Updated 3 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆88Updated 3 years ago
- ☆67Updated last year
- An attempt to restore and adapt to modern Win10 version the 'Rootkit Arsenal' original code samples☆68Updated 2 years ago
- Windows API Hashes used in the malwares☆41Updated 9 years ago
- UnpacMe IDA Byte Search☆28Updated last year
- This is a simple driver with x64 inline assembly☆54Updated 4 years ago
- Set of antianalysis techniques found in malware☆129Updated last year
- MalUnpack companion driver☆92Updated 8 months ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 8 years ago
- Windows Drivers☆97Updated 5 years ago
- Process Injection without R/W target memory and without creating a remote thread☆18Updated 3 years ago
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆53Updated 5 years ago
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 2 years ago
- Sample project for kernel debugging automation with Vagrant☆60Updated 4 years ago
- Rite Of Passage ROP Injector☆34Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆93Updated 3 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆34Updated 3 years ago
- Writeups for CTF challenges☆30Updated last year
- Write-ups for FireEye's FLARE-On challenges☆25Updated 5 years ago
- Simple 32/64-bit PEs loader.☆137Updated 6 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆46Updated 4 years ago
- Anti-Debugging detection and obufuscation techniques that involved the use of Win32 API functions.☆34Updated 8 years ago