libyal / winevt-kb
Windows Event Log Knowledge Base
☆22Updated 3 months ago
Alternatives and similar repositories for winevt-kb:
Users that are interested in winevt-kb are comparing it to the libraries listed below
- ☆32Updated 2 years ago
- Scripts, Yara rules and other files developed during malware investigations☆25Updated 2 years ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆42Updated last year
- Generate YARA rules for OOXML documents.☆37Updated last year
- ☆21Updated 3 months ago
- Generates YARA rules to detect malware using API hashing☆17Updated 3 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- ☆56Updated 3 months ago
- ☆15Updated 2 years ago
- Scripts to aid analysis of files obfuscated with ScatterBee.☆17Updated 2 years ago
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆57Updated 2 years ago
- YARA Language Server☆68Updated this week
- Unpacking and decryption tools for the Emotet malware☆46Updated 3 years ago
- ☆34Updated 2 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- Alternative YARA scanning engine☆67Updated 2 years ago
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆21Updated last year
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆37Updated last year
- ☆27Updated 2 years ago
- Steezy - Ghetto Yara Generation☆15Updated last year
- Modular malware analysis artifact collection and correlation framework☆53Updated 8 months ago
- Utilities for working with vivisect☆25Updated this week
- A set of tools for collecting forensic information☆26Updated 4 years ago
- ☆15Updated 3 years ago
- Specialized tool to dump Position Independent Code.☆21Updated 4 years ago
- General malware analysis stuff☆36Updated 4 months ago
- Royal Road RTF Weaponizer object decoder☆24Updated 3 months ago
- Repo containing my public talks☆22Updated last year
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Updated 2 years ago