malice-plugins / windows-defender
Malice Windows Defender AntiVirus Plugin
☆38Updated 2 years ago
Alternatives and similar repositories for windows-defender:
Users that are interested in windows-defender are comparing it to the libraries listed below
- This is a simple tool to dump all the reparse points on an NTFS volume.☆33Updated 4 years ago
- Malice Office/OLE/RTF Plugin☆13Updated 6 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- ssdeep cluster analysis for malware files☆30Updated 4 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Rekall Memory Forensic Framework☆32Updated 5 years ago
- ☆24Updated 5 years ago
- Sources code extracted from malwares for analysis☆36Updated 2 years ago
- ☆45Updated 6 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆31Updated 7 years ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- A ready-made template for a project based on libpeconv.☆47Updated 2 months ago
- Library for Windows XML Event Log (EVTX) data types☆18Updated 6 months ago
- ProcDot Malware Sandbox☆24Updated 5 months ago
- Tool to decrypt the configuration of NanoCore and dump all used plugins☆10Updated 4 years ago
- Privilege Escilation training project, with an emphasis on the distinction between vulnerability research & it's exposure and exploitatio…☆35Updated 8 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆53Updated 2 years ago
- ☆23Updated last year
- A summary about different projects/presentations/tools to test how to evade malware sandbox systems☆51Updated 6 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆38Updated 2 months ago
- Golang parser for OLE files☆31Updated last month
- A collection of shellcode hashes☆17Updated 6 years ago
- PE file mapping and manipulation package.☆36Updated 2 years ago
- Community-based integrated malware identification system☆82Updated 2 years ago
- A tool for scanning registery key permissions. Find where non-admins can create symbolic links.☆46Updated 5 years ago
- D-Scan project for office document analysis and generating flow diagram of macro in documents. For demo visit☆29Updated 5 months ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆120Updated 4 years ago
- ☆16Updated 4 years ago
- A More Comfortable (remote) SHell with full pty support and both reverse / bindport connection mode.☆30Updated 11 years ago
- Some simple process injection techniques targeting the Windows platform☆32Updated 5 years ago