Vovk is framework of tools that include a WinDbg extension that generates in-depth YARA rules for malware.
☆24Aug 26, 2024Updated 2 years ago
Alternatives and similar repositories for vovk
Users that are interested in vovk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"☆17Feb 6, 2025Updated last year
- Asset inventory of over 800 public bug bounty programs.☆12Jun 12, 2023Updated 3 years ago
- ☆18Aug 8, 2024Updated 2 years ago
- PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer Detection☆30Dec 6, 2023Updated 2 years ago
- This is a collection of tools that make up what we call a "Drop-Pi", primarily used as a quick placement device during a physical/social …☆37Oct 8, 2024Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- IDA Type Info Libraries for RE☆31Jan 11, 2025Updated last year
- Quick test for CVE-2023-26025 behaviours☆13Nov 29, 2023Updated 2 years ago
- Some resources to facilitate my blog on auditd for security monitoring☆13Mar 23, 2023Updated 3 years ago
- A malware scanner with Yara and ClamAV binding☆12May 23, 2026Updated 3 months ago
- Dynamic Tracing in Android (fork from iovisor/ply)☆21Nov 26, 2022Updated 3 years ago
- An extension of the sigma standard to include security metrics.☆17May 18, 2023Updated 3 years ago
- Manage attack surface data on Elasticsearch☆27Nov 20, 2023Updated 2 years ago
- HTTP client with middleware. Middleware provides composable support for record/replay, logging, exponential backoff, and more.☆13Jun 5, 2025Updated last year
- ☆17Jun 26, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An Adaptive Misuse Detection System☆49Nov 4, 2024Updated last year
- Rust implementation of the rectcut algorithm described in https://halt.software/dead-simple-layouts/☆18Feb 13, 2023Updated 3 years ago
- LD_PRELOAD Linux rootkit (x86 & ARM)☆25Apr 8, 2019Updated 7 years ago
- PoolViz provides an interactive visualization of memory allocation patterns across multiple layers of segment heap.☆26Nov 18, 2025Updated 9 months ago
- NextB的基于敏感哈希的恶意文件相似度比较工具(python版本)☆14Jan 20, 2022Updated 4 years ago
- A novel obfuscation technique for ELF programs by abusing symbol resolution metadata to break disassembly output☆23Jul 13, 2025Updated last year
- LLDB based debugger for Linux Kernel☆28Apr 5, 2025Updated last year
- Windows Minidump loader for Ghidra☆28Sep 30, 2022Updated 3 years ago
- 域前置版本FRP☆17Nov 24, 2022Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆85Jun 28, 2023Updated 3 years ago
- Share your Yara rules with VirusTotal☆27Aug 12, 2024Updated 2 years ago
- ☆10Aug 9, 2024Updated 2 years ago
- Automatic generation of YARA rules from sample files.☆28Jul 10, 2026Updated last month
- Use CMSTP.exe to bypass UAC.☆52Jun 24, 2022Updated 4 years ago
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆82Aug 31, 2023Updated 3 years ago
- POC for CVE-2023-29360☆11Aug 31, 2024Updated 2 years ago
- Neuron Activation☆28Nov 21, 2024Updated last year
- PDB Rewriting Rust Library☆27Apr 26, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Symbolic Execution based on lifting amd64 to z3☆32Jul 2, 2024Updated 2 years ago
- CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious…☆15Jan 21, 2025Updated last year
- A set of tools and exploits to cause DoS for remote Windows Server & Windows 11 machines☆33Feb 9, 2026Updated 6 months ago
- rust actix-web admin☆11Apr 22, 2022Updated 4 years ago
- Download pdbs from symbol servers and cache locally, parse symbol paths from env vars☆22Mar 7, 2025Updated last year
- ☆10Apr 30, 2021Updated 5 years ago
- a golang based dotnet ysoserial poc generation tool. Operated by cursor and reproduce from metasploit☆15Nov 12, 2025Updated 9 months ago