malwarefrank / dnfile
Parse .NET executable files.
☆74Updated 2 months ago
Alternatives and similar repositories for dnfile:
Users that are interested in dnfile are comparing it to the libraries listed below
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆66Updated 9 months ago
- IDA Pro plugin for recognizing known hashes of API function names☆82Updated 2 years ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆83Updated 2 years ago
- MalUnpack companion driver☆93Updated 7 months ago
- IDA plugin for quickly copying disassembly as encoded hex bytes☆59Updated 2 years ago
- Memory Loader Open Source Project by Sentinel-Labs.☆20Updated 3 years ago
- ☆99Updated 2 years ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆123Updated 4 months ago
- UnpacMe IDA Byte Search☆27Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 6 months ago
- Use YARA rules on Time Travel Debugging traces☆88Updated last year
- capemon: CAPE's monitor☆106Updated this week
- Static Binary Instrumentation tool for Windows x64 executables☆193Updated 2 months ago
- ☆139Updated last year
- A utility to fix intentionally corrupted UPX packed files.☆82Updated last year
- The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.☆159Updated last week
- ☆103Updated last year
- Write-ups for FireEye's FLARE-On challenges☆25Updated 5 years ago
- An IDA Pro extension for easier (malware) reverse engineering☆110Updated 2 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆86Updated 3 years ago
- ☆31Updated 2 years ago
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆74Updated 2 weeks ago
- Powershell script deobfuscation using AST in Python☆64Updated last year
- ☆66Updated last year
- Writeups for CTF challenges☆30Updated last year
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆51Updated last week
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 2 years ago