mandiant / VM-Packages
Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.
☆170Updated this week
Alternatives and similar repositories for VM-Packages:
Users that are interested in VM-Packages are comparing it to the libraries listed below
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- ☆200Updated 4 months ago
- PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs…☆176Updated 10 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆235Updated 2 weeks ago
- A C# based tool for analysing malicious OneNote documents☆111Updated last year
- The Windows Malware Analysis Reversing Core Tools☆92Updated 4 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆205Updated last year
- Collection of scripts used to deobfuscate GOOTLOADER malware samples.☆60Updated 3 months ago
- Rules shared by the community from 100 Days of YARA 2024☆85Updated 2 months ago
- ☆124Updated 3 weeks ago
- Dump quarantined files from Windows Defender☆61Updated 2 years ago
- Repository of Yara Rules☆103Updated last month
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆158Updated last month
- ☆236Updated 10 months ago
- Jupyter Notebooks for the Blue Team☆145Updated this week
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆139Updated 8 months ago
- A specification and style guide for YARA rules☆45Updated last year
- A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.☆95Updated last year
- A python script developed to process Windows memory images based on triage type.☆261Updated last year
- File analysis and management framework.☆83Updated last year
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆154Updated 4 months ago
- ☆158Updated last year
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆177Updated 2 months ago
- Active C&C Detector☆152Updated last year
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆121Updated last month
- ☆118Updated 11 months ago
- A collection of tools, scripts and personal research☆127Updated 8 months ago
- ☆67Updated last month
- Free training course offered at Hack Space Con 2023☆138Updated last year
- A guide on how to write fast and memory friendly YARA rules☆141Updated last month