mandiant / poisonplug-scatterbrainLinks
Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator
☆75Updated 10 months ago
Alternatives and similar repositories for poisonplug-scatterbrain
Users that are interested in poisonplug-scatterbrain are comparing it to the libraries listed below
Sorting:
- ☆90Updated 11 months ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆125Updated last year
- A Python script to download PDB files associated with a Portable Executable (PE)☆128Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆119Updated 2 years ago
- Rule Engine for Dynamic Malware Analysis and Research☆25Updated 9 months ago
- Abusing exceptions for code execution.☆113Updated 3 years ago
- ☆93Updated last year
- ☆31Updated 11 months ago
- Binary Ninja plugin to deobfuscate strings obfuscated with the Garble project☆43Updated 11 months ago
- ☆21Updated 2 years ago
- ☆24Updated last year
- ☆160Updated last month
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆41Updated 2 years ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆128Updated 2 years ago
- Native Rust bindings for @horsicq's Detect-It-Easy☆19Updated 3 months ago
- Virtual Trust Level (VTL 1) secure call tracing☆95Updated 5 months ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆37Updated 2 years ago
- a PE Loader and Windows API tracer. Useful in malware analysis.☆143Updated 3 years ago
- Winbindex bot to pull in binaries for specific releases☆48Updated 2 years ago
- Recon 2023 slides and code☆80Updated 2 years ago
- ☆64Updated 11 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆142Updated last week
- ☆72Updated 2 years ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆115Updated last year
- NovaHypervisor is a defensive x64 Intel host based hypervisor. The goal of this project is to protect against kernel based attacks (eithe…☆245Updated 4 months ago
- rp-bf: A library to bruteforce ROP gadgets by emulating a Windows user-mode crash-dump☆121Updated last year
- A collection of modules and scripts to help with analyzing Nim binaries☆83Updated last year
- Report and exploit of CVE-2023-36427☆90Updated 2 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆80Updated 8 months ago