mandiant / poisonplug-scatterbrainLinks
Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator
☆71Updated 8 months ago
Alternatives and similar repositories for poisonplug-scatterbrain
Users that are interested in poisonplug-scatterbrain are comparing it to the libraries listed below
Sorting:
- ☆89Updated 10 months ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆118Updated 2 years ago
- ☆31Updated 9 months ago
- Abusing exceptions for code execution.☆113Updated 2 years ago
- Rule Engine for Dynamic Malware Analysis and Research☆25Updated 7 months ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆42Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- ☆95Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆36Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆124Updated last year
- A Python script to download PDB files associated with a Portable Executable (PE)☆124Updated 10 months ago
- Binary Ninja plugin to deobfuscate strings obfuscated with the Garble project☆39Updated 9 months ago
- ☆60Updated 9 months ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆114Updated last year
- A set of LLVM and GCC based plugins that perform code obfuscation.☆134Updated last month
- a PE Loader and Windows API tracer. Useful in malware analysis.☆143Updated 3 years ago
- ☆156Updated 3 weeks ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆83Updated 8 months ago
- Report and exploit of CVE-2023-36427☆89Updated 2 years ago
- Rust bindings to the System Informer's (formerly known as Process Hacker) "phnt" native Windows headers☆47Updated 6 months ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆127Updated 2 years ago
- Modular and extensible library for Virtual Machine Introspection☆108Updated 3 months ago
- A Windows Named Pipe Multi-tool / Proxy☆76Updated last week
- ☆72Updated 2 years ago
- MalUnpack companion driver☆99Updated last year
- Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1☆67Updated 3 months ago
- ☆26Updated 3 months ago
- IDA Pro plugin to aid with the analysis of native IIS modules☆21Updated last year
- All LLVM binaries scrambled with SigBreaker and used to test against llvm-lit☆26Updated 7 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆88Updated last year