Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) passed into AMSI during dynamic execution.
☆113Apr 20, 2021Updated 5 years ago
Alternatives and similar repositories for amsi-tracer
Users that are interested in amsi-tracer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Data and structures regarding the research done on WdFilter☆12Apr 15, 2020Updated 6 years ago
- Shellcode Loader Utilizing ETW Events☆66Feb 26, 2025Updated last year
- Resolve syscall numbers at runtime for all Windows versions.☆60Nov 21, 2024Updated last year
- A tool to help malware analysts signature unique parts of RTF documents☆28Jan 5, 2026Updated 6 months ago
- A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface☆17Jan 10, 2020Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆336May 2, 2024Updated 2 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆121Apr 8, 2023Updated 3 years ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- DLL hijacking vulnerability scanner and PE infector tool☆20Sep 8, 2017Updated 8 years ago
- Load .net assemblies from memory while having them appear to be loaded from an on-disk location.☆173May 5, 2021Updated 5 years ago
- PoC to demonstrate how CLR ETW events can be tampered.☆193Mar 26, 2020Updated 6 years ago
- Data from analysis of the custom sample from the chapter "Practical Analysis and Test"☆12Aug 1, 2020Updated 5 years ago
- ☆26Aug 25, 2020Updated 5 years ago
- Managed assembly shellcode generation☆282Mar 19, 2021Updated 5 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")☆373Feb 27, 2023Updated 3 years ago
- Firebase Domain Front Code☆21May 4, 2021Updated 5 years ago
- Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which …☆447Oct 26, 2022Updated 3 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆300Apr 10, 2021Updated 5 years ago
- ☆51Apr 13, 2020Updated 6 years ago
- C Header Only Library for Virii☆11Nov 17, 2020Updated 5 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Feb 15, 2022Updated 4 years ago
- Various scripts for different malware families☆106Apr 12, 2021Updated 5 years ago
- ☆57Mar 26, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- OPSEC safe Kerberoasting in C#☆200Jun 14, 2022Updated 4 years ago
- ☆163Jul 31, 2022Updated 3 years ago
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆313Dec 9, 2023Updated 2 years ago
- Automatically create YARA rules from malicious documents.☆211May 16, 2022Updated 4 years ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆118Updated this week
- Using outlook COM objects to create convincing phishing emails without the user noticing. This project is meant for internal phishing.☆157Dec 22, 2020Updated 5 years ago
- A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies☆325Apr 8, 2023Updated 3 years ago
- YARA Rule Strings Statistics Calculator and Malware Research Helper☆14Jul 24, 2021Updated 4 years ago
- Expriments☆486Oct 3, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Yara rules☆21Mar 27, 2023Updated 3 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- Beacon Object File allowing creation of Beacons in different sessions.☆84May 23, 2022Updated 4 years ago
- PoCs and tools for investigation of Windows process execution techniques☆958Feb 2, 2026Updated 5 months ago
- ☆188Jan 5, 2021Updated 5 years ago
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆112Feb 8, 2025Updated last year
- Unpacker for donut shellcode☆22Jun 20, 2020Updated 6 years ago