mentebinaria / filegrab
Capture newly created files on Windows
☆65Updated 3 years ago
Alternatives and similar repositories for filegrab:
Users that are interested in filegrab are comparing it to the libraries listed below
- This x64dbg plugin adds several commands for dumping PE header information by address.☆62Updated 7 years ago
- A simple multiplatform command line search tool for Windows API.☆46Updated last month
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- Simple windows API logger☆101Updated 5 years ago
- ☆10Updated 6 years ago
- Al-khaser is a PoC malware with good intentions that aimes to stress your malware analysis / sandbox environement☆32Updated 10 years ago
- Crackmes Keygenmes Serialmes y más☆42Updated 2 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 7 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆43Updated 7 months ago
- My collection of unpackers for malware packers/crypters☆28Updated 7 years ago
- CLI program to calculate the entropy of files☆70Updated last year
- ☆22Updated 4 years ago
- Sample project for kernel debugging automation with Vagrant☆59Updated 5 years ago
- Enumerate user mode shared memory mappings on Windows.☆121Updated 4 years ago
- TrashDBG the world's worse debugger☆23Updated 3 years ago
- Set of antianalysis techniques found in malware☆132Updated last year
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆36Updated 7 years ago
- A DLL that performs IAT hooking☆27Updated 6 years ago
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆25Updated 5 years ago
- My repository to upload drivers from different books and all the information related to windows internals.☆156Updated 5 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- PoC for hiding PE exports☆66Updated 4 years ago
- JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.☆52Updated 4 years ago
- Kernel Detective☆143Updated 2 years ago
- MSI NTIOLib/WinIO Local Privilege Escalation exploit☆93Updated 8 years ago
- A simple password-based PE encryptor for Windows 32-bit executables.☆51Updated 3 months ago
- I was challenged by a friend to list all the processes and drivers in a system using more "unusual" methods. By doing this I learned quit…☆14Updated 8 years ago
- ☆30Updated 6 years ago
- Dump system call codes, names, and offsets from Ntdll.dll☆76Updated last year
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆71Updated 3 years ago