mgeeky / msidump
MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.
☆203Updated last year
Alternatives and similar repositories for msidump:
Users that are interested in msidump are comparing it to the libraries listed below
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆307Updated last year
- Finding secrets in kernel and user memory☆113Updated last year
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆224Updated 11 months ago
- A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!☆321Updated 6 months ago
- POC for frustrating/defeating Malware Analysts☆154Updated 2 years ago
- Aims to identify sleeping beacons☆562Updated 2 months ago
- ☆112Updated last year
- Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows☆203Updated 2 years ago
- EDRSandblast-GodFault☆250Updated last year
- ☆182Updated 2 years ago
- ETW based POC to identify direct and indirect syscalls☆180Updated last year
- ☆296Updated 3 months ago
- Kill AV/EDR leveraging BYOVD attack☆336Updated last year
- Native Syscalls Shellcode Injector☆264Updated last year
- Run Your Payload Without Running Your Payload☆180Updated 2 years ago
- ☆214Updated 2 years ago
- Detect strange memory regions and DLLs☆177Updated 3 years ago
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆165Updated last year
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆333Updated this week
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆105Updated last week
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆152Updated last month
- different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)☆184Updated last year
- ☆112Updated 2 years ago
- A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.☆318Updated 2 years ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆134Updated 6 months ago
- ☆160Updated last year
- Exploitation of process killer drivers☆196Updated last year
- Beacon Object File Loader☆282Updated last year
- Simple EDR implementation to demonstrate bypass☆166Updated 4 years ago