milankovo / YaraVM
This repository contains an IDA processor for loading and disassembling compiled yara rules.
☆38Updated 2 months ago
Alternatives and similar repositories for YaraVM:
Users that are interested in YaraVM are comparing it to the libraries listed below
- ☆25Updated 4 months ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- UnpacMe IDA Byte Search☆28Updated last year
- A small tool to unmap PE memory dumps.☆11Updated last year
- Extract data of TTD trace file to a minidump☆28Updated last year
- ☆31Updated 2 years ago
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago
- ☆23Updated last year
- IDA Pro plugin to aid with the analysis of native IIS modules☆17Updated 7 months ago
- Winbindex bot to pull in binaries for specific releases☆46Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆69Updated 10 months ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆46Updated this week
- ☆49Updated 4 months ago
- javascript extension of windbg for hacker.☆15Updated last year
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Updated 2 years ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year
- Utilities for working with vivisect☆25Updated last week
- Report and exploit of CVE-2024-21305.☆34Updated last year
- A few examples of how to trap virtual memory access on Windows.☆27Updated 2 months ago
- Custom instruction length for hex-rays☆18Updated 2 months ago
- Các IDA Flirt signatures HTC tạo☆19Updated 4 months ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆26Updated 2 years ago
- Report and exploit of CVE-2023-36427☆89Updated last year
- WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware☆45Updated 2 years ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 8 months ago