milankovo / YaraVM
This repository contains an IDA processor for loading and disassembling compiled yara rules.
☆40Updated 3 months ago
Alternatives and similar repositories for YaraVM:
Users that are interested in YaraVM are comparing it to the libraries listed below
- ☆25Updated 5 months ago
- UnpacMe IDA Byte Search☆28Updated last year
- A small tool to unmap PE memory dumps.☆11Updated last year
- ☆31Updated 2 years ago
- Các IDA Flirt signatures HTC tạo☆19Updated 5 months ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- Winbindex bot to pull in binaries for specific releases☆47Updated last year
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆47Updated this week
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- javascript extension of windbg for hacker.☆15Updated last year
- A few examples of how to trap virtual memory access on Windows.☆28Updated 3 months ago
- IDA Pro plugin to aid with the analysis of native IIS modules☆18Updated 8 months ago
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- IDA plugin to deobfuscate emotet CFF☆17Updated 2 years ago
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆114Updated 8 months ago
- Convenience routines for working with the Unicorn emulator in Python☆25Updated last month
- The Frida-Jit-unPacker aims at helping researchers and analysts understand the behavior of packed malicious .NET samples.☆56Updated 11 months ago
- ZMQ and Messagepack Powered Remote Automation Plugin for x64dbg☆17Updated last month
- Repository for Flare-On challenges and solutions/code☆9Updated 4 months ago
- ☆23Updated last year
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago
- Go fastcall analysis for ida decompiler☆31Updated last month
- ☆15Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆78Updated last month
- ☆51Updated 5 months ago
- ☆28Updated 2 years ago