milankovo / YaraVM
This repository contains an IDA processor for loading and disassembling compiled yara rules.
☆40Updated 3 months ago
Alternatives and similar repositories for YaraVM:
Users that are interested in YaraVM are comparing it to the libraries listed below
- ☆25Updated 5 months ago
- A small tool to unmap PE memory dumps.☆11Updated last year
- Winbindex bot to pull in binaries for specific releases☆47Updated last year
- ☆31Updated 2 years ago
- UnpacMe IDA Byte Search☆28Updated last year
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Updated 2 years ago
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- Extract data of TTD trace file to a minidump☆28Updated last year
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- Remove WPP calls from hexrays decompiled code☆45Updated 2 weeks ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated last year
- ☆29Updated last month
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆49Updated this week
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- ☆52Updated 6 months ago
- Các IDA Flirt signatures HTC tạo☆19Updated 5 months ago
- ☆23Updated last year
- ☆22Updated 10 months ago
- Report and exploit of CVE-2023-36427☆90Updated last year
- IDA Pro plugin to aid with the analysis of native IIS modules☆18Updated 8 months ago
- Different tools for Microsoft Hyper-V researching☆52Updated 10 months ago
- A few examples of how to trap virtual memory access on Windows.☆29Updated 4 months ago
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆56Updated 3 years ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- Binary Ninja plugin for interacting with the OALabs HashDB service☆18Updated 5 months ago
- ☆28Updated 2 years ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆34Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆78Updated last month