mr-tz / idapython
IDAPython scripts
☆15Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for idapython
- ☆21Updated 3 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- A python script that can be used to scan data within in an IDB using Yara.☆22Updated 6 years ago
- ☆28Updated 4 years ago
- Generates YARA rules to detect malware using API hashing☆17Updated 3 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- Hansel - a simple but flexible search for IDA☆26Updated 5 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- My collection of unpackers for malware packers/crypters☆28Updated 7 years ago
- Rekall Memory Forensic Framework☆29Updated 5 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆39Updated 5 years ago
- VB Exe Parser is an IDA script written in Python. This script will help you to parse VB program internal structures. It can find: Event, …☆16Updated 8 years ago
- Utilities for working with vivisect☆23Updated 3 weeks ago
- IDARay is an IDA Pro plugin that matches the database against multiple YARA files which themselves may contain multiple rules.☆18Updated 6 years ago
- Go Lang Portable Executable Parser☆37Updated 3 years ago
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆30Updated 5 months ago
- Notepad++ Syntax Highlighting for Languages Used by Cyber Security Professionals☆14Updated 4 years ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- A small tool to unmap PE memory dumps.☆11Updated last year
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆35Updated 7 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 2 years ago
- ☆33Updated 7 years ago
- ☆33Updated 3 years ago
- ☆66Updated last year
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆26Updated 7 years ago
- Memory Loader Open Source Project by Sentinel-Labs.☆20Updated 3 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- Yet another rule generator for Yara☆25Updated 4 years ago