n1ght-w0lf / HawkEye
Malware dynamic instrumentation tool based on frida framework
☆105Updated 4 years ago
Alternatives and similar repositories for HawkEye:
Users that are interested in HawkEye are comparing it to the libraries listed below
- Go Lang Portable Executable Parser☆39Updated 4 years ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- Capa analysis importer for Ghidra.☆61Updated 4 years ago
- IDA python plugin to scan binary with Yara rules☆172Updated last year
- An IDA Pro extension for easier (malware) reverse engineering☆112Updated 2 years ago
- ☆71Updated last year
- Ebfuscator: Abusing system errors for binary obfuscation☆52Updated 5 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- Write-ups for crackmes and CTF challenges☆51Updated 2 years ago
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 2 years ago
- ☆105Updated last year
- Robust Automated Malware Unpacker☆84Updated last year
- Multi-tool reverse engineering collaboration solution.☆138Updated last year
- Automatically rebuild Import Address Table for dumped PE file. With python bindings!☆118Updated 6 years ago
- This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultim…☆105Updated 7 months ago
- IDA plugin to pinpoint obfuscated code☆140Updated 2 years ago
- Slides, recordings and materials of my public presentations, talks and workshops.☆78Updated 3 weeks ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆91Updated last month
- Write-ups for FireEye's FLARE-On challenges☆25Updated 5 years ago
- Malware Configuration Extraction Modules☆49Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated last year
- ☆108Updated 4 years ago
- Ghidra scripts such as a RC4 decrypter, Yara search, stack string decoder, etc.☆158Updated 5 years ago
- IDA plugin for quickly copying disassembly as encoded hex bytes☆61Updated 3 years ago
- Generating YARA rules based on binary code☆208Updated 3 years ago
- Import DynamoRIO drcov code coverage data into Ghidra☆43Updated last year
- Writeups for CTF challenges☆31Updated last year
- A collection of ready-to-use library code and symbols for the MinHash-based Code Relationship & Investigation Toolkit (MCRIT)☆11Updated 11 months ago
- TrashDBG the world's worse debugger☆23Updated 3 years ago
- IDA Pro resources, scripts, and configurations☆111Updated last year