ntddk / blueLinks
Some anti QEMU trick used by in-the-wild malware.
☆14Updated 10 years ago
Alternatives and similar repositories for blue
Users that are interested in blue are comparing it to the libraries listed below
Sorting:
- PCAUSA Rawether for Windows Local Privilege Escalation☆39Updated 8 years ago
- MALM: Malware Monitor☆50Updated 12 years ago
- find and kill injectedThreads from memory☆12Updated 9 years ago
- Bypass Antivm and Cuckoo Sandbox Techniques☆12Updated 8 years ago
- Examples for detection of hidden processes on windows☆34Updated 11 years ago
- APIInfo Plugin (x86) - A Plugin For x64dbg☆49Updated 7 years ago
- Open source Anti Debug methods to use for your games. This uses SAC as an example. Will be sure to update it and / or add new features in…☆18Updated 4 years ago
- APISearch Plugin (x86) - A Plugin For x64dbg☆52Updated 7 years ago
- PoC for detecting and dumping process hollowing code injection☆52Updated 6 years ago
- OpenHIPS prevents exploitation of Windows systems☆35Updated 12 years ago
- Class implementation of PowerLoader injection technique☆32Updated 8 years ago
- Scanning and identifying XOR encrypted PE files in PE resources☆28Updated 11 years ago
- Simple tool for unpacking packed/protected malware executables.☆33Updated 13 years ago
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆37Updated 7 years ago
- A simple native code virtualizer for 32-bit Windows PE☆15Updated 9 years ago
- Obtain remote process cookies by performing a brute-force attack on ntdll.RtlDecodePointer using known pointer encodings.☆22Updated 8 years ago
- Malware monitor template based on MinHook☆16Updated 10 years ago
- ☆19Updated 8 years ago
- A tool to monitor how a target process modifies other processes☆25Updated 7 years ago
- C++ game hack for Counter-Strike: Source. It was coded for the "Orange Box" update.☆15Updated 10 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆57Updated 6 years ago
- My collection of unpackers for malware packers/crypters☆28Updated 8 years ago
- Plugin for x64dbg to break on unresolved APIs.☆12Updated 7 years ago
- Simple AntiVirus Driver example☆38Updated 7 years ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆19Updated 9 years ago
- Today Plugin (x64) - A Plugin For x64dbg☆13Updated 7 years ago
- MemoryHacker is a tool which can search for values on the target process!☆23Updated 9 years ago
- Protect process fsfilter driver. Windows x64☆36Updated 9 years ago
- windows create process with a dll load first time via LdrHook☆30Updated 8 years ago
- A MITM proxy server for reflective DLL injection through WinINet☆15Updated 7 years ago