ntddk / blueLinks
Some anti QEMU trick used by in-the-wild malware.
☆14Updated 10 years ago
Alternatives and similar repositories for blue
Users that are interested in blue are comparing it to the libraries listed below
Sorting:
- PoC for detecting and dumping process hollowing code injection☆52Updated 7 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Updated 10 years ago
- Code Injection technique written in cpp language☆34Updated 8 years ago
- A simple native code virtualizer for 32-bit Windows PE☆15Updated 10 years ago
- Examples for detection of hidden processes on windows☆35Updated 11 years ago
- Simple AntiVirus Driver example☆39Updated 8 years ago
- Bootkit for Windows 7☆27Updated 11 years ago
- Open source Anti Debug methods to use for your games. This uses SAC as an example. Will be sure to update it and / or add new features in…☆18Updated 5 years ago
- User-mode hook bypassing method☆33Updated 9 years ago
- Bypass Antivm and Cuckoo Sandbox Techniques☆12Updated 9 years ago
- A session-0 capable dll injection utility☆76Updated 7 years ago
- Class implementation of PowerLoader injection technique☆32Updated 9 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆58Updated 7 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆76Updated 7 years ago
- Protect process fsfilter driver. Windows x64☆36Updated 9 years ago
- Scanning and identifying XOR encrypted PE files in PE resources☆30Updated 11 years ago
- PCAUSA Rawether for Windows Local Privilege Escalation☆39Updated 8 years ago
- Windows DKOM : Hide Processus☆19Updated 13 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆28Updated 7 years ago
- Kernel mode driver loader, injecting into the windows kernel, Rootkit. Driver injections.☆48Updated 11 years ago
- MALM: Malware Monitor☆49Updated 12 years ago
- A Windows native DLL injection library written in C# that supports several methods of injection.☆13Updated 7 years ago
- APISearch Plugin (x86) - A Plugin For x64dbg☆53Updated 7 years ago
- Simple tool for unpacking packed/protected malware executables.☆32Updated 14 years ago
- A tool to monitor how a target process modifies other processes☆25Updated 8 years ago
- My collection of unpackers for malware packers/crypters☆28Updated 8 years ago
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆37Updated 8 years ago
- simple PE packer written in C++☆56Updated 7 years ago
- A DLL that performs IAT hooking☆27Updated 7 years ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆19Updated 9 years ago