ntddk / blueLinks
Some anti QEMU trick used by in-the-wild malware.
☆14Updated 10 years ago
Alternatives and similar repositories for blue
Users that are interested in blue are comparing it to the libraries listed below
Sorting:
- APISearch Plugin (x86) - A Plugin For x64dbg☆53Updated 7 years ago
- A tool to monitor how a target process modifies other processes☆25Updated 8 years ago
- Code Injection technique written in cpp language☆33Updated 7 years ago
- PoC for detecting and dumping process hollowing code injection☆52Updated 7 years ago
- Examples for detection of hidden processes on windows☆35Updated 11 years ago
- Open source Anti Debug methods to use for your games. This uses SAC as an example. Will be sure to update it and / or add new features in…☆18Updated 5 years ago
- MALM: Malware Monitor☆49Updated 12 years ago
- Bypass Antivm and Cuckoo Sandbox Techniques☆12Updated 9 years ago
- Kernel mode driver loader, injecting into the windows kernel, Rootkit. Driver injections.☆48Updated 11 years ago
- Class implementation of PowerLoader injection technique☆32Updated 8 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆79Updated 10 years ago
- Plugin for x64dbg to break on unresolved APIs.☆12Updated 8 years ago
- A simple native code virtualizer for 32-bit Windows PE☆15Updated 9 years ago
- Today Plugin (x64) - A Plugin For x64dbg☆13Updated 7 years ago
- User-mode hook bypassing method☆33Updated 9 years ago
- Obtain remote process cookies by performing a brute-force attack on ntdll.RtlDecodePointer using known pointer encodings.☆22Updated 8 years ago
- Simple tool for unpacking packed/protected malware executables.☆33Updated 14 years ago
- Scanning and identifying XOR encrypted PE files in PE resources☆29Updated 11 years ago
- Wow64 syscall hook☆42Updated 8 years ago
- Helper utility for debugging windows PE/PE+ loader.☆52Updated 10 years ago
- Simple AntiVirus Driver example☆39Updated 7 years ago
- PE rebuilder, based on yoda's realigndll☆12Updated 14 years ago
- WhoCalls can query a directory of files, find the binaries, and search for a user specified Win API import. It and works with both 32-bit…☆18Updated 3 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆57Updated 7 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆35Updated 8 years ago
- simple PE packer written in C++☆55Updated 7 years ago
- PCAUSA Rawether for Windows Local Privilege Escalation☆39Updated 8 years ago
- APIInfo Plugin (x86) - A Plugin For x64dbg☆49Updated 7 years ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆19Updated 9 years ago
- ice9 - is anticheat based on usermode tricks and undocumented methods , builded as dll for loading trought the shibari framework☆24Updated 9 months ago