packing-box / peid
Python implementation of the Packed Executable iDentifier (PEiD)
☆136Updated 10 months ago
Alternatives and similar repositories for peid:
Users that are interested in peid are comparing it to the libraries listed below
- HashDB API hash lookup plugin for IDA Pro☆308Updated 5 months ago
- Robust Automated Malware Unpacker☆84Updated last year
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆125Updated 3 years ago
- Dataset of packed PE samples☆33Updated 8 months ago
- Dynamic unpacker based on PE-sieve☆717Updated last week
- capemon: CAPE's monitor☆110Updated this week
- Debug Child Process Tool (auto attach)☆282Updated last year
- Automatic and platform-independent unpacker for Windows binaries based on emulation☆685Updated 6 months ago
- LERN GHIDRA☆90Updated 2 years ago
- ☆101Updated 2 years ago
- Assortment of hashing algorithms used in malware☆351Updated 3 weeks ago
- Ghidra scripts for malware analysis☆92Updated last year
- Quickly debug shellcode extracted during malware analysis☆595Updated last year
- Extract AutoIt scripts embedded in PE binaries☆181Updated 8 months ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆786Updated last year
- An interactive list of plugins for hex-rays' IDA Pro☆420Updated 4 months ago
- Ghidra Extension to integrate BinDiff for function matching☆264Updated last month
- Advanced driver monitoring utility.☆207Updated 2 years ago
- Tool for viewing and analyzing execution traces☆277Updated 4 years ago
- Binary Ninja plugin to identify obfuscated code and other interesting code constructs☆616Updated 2 weeks ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆119Updated last year
- Code snips and notes☆135Updated 3 years ago
- CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- p…☆126Updated 4 months ago
- Pyhidra is a Python library that provides direct access to the Ghidra API within a native CPython interpreter using jpype.☆200Updated 5 months ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆386Updated last week
- Automatically identify and extract potential anti-debugging techniques used by malware.☆151Updated 4 months ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆203Updated 2 years ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆248Updated 2 years ago
- ☆199Updated last year