pagiux / IRPLoggerLinks
A minifilter driver to capture processes behavior from a filesystem prospective.
☆16Updated last year
Alternatives and similar repositories for IRPLogger
Users that are interested in IRPLogger are comparing it to the libraries listed below
Sorting:
- A new idea to build an anti ransomware☆24Updated 5 years ago
- This repo is created to perform I/O Request Packet (IRP) driven ransomware analysis where the IRP logs were collected during ransomware e…☆11Updated 5 years ago
- Robust API monitoring system presented in the paper "Designing Robust API Monitoring Solutions" (IEEE TDSC)☆24Updated 4 years ago
- RanSAP: An Open Dataset of Ransomware Storage Access Patterns for Training Machine Learning Models☆28Updated last year
- Public datasets of malware and benign executable files (Windows EXE files). The dataset can be used by cybersecurity researchers focusing…☆24Updated 2 years ago
- capemon: CAPE's monitor☆146Updated last week
- Robust Automated Malware Unpacker☆87Updated 2 years ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆128Updated 4 years ago
- This repository contains D-TIME: Distributed Threadless Independent Malware Execution for Runtime Obfuscation.☆36Updated 5 years ago
- 🔍 "2015 Microsoft Malware Classification Challenge" - Using machine learning to classify malware into different families based on Window…☆31Updated last year
- Ransomware detection application for Windows using Windows Minifilter driver☆93Updated 5 years ago
- ☆13Updated 5 years ago
- Defense from the 2020 Microsoft Evasion Competition☆17Updated 4 years ago
- ☆15Updated 5 years ago
- ☆21Updated 3 months ago
- Malware datasets tagged by behavior, platform, vulnerability, and packer☆29Updated last year
- IntroVirt is an guest introspection library for KVM☆60Updated 2 weeks ago
- ☆44Updated last year
- Code and Data for AisaCCS 2018 paper: Hardware Performance Counters Can Detect Malware: Myth or Fact?☆22Updated this week
- Dataset of packed PE samples☆43Updated 2 weeks ago
- A Deep Learning ensemble that classifies Windows executable files as either benign, ransomware, or other malware.☆27Updated 6 years ago
- Training and testing pipeline for ransomware classification based on screenshots of the splash screens or ransom notes (https://arxiv.org…☆11Updated 5 years ago
- Virtual Machine Introspection (VMI) for memory forensics and machine-learning.☆27Updated 8 months ago
- File system minifilter driver for Windows to block symbolic link attacks.☆52Updated 5 years ago
- AVCLASS++: Yet Another Massive Malware Labeling Tool☆14Updated 6 years ago
- Automated Yara Rule generation using Biclustering☆77Updated 4 months ago
- ☆16Updated 6 years ago
- KVM Virtual Machine Introspection Library☆48Updated 2 years ago
- LibVMI Python bindings☆35Updated 5 months ago
- Automated Integration of anti-Reversing methods in PE executables☆53Updated 7 years ago