pagiux / IRPLogger
A minifilter driver to capture processes behavior from a filesystem prospective.
☆14Updated 4 months ago
Alternatives and similar repositories for IRPLogger:
Users that are interested in IRPLogger are comparing it to the libraries listed below
- ☆10Updated 4 years ago
- Research tool able to detect and mitigate evasion techniques used by malware in-the-wild☆11Updated last year
- Robust API monitoring system presented in the paper "Designing Robust API Monitoring Solutions" (IEEE TDSC)☆23Updated 3 years ago
- Dataset of packed PE samples☆32Updated 7 months ago
- AVCLASS++: Yet Another Massive Malware Labeling Tool☆14Updated 5 years ago
- Automated Integration of anti-Reversing methods in PE executables☆50Updated 6 years ago
- Technion CS Ransomware Project: Writing Windows Mini-Filter Driver to protect PC from Ransomware☆35Updated 4 years ago
- Ransomware detection application for Windows using Windows Minifilter driver☆81Updated 4 years ago
- RanSAP: An Open Dataset of Ransomware Storage Access Patterns for Training Machine Learning Models☆28Updated 6 months ago
- Public datasets of malware and benign executable files (Windows EXE files). The dataset can be used by cybersecurity researchers focusing…☆22Updated last year
- This repository contains D-TIME: Distributed Threadless Independent Malware Execution for Runtime Obfuscation.☆35Updated 4 years ago
- capemon: CAPE's monitor☆107Updated this week
- Robust Automated Malware Unpacker☆84Updated last year
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆123Updated 3 years ago
- Library to hide DBI artifacts when using Intel Pin. Code from the ASIA CCS 2019 paper "SoK: Using Dynamic Binary Instrumentation for Secu…☆22Updated 5 years ago
- A minifilter driver preserves all modified and deleted files.☆80Updated 9 years ago
- Virtual Machine Introspection (VMI) for memory forensics and machine-learning.☆26Updated last month
- ☆36Updated 5 years ago
- ☆28Updated 7 years ago
- KVM Virtual Machine Introspection Library☆46Updated last year
- Small and lightweight x86-64 VBR bootkit for research purposes☆9Updated 2 years ago
- ☆12Updated 4 years ago
- Malware Classification and Labelling using Deep Neural Networks☆34Updated 5 years ago
- Example WDF/KMDF driver and test app demonstrating the "inverted call model"☆33Updated 4 years ago
- Automated Yara Rule generation using Biclustering☆63Updated 3 years ago
- Meltdown/Spectre PoC for Windows☆24Updated 5 years ago
- IntroVirt is an guest introspection library for KVM☆54Updated 5 months ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- ☆33Updated last year
- ☆12Updated 3 years ago