ph0sec / CaptureBAT-client
Capture BAT is a behavioral analysis tool of applications for the Win32 operating system family.
☆32Updated 11 years ago
Alternatives and similar repositories for CaptureBAT-client:
Users that are interested in CaptureBAT-client are comparing it to the libraries listed below
- Blog posts☆30Updated 4 years ago
- CAPE monitor DLLs☆39Updated 5 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- Rekall Memory Forensic Framework☆31Updated 5 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 3 years ago
- It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.☆23Updated 6 years ago
- My collection of unpackers for malware packers/crypters☆28Updated 7 years ago
- Analysis PE file or Shellcode☆49Updated 8 years ago
- ☆22Updated 4 years ago
- DLL Injection Library & Tools☆72Updated 8 years ago
- TA505 unpacker Python 2.7☆47Updated 4 years ago
- VB Exe Parser is an IDA script written in Python. This script will help you to parse VB program internal structures. It can find: Event, …☆16Updated 8 years ago
- DotNext 2019 St. Petersburg Talk Demos☆38Updated 5 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆45Updated 7 years ago
- a program to detect reflective dll injection on a live machine☆75Updated 9 years ago
- Evil Reflective DLL Injection Finder☆47Updated 6 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 3 years ago
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆31Updated 4 years ago
- A DLL that serves OutputDebugString content over a TCP connection☆35Updated 3 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆34Updated 8 years ago
- Yaras Random☆20Updated 6 years ago
- Handy scripts to speed up malware analysis☆35Updated last year
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- ☆33Updated 7 years ago
- Discover TimeDateStamps In PE File☆17Updated 9 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 5 months ago
- Telsy CTI Research Team☆57Updated 4 years ago
- A summary about different projects/presentations/tools to test how to evade malware sandbox systems☆48Updated 6 years ago
- Common Malware Techniques☆13Updated last year