pracsec / YaraTools
Over 100K open-source YARA signatures evaluated against over 280K files to give insights into the performance of each YARA rule.
☆23Updated 2 years ago
Alternatives and similar repositories for YaraTools:
Users that are interested in YaraTools are comparing it to the libraries listed below
- Defeating Anti-Debugging Techniques for Malware Analysis☆13Updated 2 years ago
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆27Updated last year
- ☆18Updated 11 months ago
- Extension functionality for the NightHawk operator client☆26Updated last year
- A cap/pcap packet parser to make life easier when performing stealth/passive reconnaissance.☆21Updated 7 months ago
- WMI SA stuffs☆29Updated 2 years ago
- ☆12Updated 2 years ago
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆48Updated last year
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- Searching .evtx logs for remote connections☆23Updated last year
- ☆24Updated 2 years ago
- USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is exec…☆20Updated 2 years ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆20Updated last year
- ☆25Updated 3 months ago
- EventLogSilencer is a PowerShell script designed for disable Windows Event Logging☆15Updated last year
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- A project created with an aim to emulate and test exfiltration of data over different network protocols.☆31Updated last year
- The Catherine Framework is a general-purpose cybersecurity framework built to provide extended support for defense operations.☆16Updated 10 months ago
- Script to chain search parameters for MalwareBazaar☆9Updated last month
- freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package☆33Updated last year
- CSharp4Pentesters☆12Updated 3 years ago
- Yet, Another Packer/Loader☆25Updated 2 years ago
- Tool that can be used to trim useless things from a PE file such as the things a file pumper would add.☆26Updated 8 months ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- Method of finding interesting domains using keywords + JARMs☆13Updated 2 years ago
- OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research tea…☆18Updated 3 years ago
- A collection of my presentation materials.☆16Updated 10 months ago
- CIS Benchmark testing of Windows SIEM configuration☆44Updated last year
- ☆14Updated 2 years ago
- A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro…☆23Updated 2 years ago