ralphje / signifyLinks
Module to generate and verify PE signatures
☆55Updated last month
Alternatives and similar repositories for signify
Users that are interested in signify are comparing it to the libraries listed below
Sorting:
- Parse .NET executable files.☆76Updated last week
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆73Updated last year
- A cross-platform library for verifying Authenticode signatures☆153Updated 4 months ago
- A set of small utilities, helpers for PIN tracers☆32Updated last year
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆145Updated 4 years ago
- Windows Event Log Knowledge Base☆26Updated 9 months ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆65Updated 3 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆76Updated 6 months ago
- Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.☆18Updated last year
- A ready-made template for a project based on libpeconv.☆49Updated 4 months ago
- Python implementation of LZNT1 compression/decompression☆65Updated 5 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆71Updated 2 months ago
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆32Updated last year
- capemon: CAPE's monitor☆124Updated 3 weeks ago
- Command line utility for copying files on NTFS using low level disk access☆36Updated last year
- A WinDbg extension to trace COM interactions☆115Updated last year
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 3 years ago
- Windows Process Lockdown Tool using Job Objects☆69Updated 11 years ago
- GetHooks is a program designed for the passive detection and monitoring of hooks from a limited user account.☆61Updated 3 years ago
- Trace events in real time sessions☆45Updated last year
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆36Updated 7 years ago
- Use YARA rules on Time Travel Debugging traces☆92Updated 2 years ago
- Memory Loader Open Source Project by Sentinel-Labs.☆24Updated 4 years ago
- anti-ransomware file-system filter☆59Updated 10 months ago
- ☆62Updated last year
- Simple windows API logger☆108Updated 5 years ago
- Small visualizator for PE files☆69Updated last year