ralphje / signify
Module to generate and verify PE signatures
☆46Updated 2 months ago
Alternatives and similar repositories for signify:
Users that are interested in signify are comparing it to the libraries listed below
- A cross-platform library for verifying Authenticode signatures☆142Updated this week
- Golang parser for OLE files☆31Updated 8 months ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 3 years ago
- Alternative YARA scanning engine☆67Updated 2 years ago
- ☆13Updated 2 years ago
- ☆16Updated last year
- Trace events in real time sessions☆44Updated last year
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆52Updated 2 years ago
- Library and tools to access the Windows Event Log (EVT) format☆58Updated 7 months ago
- Library and tools to access the Windows Minidump (MDMP) format☆40Updated 7 months ago
- Yet another rule generator for Yara☆27Updated 4 years ago
- Tools for inspecting YARA bytecode☆15Updated 4 years ago
- A Portable Executable parser for Golang☆47Updated last month
- Pure Python parser for data encoded by .NET's BinaryFormatter☆50Updated 6 years ago
- capemon: CAPE's monitor☆107Updated this week
- ☆23Updated 5 years ago
- YARA Language Server☆68Updated this week
- Named pipe I/O ETW provider for Windows☆69Updated 4 years ago
- zer0m0n driver for cuckoo sandbox☆87Updated 8 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆72Updated last month
- Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.☆16Updated 11 months ago
- Automatically exported from code.google.com/p/verify-sigs☆18Updated 8 years ago
- File Capability Extractor☆13Updated 3 months ago
- Parsing of YARA rules into AST and building new rulesets in C++.☆121Updated 3 weeks ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆68Updated 10 months ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆63Updated 3 years ago
- xlrd2 is a variant of xlrd that is actively maintained☆23Updated 6 months ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year