ralphje / signifyLinks
Module to generate and verify PE signatures
☆53Updated last week
Alternatives and similar repositories for signify
Users that are interested in signify are comparing it to the libraries listed below
Sorting:
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆58Updated 4 years ago
- Yet another rule generator for Yara☆29Updated 3 weeks ago
- Windows Event Log Knowledge Base☆25Updated 8 months ago
- Trace events in real time sessions☆45Updated last year
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆32Updated last year
- A ready-made template for a project based on libpeconv.☆48Updated 4 months ago
- Golang parser for OLE files☆32Updated 3 months ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 2 years ago
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆73Updated last year
- A cross-platform library for verifying Authenticode signatures☆151Updated 4 months ago
- Parse .NET executable files.☆76Updated last month
- ☆13Updated 2 years ago
- SPI flash read MitM attack PoC☆38Updated 3 years ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 3 years ago
- Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.☆18Updated last year
- Native Python3 bindings for @horsicq's Detect-It-Easy☆71Updated last month
- Python module to extract Ascii, Utf8, and Unicode strings from binary data. Lightning fast wrapper around c++ compiled code.☆53Updated last week
- A Portable Executable parser for Golang☆47Updated 5 months ago
- capemon: CAPE's monitor☆123Updated 2 weeks ago
- Memory Loader Open Source Project by Sentinel-Labs.☆24Updated 4 years ago
- YARA Language Server☆71Updated 3 weeks ago
- Inject unsigned DLL into Protected Process Light (PPL)☆25Updated last month
- Utilities for working with vivisect☆25Updated 3 months ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆65Updated 3 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆35Updated 9 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆143Updated 4 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆60Updated 10 months ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Scripts to aid analysis of files obfuscated with ScatterBee.☆20Updated 2 years ago