ralphje / signifyLinks
Module to generate and verify Authenticode signatures
☆84Updated last week
Alternatives and similar repositories for signify
Users that are interested in signify are comparing it to the libraries listed below
Sorting:
- Parse .NET executable files.☆76Updated last month
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- Windows kernel PDB data parsed into YAML☆41Updated 11 months ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆118Updated 2 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆75Updated 5 months ago
- a PE Loader and Windows API tracer. Useful in malware analysis.☆143Updated 3 years ago
- Simple windows API logger☆109Updated 6 years ago
- anti-ransomware file-system filter☆62Updated last year
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆144Updated 5 years ago
- Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.☆19Updated last year
- ☆25Updated last year
- Winbindex bot to pull in binaries for specific releases☆48Updated 2 years ago
- Small visualizator for PE files☆70Updated 2 years ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆103Updated 2 years ago
- Run Processes as PPL with ELAM☆173Updated 3 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆69Updated 4 years ago
- Command line utility for copying files on NTFS using low level disk access☆37Updated last year
- MalUnpack companion driver☆97Updated last year
- Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator☆64Updated 7 months ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆32Updated 3 years ago
- IDA Pro plugin to aid with the analysis of native IIS modules☆19Updated last year
- Windows Event Log Knowledge Base☆27Updated this week
- capemon: CAPE's monitor☆129Updated last week
- ☆32Updated 3 years ago
- Use YARA rules on Time Travel Debugging traces☆93Updated 2 years ago
- The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent …☆40Updated 3 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆143Updated 6 years ago
- Call arbitrary Windows kernel-mode functions from Python on another machine☆44Updated 4 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆62Updated last year
- A ready-made template for a project based on libpeconv.☆50Updated 7 months ago