saferwall / pe
A lightweight Go package to parse, analyze and extract metadata from Portable Executable (PE) binaries. Designed for malware analysis tasks and robust against PE malformations.
☆358Updated 5 months ago
Alternatives and similar repositories for pe:
Users that are interested in pe are comparing it to the libraries listed below
- A command line Windows API tracing tool for Golang binaries.☆156Updated last year
- Go symbol recovery tool☆717Updated 2 months ago
- GoRE - Package gore is a library for analyzing Go binaries☆488Updated this week
- IDApython Scripts for Analyzing Golang Binaries☆626Updated 9 months ago
- Universal Shared Library User-space Loader☆225Updated 2 years ago
- Assortment of hashing algorithms used in malware☆360Updated last month
- It's a go variant of Hells gate! (directly calling windows kernel functions, but from Go!)☆504Updated 2 years ago
- Donut Injector ported to pure Go. For use with https://github.com/TheWover/donut☆337Updated 2 years ago
- Fork of pkg/debug that adds some additional functionality.☆124Updated last year
- A way to delete a locked file, or current running executable, on disk.☆524Updated 9 months ago
- Dynamic unpacker based on PE-sieve☆730Updated last month
- Process Injection Techniques with Golang☆77Updated 4 years ago
- x86 malware emulator☆217Updated last month
- A Binary Genetic Traits Lexer Framework☆490Updated 2 months ago
- Elf binary infector written in Go.☆209Updated 4 months ago
- Redress - A tool for analyzing stripped Go binaries☆1,030Updated this week
- Pakkero is a binary packer written in Go made for fun and educational purpose. Its main goal is to take in input a program file (elf bina…☆260Updated 2 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆743Updated last year
- Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging☆546Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆388Updated this week
- Yet another variant of Process Hollowing☆392Updated 3 months ago
- Go interface to NTDLL functions☆74Updated last year
- Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ON…☆627Updated 2 weeks ago
- Golang PE injection on windows☆167Updated 3 years ago
- Exploiting DLL Hijacking by DLL Proxying Super Easily☆504Updated last year
- Signtool for expired certificates☆477Updated last year
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆668Updated last year
- A DTrace on Windows Reimplementation☆344Updated 3 months ago
- A PoC package for hosting the CLR and executing .NET from Go☆219Updated 2 years ago
- Python tool to resolve all strings in Go binaries obfuscated by garble☆74Updated 2 months ago