sandflysecurity / sandfly-file-decloak
Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.
☆22Updated 2 years ago
Alternatives and similar repositories for sandfly-file-decloak:
Users that are interested in sandfly-file-decloak are comparing it to the libraries listed below
- Linux #rootkit and #malware revealer☆24Updated 7 months ago
- Scripts and lists to help generate YARA friendly string mutations☆21Updated last year
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 3 years ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆21Updated last year
- ☆17Updated 7 months ago
- Surface Analysis System on Cloud☆19Updated last year
- ☆22Updated 4 years ago
- ☆22Updated 5 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆38Updated last month
- Hunt for SQLite files used by various applications☆23Updated last week
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆24Updated last week
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated last month
- ☆44Updated last year
- Links to malware-related YARA rules☆15Updated 2 years ago
- ☆34Updated 2 years ago
- C# User Simulation☆32Updated 2 years ago
- THOR Thunderstorm Collectors☆24Updated last month
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆26Updated 2 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- DNS Dashboard for hunting and identifying beaconing☆15Updated 4 years ago
- Old home of LimaCharlie, open source EDR☆30Updated last year
- Hundred Days of Yara Challenge☆12Updated 2 years ago
- ☆19Updated 4 months ago
- An extension of the sigma standard to include security metrics.☆15Updated last year
- Generate YARA rules for OOXML documents.☆38Updated last year
- Low budget VirusTotal Intelligence Cosplay☆20Updated 3 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Updated 4 years ago