seekbytes / MicroSCOPE
Static analysis tool that detects potential ransomware in PE and ELF files through heuristic analysis
☆18Updated last year
Alternatives and similar repositories for MicroSCOPE:
Users that are interested in MicroSCOPE are comparing it to the libraries listed below
- Go library to parse Executable and Linkable Format (ELF) files.☆48Updated 10 months ago
- Native Rust bindings for @horsicq's Detect-It-Easy☆15Updated 3 months ago
- My software engineering notes.☆18Updated last week
- Attack tool for altering packed samples so that they evade static packing detection☆17Updated 3 months ago
- Very simple cross-platform utility to manage your git identities.☆10Updated 2 years ago
- Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.☆16Updated 5 years ago
- A Linux x86/x86-64 tool to trace registers and memory regions.☆37Updated 2 years ago
- ☆15Updated 2 years ago
- Pure Go bindings for Zydis.☆11Updated 9 months ago
- Practical Reverse Engineering book exercises☆9Updated 4 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Visualizing Mach-O Loads Recursively using Graphviz☆16Updated last year
- Lightweight x86-64 disassembling library☆41Updated 2 years ago
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- Collection of Windows Driver Utils☆11Updated last year
- ugly code to check linux kernel memory and dump some internal structures☆46Updated 5 months ago
- AMD SVM hypervisor rootkit proof of concept☆46Updated last year
- A wrapper around Windows, calls explicitly the lowest possible calls☆13Updated 2 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- A parser for Microsoft PDB (Program Database) debugging information☆27Updated 6 months ago
- hypervisor enforced patch protection for the linux kernel with xen + libvmi, libvmi KASLR offset spoofer☆32Updated last year
- Collaboration platform for reverse engineering tools.☆40Updated 4 months ago
- A tiny library to properly encrypt IP addresses.☆16Updated this week
- Rizin FLIRT Signature Database☆40Updated last year
- IDA's Lumina feature, reimplemented for Ghidra☆22Updated last year
- Fetch PDB symbols directly from Microsoft's symbol servers☆41Updated 3 years ago
- .NET Tool for parsing and utilizing x86 semantics defined in K. It currently features a WIP symbolic expression generator for VTIL.☆16Updated 4 years ago
- Probably the first binary (PE/ELF) infector ever created in GoLang.☆50Updated 2 years ago
- Find RSA primes in files☆20Updated 2 years ago