seekbytes / MicroSCOPE
Static analysis tool that detects potential ransomware in PE and ELF files through heuristic analysis
☆16Updated last year
Alternatives and similar repositories for MicroSCOPE:
Users that are interested in MicroSCOPE are comparing it to the libraries listed below
- EDR PoC WIP LLC☆11Updated last year
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Go library to parse Executable and Linkable Format (ELF) files.☆45Updated 8 months ago
- Standalone API for Binary Ninja's LLIL☆18Updated 7 months ago
- A C++ tool to inspect and extract contents from PyInstaller archives☆10Updated 2 weeks ago
- Rust version of the objdir tool☆12Updated last year
- Attack tool for altering packed samples so that they evade static packing detection☆16Updated last month
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 2 years ago
- ☆20Updated 3 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆77Updated 7 months ago
- Symbolic Execution based on lifting amd64 to z3☆26Updated 8 months ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆19Updated 5 months ago
- A parser for Microsoft PDB (Program Database) debugging information☆27Updated 4 months ago
- hypervisor enforced patch protection for the linux kernel with xen + libvmi, libvmi KASLR offset spoofer☆29Updated 11 months ago
- Native Rust bindings for @horsicq's Detect-It-Easy☆13Updated 2 months ago
- Easily search LLVM headers for all major versions!☆19Updated last month
- ☆38Updated 2 years ago
- Taking advantage of CRT initialization, to get away with hooking protected applications☆46Updated 2 years ago
- decryptor for nvdisasm☆12Updated this week
- Easy encrypt/decrypt data with TPM☆25Updated last year
- Generate Go bindings for shared C libraries.☆14Updated 8 months ago
- Native API header files for the Process Hacker project (nightly).☆26Updated this week
- Header-only C++ library for producing PE files.☆31Updated last year
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆23Updated 8 months ago
- Lightweight x86-64 disassembling library☆41Updated 2 years ago
- Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.☆16Updated 5 years ago
- Input-output driver☆24Updated last week
- Very simple cross-platform utility to manage your git identities.☆10Updated 2 years ago
- Signature finder (from PE-bear)☆32Updated 9 months ago