seekbytes / MicroSCOPE
Static analysis tool that detects potential ransomware in PE and ELF files through heuristic analysis
☆18Updated last year
Alternatives and similar repositories for MicroSCOPE:
Users that are interested in MicroSCOPE are comparing it to the libraries listed below
- Go library to parse Executable and Linkable Format (ELF) files.☆47Updated 9 months ago
- My software engineering notes.☆18Updated last week
- Rust version of the objdir tool☆13Updated last year
- anti-ransomware file-system filter☆57Updated 7 months ago
- ☆21Updated 4 months ago
- Pure Go bindings for Zydis.☆10Updated 9 months ago
- Attack tool for altering packed samples so that they evade static packing detection☆16Updated 2 months ago
- ☆17Updated last month
- A tiny Windows hook library for x86/x64☆14Updated last year
- BlockChain antivirus☆9Updated last year
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- ☆25Updated last year
- A wrapper around Windows, calls explicitly the lowest possible calls☆13Updated 2 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- LLDB based debugger for Linux Kernel☆23Updated last week
- Lightweight x86-64 disassembling library☆41Updated 2 years ago
- A C++ tool to inspect and extract contents from PyInstaller archives☆10Updated last month
- A curated list of awesome resources related to anti virtualization techniques☆44Updated this week
- Code used in blog posts☆34Updated 8 months ago
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆19Updated last year
- rpv-web is a browser based frontend for the rpv library☆24Updated last week
- Easy encrypt/decrypt data with TPM☆25Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- rpv is a v library for analyzing RPC servers and interfaces on the Windows operating system☆32Updated last week
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆19Updated 6 months ago
- Leveraging TPM2 TCG Logs (Measured Boot) to Detect UEFI Drivers and Pre-Boot Applications☆15Updated 2 weeks ago
- Signature finder (from PE-bear)☆36Updated 10 months ago
- Native Rust bindings for @horsicq's Detect-It-Easy☆13Updated 2 months ago
- Practical Reverse Engineering book exercises☆9Updated 4 years ago