serializingme / emofishesLinks
Emofishes is a collection of proof-of-concepts that help improve, bypass or detect virtualized execution environments (focusing on the ones setup for malware analysis).
☆15Updated 2 years ago
Alternatives and similar repositories for emofishes
Users that are interested in emofishes are comparing it to the libraries listed below
Sorting:
- Work Fast With the pattern matching swiss knife for malware researchers.☆38Updated 9 years ago
- POC for IAT Parsing Payloads☆48Updated 9 years ago
- This script is used for extracting DDE in docx and xlsx☆12Updated 8 years ago
- A simple reflective dll example☆19Updated 9 years ago
- Environmental (and http) keying for scripting languages☆39Updated 7 years ago
- Making shellcode UD - https://osandamalith.com☆25Updated 9 years ago
- Python based module to find common vulnerabilities which lead to Windows privilege escalation☆30Updated 9 years ago
- Network detector for Winnti malware☆21Updated 7 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆40Updated 7 years ago
- Nano meterpreter shell based on TinyMet☆28Updated 9 years ago
- PowerShell Empire module for logging USB keystrokes via ETW☆32Updated 9 years ago
- A Generic Windows Memory Scraping Tool☆71Updated 8 years ago
- List of scripts used for malware analysis☆15Updated 10 years ago
- ☆18Updated 7 years ago
- Memory searching utilities☆43Updated 12 years ago
- ☆22Updated 8 years ago
- ☆53Updated 10 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆88Updated 8 years ago
- Talk given at DerbyCon and RuxCon 2016☆23Updated 9 years ago
- Mimikatz HashClash☆12Updated 10 years ago
- ☆10Updated 8 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆100Updated 6 years ago
- API Tracker by Cysinfo Team☆22Updated 9 years ago
- Fileless SQL Server CLR-based Custom Stored Procedure Command Execution☆35Updated 8 years ago
- Reverse to use in a batfile which can call the ip and ports from itself☆25Updated 5 years ago
- Powershell Persistence Locator☆66Updated 9 years ago
- Resolves DLL API entrypoints for a process w/ remote query capabilities.☆58Updated 8 years ago
- McAfee ePolicy 0wner exploit code☆46Updated 7 years ago
- Mixing up CVE and MS like a pro☆25Updated 8 years ago
- A multi-purpose meterpreter executable (inline, many transports, msfpayload)☆81Updated 7 years ago