snemes / malware-analysis
☆23Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for malware-analysis
- ☆10Updated 4 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆21Updated 2 years ago
- TA505 unpacker Python 2.7☆46Updated 4 years ago
- Generates YARA rules to detect malware using API hashing☆17Updated 3 years ago
- Scripts, Yara rules and other files developed during malware investigations☆24Updated 2 years ago
- Specialized tool to dump Position Independent Code.☆21Updated 4 years ago
- ☆15Updated 2 years ago
- AMSI detection PoC☆30Updated 4 years ago
- Tools for playing w/ CobaltStrike config - extractin, detection, processing, etc...☆27Updated last year
- Yara rules☆19Updated last year
- Maltego transforms to pivot between PE files based on their VirusTotal codeblocks☆18Updated 3 years ago
- Walking the PEB in VBA☆22Updated 4 years ago
- Generate YARA rules for OOXML documents.☆37Updated last year
- ☆18Updated 4 years ago
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆21Updated last year
- pypykatz plugin for volatility3 framework☆31Updated 7 months ago
- A collection of threat intelligence data such as IOC, Yara and Snort/Suricata Rules etc.☆10Updated 5 years ago
- Python emulator for Excel XLM macros.☆18Updated 4 years ago
- Presentation materials for talks I've given.☆20Updated 5 years ago
- The repository accompanying the Buer Emulation workshop☆23Updated 3 years ago
- Links to malware-related YARA rules☆14Updated 2 years ago
- ☆13Updated 2 years ago
- C# User Simulation☆33Updated 2 years ago
- Liberating dem proprietary APT implants☆21Updated 4 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆41Updated 5 years ago
- A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique☆50Updated 5 years ago
- Protect your servers with a secret header☆28Updated 4 years ago
- ☆34Updated last year
- PE File Blessing - To continue or not to continue☆86Updated 4 years ago