stellarbear / YaraSharp
C# wrapper around the Yara pattern matching library
☆36Updated 2 years ago
Alternatives and similar repositories for YaraSharp:
Users that are interested in YaraSharp are comparing it to the libraries listed below
- .NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects☆53Updated 5 months ago
- A simple utility to list all methods of a given .NET Assembly and to invoke them☆72Updated 3 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆51Updated 6 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆33Updated 8 years ago
- Framework for C# development☆71Updated last month
- Dump certificates from PE files in different formats☆38Updated last year
- Implementation of the .NET Profiler DLL hijack in C#☆98Updated 6 years ago
- A multi-platform .Net wrapper library for the native Yara library.☆38Updated last year
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆30Updated 4 years ago
- A manual system call library that supports functions from both ntdll.dll and win32u.dll☆107Updated last year
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆63Updated 3 years ago
- .NET executable packer☆60Updated 6 years ago
- Win32 memory leak detector with ETW☆41Updated 7 years ago
- Bare template for a Kernel Mode Driver☆51Updated 4 years ago
- Simple packer for arbitrary data using only .NET API calls. Produces a unique signature with every usage. Standalone program and library.…☆90Updated 5 years ago
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆39Updated 5 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- Small visualizator for PE files☆67Updated last year
- The evolution of NxRansomware☆10Updated 5 years ago
- .NET instrumentation framework☆72Updated 7 years ago
- Lnk file parser☆79Updated last week
- ☆22Updated 3 years ago
- ☆43Updated last year
- Parse .NET executable files.☆74Updated 2 months ago
- ☆61Updated last week
- Library of tools and examples for loading/bootstrapping managed code from unmanaged code in .NET☆62Updated 5 years ago
- IDAPython scripts☆15Updated 7 years ago
- A ready-made template for a project based on libpeconv.☆43Updated 2 months ago
- JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.☆50Updated 4 years ago