Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff
☆56Sep 15, 2025Updated last year
Alternatives and similar repositories for KnowledgeBase
Users that are interested in KnowledgeBase are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Apr 10, 2022Updated 4 years ago
- a simple python script to de-obfuscate ABOBUS Batch script obfuscator☆10Jan 2, 2025Updated last year
- UnpacMe IDA Byte Search☆29Nov 20, 2023Updated 2 years ago
- Defeating Anti-Debugging Techniques for Malware Analysis☆12Oct 1, 2022Updated 3 years ago
- ☆12Jun 29, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆75Nov 30, 2023Updated 2 years ago
- How to retro theme your Ghidra☆36Feb 24, 2026Updated 6 months ago
- A tool for de-obfuscating PowerShell scripts☆71Apr 24, 2019Updated 7 years ago
- Threat Box Assessment Tool☆19Mar 5, 2026Updated 6 months ago
- ☆25Jan 8, 2024Updated 2 years ago
- This repository contains files from AppGate / Immunity Malware Analysis Team.☆21Oct 19, 2021Updated 4 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆67Aug 23, 2023Updated 3 years ago
- A small tool to unmap PE memory dumps.☆11Nov 9, 2023Updated 2 years ago
- Frida example to trace VBA CreateObject calls and some string deobfuscations calls. You need latest Frida 12.9.8 for improved symbol look…☆25Sep 3, 2020Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Unpacking and decryption tools for the Emotet malware☆44Dec 5, 2021Updated 4 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆121Apr 8, 2023Updated 3 years ago
- function identification signatures☆12Apr 26, 2021Updated 5 years ago
- shared samples from #dailyphish and/or #apt tweets☆42Sep 3, 2025Updated last year
- AutoIt Analysis Library: Parser & Emulator For Malware Researchers☆22Apr 27, 2019Updated 7 years ago
- Ida Pro plugin to aid in reverse engineering Rust binaries.☆20Dec 9, 2024Updated last year
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Jul 9, 2023Updated 3 years ago
- ☆32Apr 24, 2022Updated 4 years ago
- Various short scripts and tools used for Digital Forensics☆14Jul 9, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Rules Shared by the Community from 100 Days of YARA 2023 -☆19Apr 10, 2023Updated 3 years ago
- Generate YARA rules from Windows API hashes for malware detection and hunting.☆17Aug 11, 2026Updated last month
- EvtPsst☆55Oct 24, 2023Updated 2 years ago
- A simple utility to list all methods of a given .NET Assembly and to invoke them☆73Sep 21, 2021Updated 5 years ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆24Oct 9, 2024Updated last year
- Example of CRUSH compression with optimal parsing using BriefLZ algorithms☆16Nov 1, 2023Updated 2 years ago
- Extension functionality for the NightHawk operator client☆26Oct 31, 2023Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆75Apr 18, 2024Updated 2 years ago
- ☆13Oct 29, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Rust library along with a Win32 GUI application to determine the driver load order of a Windows system (cf. https://colinfinck.de/posts…☆13Jan 26, 2025Updated last year
- ☆13Jun 20, 2013Updated 13 years ago
- a PE Loader and Windows API tracer. Useful in malware analysis.☆143Sep 19, 2022Updated 4 years ago
- miscellaneous codes☆38Sep 24, 2023Updated 2 years ago
- ☆19Aug 6, 2021Updated 5 years ago
- Scripts, Yara rules and other files developed during malware investigations☆28Aug 19, 2022Updated 4 years ago
- Research into removing strings & API call references at compile-time (Anti-Analysis)☆27Jun 2, 2024Updated 2 years ago