Defeating Anti-Debugging Techniques for Malware Analysis
☆12Oct 1, 2022Updated 3 years ago
Alternatives and similar repositories for Antidebug
Users that are interested in Antidebug are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This repository contains several AMSI bypasses. These bypasses are based on some very nice research that has been put out by some awesome…☆23Jul 7, 2022Updated 4 years ago
- ☆18Sep 24, 2024Updated last year
- ☆35Dec 21, 2023Updated 2 years ago
- Lazy SPL to detect Spring4Shell exploitation☆12Jul 8, 2022Updated 4 years ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆65Apr 4, 2026Updated 4 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A payload delivery system which embeds payloads in an executable's icon file!☆74Jan 26, 2024Updated 2 years ago
- Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.☆11May 17, 2024Updated 2 years ago
- My malware analysis code snippets☆28Jul 15, 2023Updated 3 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Oct 10, 2022Updated 3 years ago
- Source Code of MSIL Ransom☆14Feb 11, 2023Updated 3 years ago
- simple C# portscanner - written for playing around with Metasploit's Execute-Assembly☆10Jul 1, 2023Updated 3 years ago
- ☆27Jul 11, 2022Updated 4 years ago
- Windows malware analysis logging tool.☆15May 28, 2016Updated 10 years ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆32Nov 1, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Jul 9, 2023Updated 3 years ago
- Emulator for Windows Malware Analysis☆15Feb 26, 2022Updated 4 years ago
- Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff☆56Sep 15, 2025Updated 11 months ago
- Grepify the GUI Regex Text Scanner for Code Reviewers☆23Apr 15, 2013Updated 13 years ago
- Bypass Malware Time Delays☆105Sep 23, 2022Updated 3 years ago
- Windows symbol tables for Volatility 3☆99Jul 11, 2024Updated 2 years ago
- ☆19Jul 29, 2022Updated 4 years ago
- Nemo - An offensive Remote Access Tool & Post-Exploitation Framework (WIP).☆14Apr 25, 2023Updated 3 years ago
- Remote process shellcode injection with interactive output via named pipes☆51Jan 10, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows Persistence Toolkit in C#☆37Sep 23, 2022Updated 3 years ago
- Simple POC of Voice C2 using Speech Recognition☆13Apr 27, 2022Updated 4 years ago
- ☆47Feb 11, 2023Updated 3 years ago
- My personal tech blog☆17Dec 13, 2024Updated last year
- Various code samples and useful tips and tricks from reverse engineering and malware analysis fields.☆107Jun 11, 2025Updated last year
- A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis☆13Mar 22, 2022Updated 4 years ago
- Loading and executing shellcode in C# without PInvoke.☆22Jan 10, 2022Updated 4 years ago
- Simple and sane compression wrapper library.☆19Oct 28, 2022Updated 3 years ago
- Shellcode Loader / bypass *60、*rong☆15Dec 1, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- PoC MSI payload based on ASEC/AhnLab's blog post☆25Sep 19, 2022Updated 3 years ago
- UPX - the Ultimate Packer for eXecutables☆68Mar 9, 2022Updated 4 years ago
- Duplicate not owned Token from Running Process☆74Jul 21, 2023Updated 3 years ago
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Apr 10, 2022Updated 4 years ago
- Extension functionality for the NightHawk operator client☆27Oct 31, 2023Updated 2 years ago
- Tool to retrieve Config from Redline C2 servers☆16Mar 14, 2023Updated 3 years ago
- ☆18Dec 9, 2023Updated 2 years ago