williballenthin / python-dotnet-binaryformat
Pure Python parser for data encoded by .NET's BinaryFormatter
☆48Updated 6 years ago
Related projects: ⓘ
- Hansel - a simple but flexible search for IDA☆25Updated 5 years ago
- A python script that can be used to scan data within in an IDB using Yara.☆21Updated 6 years ago
- ☆57Updated this week
- Analysis PE file or Shellcode☆48Updated 8 years ago
- Maltego transforms to pivot between PE files based on their VirusTotal codeblocks☆18Updated 3 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆38Updated 4 years ago
- ☆33Updated this week
- Tools for inspecting YARA bytecode☆15Updated 4 years ago
- A collection of Volatility Framework plugins.☆26Updated 11 years ago
- Flare-On solutions☆36Updated 4 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆52Updated 6 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆73Updated 9 years ago
- ☆51Updated 6 years ago
- ANBU (Automatic New Binary Unpacker) a tool for me to learn about PIN and about algorithms for generic unpacking.☆88Updated 5 years ago
- Use this library to automatically extract PE files compressed with aplib from a binary blob.☆32Updated 5 years ago
- pyGoRE - Python library for analyzing Go binaries☆63Updated 2 years ago
- Go Lang Portable Executable Parser☆37Updated 3 years ago
- QEMU with rVMI extensions☆25Updated 7 years ago
- ☆22Updated 5 years ago
- Framework to automatically test and explore the capabilities of generic AV engines☆70Updated 5 years ago
- Extract GUIDs from .NET assemblies☆21Updated 8 years ago
- ☆13Updated 3 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆72Updated 5 years ago
- ☆32Updated 3 months ago
- ☆35Updated this week
- ☆64Updated this week
- Yet another rule generator for Yara☆24Updated 4 years ago
- Random stuff for FlareOn☆13Updated 5 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago