hasherezade
hasherezade's tracked open-source repos, sorted by stars.
- #1
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
★ 3,879+12Star change over the last 7 days - #2★ 3,790+8Star change over the last 7 days
- #3
Converts PE into a shellcode
★ 2,793+0Star change over the last 7 days - #4
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
★ 2,402+1Star change over the last 7 days - #5
Materials for Windows Malware Analysis training (volume 1)
★ 2,103+4Star change over the last 7 days - #6
A Pin Tool for tracing API calls etc
★ 1,695+2Star change over the last 7 days - #7
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl
★ 1,387+2Star change over the last 7 days - #8
Converts a EXE into DLL
★ 1,373+0Star change over the last 7 days - #9
Dynamic unpacker based on PE-sieve
★ 837+1Star change over the last 7 days - #10
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
★ 699+0Star change over the last 7 days - #11
Portable Executable parsing library (from PE-bear)
★ 656+0Star change over the last 7 days - #12
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging
★ 587+0Star change over the last 7 days