Skip to main content
buildradar
Sign in
Owner · hasherezade

hasherezade

hasherezade's tracked open-source repos, sorted by stars.

12 repos
  • pe-sieve@hasherezade

    Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

    3,879+12Star change over the last 7 days
  • pe-bear@hasherezade

    Portable Executable reversing tool with a friendly GUI

    3,790+8Star change over the last 7 days
  • pe_to_shellcode@hasherezade

    Converts PE into a shellcode

    2,793+0Star change over the last 7 days
  • hollows_hunter@hasherezade

    Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

    2,402+1Star change over the last 7 days
  • malware_training_vol1@hasherezade

    Materials for Windows Malware Analysis training (volume 1)

    2,103+4Star change over the last 7 days
  • tiny_tracer@hasherezade

    A Pin Tool for tracing API calls etc

    1,695+2Star change over the last 7 days
  • libpeconv@hasherezade

    A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl

    1,387+2Star change over the last 7 days
  • exe_to_dll@hasherezade

    Converts a EXE into DLL

    1,373+0Star change over the last 7 days
  • mal_unpack@hasherezade

    Dynamic unpacker based on PE-sieve

    837+1Star change over the last 7 days
  • process_ghosting@hasherezade

    Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file

    699+0Star change over the last 7 days
  • bearparser@hasherezade

    Portable Executable parsing library (from PE-bear)

    656+0Star change over the last 7 days
  • Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging

    587+0Star change over the last 7 days
← Back to owner ranking