跳到主要内容
buildradar
登录
所有者 · hasherezade

hasherezade

hasherezade 收录中的开源项目,按星标数排序。

共 12 个项目
  • pe-sieve@hasherezade

    扫描指定进程。识别并转储各种潜在恶意植入物(替换/注入 PE、shellcode、挂钩、内存补丁)

    3,879+0近 7 天星标变化
  • pe-bear@hasherezade

    可携式可执行文件逆向工具,带友好 GUI

    3,790+0近 7 天星标变化
  • pe_to_shellcode@hasherezade

    将 PE 转换为 shellcode

    2,793+0近 7 天星标变化
  • hollows_hunter@hasherezade

    扫描所有运行中的进程。识别并转储各种潜在的恶意植入物(被替换/植入的 PE、shellcode、hook、内存补丁)。

    2,402+0近 7 天星标变化
  • malware_training_vol1@hasherezade

    Windows 恶意软件分析培训教材(第一册)

    2,103+0近 7 天星标变化
  • tiny_tracer@hasherezade

    用于追踪 API 调用等的 Pin Tool

    1,695+0近 7 天星标变化
  • libpeconv@hasherezade

    用于加载、操作、转储 PE 文件的库。另见:https://github.com/hasherezade/libpeconv_tpl

    1,387+0近 7 天星标变化
  • exe_to_dll@hasherezade

    将 EXE 转换为 DLL

    1,373+0近 7 天星标变化
  • mal_unpack@hasherezade

    基于 PE-sieve 的动态脱壳工具

    838+1近 7 天星标变化
  • process_ghosting@hasherezade

    Process Ghosting 是一种 PE 注入技术,类似于 Process Doppelgänging,但使用等待删除(delete-pending)的文件而非事务文件

    699-1近 7 天星标变化
  • bearparser@hasherezade

    Portable Executable 解析库(源自 PE-bear)

    656+0近 7 天星标变化
  • Transacted Hollowing - 一种 PE 注入技术,结合了 ProcessHollowing 与 ProcessDoppelgänging 的混合技术

    587+1近 7 天星标变化
← 返回所有者排行