跳到主要內容
buildradar
Sign in
擁有者 · hasherezade

hasherezade

hasherezade 收錄中的開源專案,依星數排序。

共 12 個專案
  • pe-sieve@hasherezade

    掃描指定進程。識別並轉儲各種潛在惡意植入物(替換/注入 PE、shellcode、掛鉤、內存補丁)

    3,879+5近 7 天星數變化
  • pe-bear@hasherezade

    可攜式可執行文件逆向工具,帶友好 GUI

    3,790+5近 7 天星數變化
  • pe_to_shellcode@hasherezade

    將 PE 轉換為 shellcode

    2,793+1近 7 天星數變化
  • hollows_hunter@hasherezade

    掃描所有執行中的行程。辨識並傾印各種潛在的惡意植入物(被替換/植入的 PE、shellcode、hook、記憶體修補)。

    2,402+0近 7 天星數變化
  • malware_training_vol1@hasherezade

    Windows 惡意軟體分析培訓教材(第一冊)

    2,103+1近 7 天星數變化
  • tiny_tracer@hasherezade

    用於追蹤 API 呼叫等的 Pin Tool

    1,695+2近 7 天星數變化
  • libpeconv@hasherezade

    用於載入、操作、傾印 PE 檔案的程式庫。另見:https://github.com/hasherezade/libpeconv_tpl

    1,387+2近 7 天星數變化
  • exe_to_dll@hasherezade

    將 EXE 轉換為 DLL

    1,373-1近 7 天星數變化
  • mal_unpack@hasherezade

    基於 PE-sieve 的動態脫殼工具

    838+1近 7 天星數變化
  • process_ghosting@hasherezade

    Process Ghosting 是一種 PE 注入技術,類似於 Process Doppelgänging,但使用等待刪除(delete-pending)的檔案而非交易檔案

    699-1近 7 天星數變化
  • bearparser@hasherezade

    Portable Executable 解析函式庫(源自 PE-bear)

    656+0近 7 天星數變化
  • Transacted Hollowing - 一種 PE 注入技術,結合了 ProcessHollowing 與 ProcessDoppelgänging 的混合技術

    587+1近 7 天星數變化
← 返回擁有者排行