
NtWarden
Windows Analysis and Research Toolkit
binary-analysisdefensive-toolsdigital-forensics+4
6794 months ago

Windows Analysis and Research Toolkit

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

Technical Analysis of Bibi-Windows Wiper Targeting Israeli Organizations

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…