
scan
0-day malware detection for binaries, source & scripts (that doesn't suck)

0-day malware detection for binaries, source & scripts (that doesn't suck)

Windows kernel driver experiment based on KasperskyHook that uses direct syscalls for interprocess memory copying, with support for unloading the…

A helper script for unpacking and decompiling EXEs compiled from python code.

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

x64 Dynamic Reverse Engineering Toolkit

Golang bindings for PE-sieve

Elastic Security Labs releases

Signature finder (from PE-bear)

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.