
inspec_cve_2019_15224
Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

A script to detect stack-strings by using emulation (leveraging Unicorn)

Golang bindings for PE-sieve

.NET deobfuscator and unpacker.

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Django application that performs SAST and Malware Analysis for Android APKs

A ProcessMonitor visualization application written in rust.

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox.