
WhoamiAlternatives
Different methods to get current username without using whoami

Different methods to get current username without using whoami

Automated vulnerability, misconfiguration, and rootkit scanner for AWS EC2 instances using Vuls, Lynis, and Chkrootkit via snapshot-based offline…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Signature finder (from PE-bear)

GreyEnergy Mini Module Malware Analysis (Turkish)

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

A frida tool to dump dex in memory to support security engineers analyzing malware.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Community-maintained Volatility plugin collection for memory forensics, extending memory dump analysis with modules for malware and process…

Live hunting of code injection techniques

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Enumerates Windows timer-queue timers to detect Ekko sleep obfuscation, aiding memory forensics and malware analysis in identifying evasive…

Live memory analysis tool for detecting reflectively loaded .NET DLLs by scanning process memory regions for abnormal flags, page types, and PE…