
Process-Dump
Windows tool for dumping malware PE files from memory back to disk for analysis.
binary-analysisforensicsmalware-analysis+2
1.9k7 days ago

Windows tool for dumping malware PE files from memory back to disk for analysis.

Quickly find differences and similarities in disassembled code

Pishi is a code coverage tool like kcov for macOS.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Static Binary Instrumentation tool for Windows x64 executables

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

A frida tool to dump dex in memory to support security engineers analyzing malware.