Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
amcache-evilhunter — 解析和分析 Windows Amcache.hve 注册表配置单元,VirusTotal 集成。 | Kitploit
工具/GitHubGitHub/cristianzsh/amcache-evilhunter
取证分析恶意软件分析数字取证威胁情报事件响应
GitHubcristianzsh/amcache-evilhunter

amcache-evilhunter

解析和分析 Windows Amcache.hve 注册表配置单元,VirusTotal 集成。

查看仓库
1148162天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

AmCache-EvilHunter

AmCache-EvilHunter 是一个命令行工具,用于解析和分析 Windows Amcache.hve 注册表配置单元,识别执行痕迹、可疑可执行文件,并集成 VirusTotal/OpenTIP 查询以增强威胁情报。

https://github.com/user-attachments/assets/e23fb99b-48ad-4260-b372-2f15e5320c74

功能特性

  • 解析离线 Amcache.hve 注册表配置单元。
  • 按日期范围筛选记录(--start、--end)。
  • 使用关键词搜索记录(--search)。
  • 识别已知的可疑可执行文件(--find-suspicious)。
  • 识别没有发布者的可执行文件(--missing-publisher)。
  • 集成 Kaspersky OpenTIP 进行哈希查询(--opentip、--only-detections)。
  • 集成 VirusTotal 进行哈希查询(--vt、--only-detections)。
  • 将结果导出为 JSON(--json)或 CSV(--csv)。

环境要求

  • Python 3.7 或更高版本
  • requests
  • python-registry
  • rich

通过 pip 安装依赖:

pip3 install -r requirements.txt

安装

git clone https://github.com/cristianzsh/amcache-evilhunter.git
cd amcache-evilhunter
pip3 install -r requirements.txt

使用方法

python3 amcache_evilhunter.py -i path/to/Amcache.hve [OPTIONS]

选项

参数描述
-i, --input PATHAmcache.hve 的路径(必填)
--start YYYY-MM-DD仅包含此日期当天或之后的记录
--end YYYY-MM-DD仅包含此日期当天或之前的记录
--search TERMS逗号分隔、不区分大小写的搜索词
--find-suspicious仅筛选匹配已知可疑模式的记录
--missing-publisher仅筛选缺少 Publisher 的记录
--exclude-os仅包含非操作系统组件文件
--opentip启用 Kaspersky OpenTIP 查询(需要 OPENTIP_API_KEY 环境变量)
-v, --vt启用 VirusTotal 查询(需要 VT_API_KEY 环境变量)
--only-detections仅显示/保存具有 ≥1 个 VT 检测的文件
--json PATH写入完整 JSON 输出的路径
--csv PATH写入完整 CSV 输出的路径
-V, --version显示版本信息

示例

  • 解析并显示所有记录:

    python3 amcache_evilhunter.py -i Amcache.hve
    
  • 按日期范围筛选并搜索 "notepad":

    python3 amcache_evilhunter.py -i Amcache.hve --start 2021-01-01 --end 2021-12-31 --search notepad
    
  • 识别可疑可执行文件并查询 VirusTotal:

    python3 amcache_evilhunter.py -i Amcache.hve --find-suspicious -v
    
  • 将 VirusTotal 检测结果导出为 JSON:

    export VT_API_KEY=YOUR_API_KEY
    python3 amcache_evilhunter.py -i Amcache.hve -v --only-detections --json detections.json
    

环境变量

  • VT_API_KEY:用于文件哈希查询的 VirusTotal API 密钥。
  • OPENTIP_API_KEY:用于文件哈希查询的 OpenTIP API 密钥。

构建可执行文件

提供了 build.sh 脚本,用于为 Linux 和 Windows(通过 Wine)生成独立二进制文件。

chmod +x build.sh
./build.sh

如何引用本工作

AmCache-EvilHunter 已在第 XXVI 届巴西网络安全研讨会(SBSeg 2026)上展示。

@inproceedings{souza2026amcache,
  author = {Cristian Souza and Eduardo Chavarro and Daniel Batista},
  title = {AmCache-EvilHunter: Automating Evidence of Execution Extraction from the Amcache.hve Artifact},
  booktitle = {Anais Estendidos do XXVI Simpósio Brasileiro de Cibersegurança},
  location = {Armação dos Búzios/RJ},
  year = {2026},
  pages = {100--108},
  publisher = {SBC},
  address = {Porto Alegre, RS, Brasil},
  doi = {10.5753/sbseg_estendido.2026.33555},
  url = {https://sol.sbc.org.br/index.php/sbseg_estendido/article/view/44456}
}

许可证

本项目采用 MIT 许可证。详情请参阅 LICENSE。

下载工具