Stars
4
stars
written in C++
Clear filter
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
自动化找白文件,用于扫描 EXE 文件的导入表,列出导入的DLL文件,并筛选出非系统DLL,符合条件的文件将被复制到特定的 X64 或 X86 文件夹
复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》
🔬Collection of malware, ransomware, RATs, botnets, stealers, etc.