hasherezade

Results 61 repositories owned by hasherezade

pe-bear-releases

763
Stars
73
Forks
Watchers

PE-bear (builds only)

chimera_pe

213
Stars
57
Forks
Watchers

ChimeraPE (a PE injector type - alternative to: RunPE, ReflectiveLoader, etc) - a template for manual loading of EXE, loading imports payload-side

ida_ifl

408
Stars
61
Forks
Watchers

IFL - Interactive Functions List (plugin for IDA Pro)

process_doppelganging

561
Stars
115
Forks
Watchers

My implementation of enSilo's Process Doppelganging (PE injection technique)

process_ghosting

605
Stars
113
Forks
Watchers

Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file

transacted_hollowing

497
Stars
72
Forks
Watchers

Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging

antianalysis_demos

124
Stars
22
Forks
Watchers

Set of antianalysis techniques found in malware

exe_to_dll

1.2k
Stars
178
Forks
Watchers

Converts a EXE into DLL

malware_analysis

451
Stars
123
Forks
Watchers

Various snippets created during malware analysis