hasherezade
hasherezade
chimera_pe
ChimeraPE (a PE injector type - alternative to: RunPE, ReflectiveLoader, etc) - a template for manual loading of EXE, loading imports payload-side
ida_ifl
IFL - Interactive Functions List (plugin for IDA Pro)
process_doppelganging
My implementation of enSilo's Process Doppelganging (PE injection technique)
process_ghosting
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
transacted_hollowing
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging
mal_unpack
Dynamic unpacker based on PE-sieve
antianalysis_demos
Set of antianalysis techniques found in malware
malware_analysis
Various snippets created during malware analysis