ThreatCheck
ThreatCheck copied to clipboard
Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.
This merge requests implements correct labeling of the hex output, regarding the found malicious block and its appearance. See the left-side oft the following screenshots as an example: Before: ...
Since Windows Defender detects the copied file being analyzed in C:\Temp, I added support to pass a parameter (-b) used to set a custom path. Follows the error I encountered...
.NET Framework 4.0 is no longer supported. This PR: * Bumps .NET Framework 4.0 -> 4.8 * Bumps `CommandLineParser` to 4.8 target and version bumps it