halsten's Stars
killbug2004/insight
A(nother) Binary Analysis Framework
killbug2004/PErmutator
killbug2004/compressor2
Automatically exported from code.google.com/p/compressor2
killbug2004/pescrambler
Automatically exported from code.google.com/p/pescrambler
killbug2004/accessch
Automatically exported from code.google.com/p/accessch
SLAUC91/RealisticMouse
Realistic Mouse Movement (C++)
SLAUC91/PatternScanner
Byte Pattern Scanner
SLAUC91/SDS
Software Distribution Service
killbug2004/Winbagility
Debug Windows in non debug mode !
killbug2004/x64emu
x86_x64 emulator
killbug2004/diskflt
Automatically exported from code.google.com/p/diskflt
tandasat/meow
nyā
cgutman/NTcloak
Filter manager minifilter and user-mode control program example
Nukem9/VirtualDbg
Test code only. Not reliable for actual use.
Nukem9/VirtualDbgHide
Windows kernel mode driver to prevent detection of debuggers.
xiaoweime/WProtect
slavaim/MacOSX-Kernel-Filter
A Mac OS X kernel mode filter driver ( a kernel extension ) for devices, file systems and network
googleprojectzero/sandbox-attacksurface-analysis-tools
Set of tools to analyze Windows sandboxes for exposed attack surface.
JonDoNym/peinjector
peinjector - MITM PE file infector
BromiumLabs/PackerAttacker
C++ application that uses memory and code hooks to detect packers
baderj/domain_generation_algorithms
Some results of my DGA reversing efforts
unicorn-engine/unicorn
Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
rpp0/scapy-fakeap
Fake wireless Access Point (AP) implementation using Python and Scapy, intended for convenient testing of 802.11 protocols and implementations.
rpp0/aggr-inject
Remote frame injection PoC by exploiting a standard compliant A-MPDU aggregation vulnerability in 802.11n networks.
uxmal/reko
Reko is a binary decompiler.
tandasat/PgResarch
PatchGuard Research
tandasat/RemoteWriteMonitor
A tool to help malware analysts tell that the sample is injecting code into other process.
tandasat/Scavenger
A minifilter driver preserves all modified and deleted files.
9ee1/Capstone.NET
.NET Core and .NET Framework binding for the Capstone Disassembly Framework