Repository navigation
anti-emulation
- Website
- Wikipedia
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into categories for ease of searching and understanding. Also provided are code samples, signature recommendations and countermeasures within each category for the described techniques.
This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or analysis tools
.Net Framweork and .Net Core Anti Debugging to stop multiple malicious tools and hooks on your software.
ice9 - is anticheat based on usermode tricks and undocumented methods , builded as dll for loading trought the shibari framework
Some anti QEMU trick used by in-the-wild malware.
Attempts to trick malware using techniques from NavyTitanium/Fake-Sandbox-Artifacts