Repository navigation

#

pefile

PE Tools - Portable executable (PE) manipulation toolkit

1092
7 年前

Automatic and platform-independent unpacker for Windows binaries based on emulation

Python
689
7 个月前

Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file

C
657
1 年前

Portable Executable (PE) library written in .Net

C#
611
4 天前

Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging

C
543
1 年前
Jupyter Notebook
127
6 年前

POC of a better implementation of GetProcAddress for ntdll using binary search

C
109
1 年前

A Malware classifier dataset built with header fields’ values of Portable Executable files

YARA
90
2 年前

A Machine Learning approach for classifying a file as Malicious or Legitimate

Jupyter Notebook
76
9 年前

PE Binary Shellcode Injector - Automated code cave discovery, shellcode injection, ASLR bypass, x86/x64 compatible

Python
75
5 年前
Python
69
2 年前

Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping

C
54
3 年前

Dump certificates from PE files in different formats

C#
38
1 年前

A malware dataset curation tool which helps identify packed samples.

Python
32
6 年前

Golang port of pefile

Python
23
8 年前

Hex Workshop editor's structure library for the Microsoft's Portable Executable format.

17
6 年前