STrace
flare-floss
STrace | flare-floss | |
---|---|---|
2 | 4 | |
308 | 3,024 | |
0.6% | 1.3% | |
7.8 | 9.2 | |
23 days ago | 4 days ago | |
C++ | Python | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
STrace
-
DTrace-on-Windows: Code for the cross platform, OpenDTrace implementation
While amazing, this Microsoft implementation has some limitations. See my adaptation / reimplementation here https://github.com/mandiant/STrace
- STrace: MIT Licensed Windows Reimplementation of DTrace
flare-floss
-
Why is this de-compiled code showing a different value in memory sometimes?
Depending on how clever the developer was, this tool works well to find hidden strings: https://github.com/mandiant/flare-floss
-
Static Analysis Research - Windows PE
Recently, I decided do delve a little bit more into static analysis, something beyond just running strings on a binary and getting the ASCII characters that are printable. I decided to take a deep look at how FLOSS is working and possibly recreate some of its functionality in my own tool.
- Hogy lehet észrevenni, ha valaki bejár a gépedre és adatot visz ki? KRÉTA sztori spin-off
- Installed Kaspersky today, Trojan.Win32.Hosts2.gen detected. Malwarebytes and Windows Defender didn’t detected it before. False positive?
What are some alternatives?
capa - The FLARE team's open-source tool to identify capabilities in executable files.
yara - The pattern matching swiss knife
gsoc - NumFOCUS Google Summer of Code Materials
flare-fakenet-ng - FakeNet-NG - Next Generation Dynamic Network Analysis Tool
win32-shellcode - Win32 Shellcode CheatSheet: Your visual guide for crafting and understanding shellcode. Ideal for malware, and exploit developers
pytextcodifier - :package: Turn your text files into codified images or your codified images into text files.
peresources
Microsoft-Activation-Scripts - A collection of scripts for activating Microsoft products using HWID / KMS38 / Online KMS activation methods with a focus on open-source code, less antivirus detection and user-friendliness.