pe-sieve
hollows_hunter
pe-sieve | hollows_hunter | |
---|---|---|
1 | 4 | |
2,890 | 1,877 | |
- | - | |
8.6 | 8.3 | |
26 days ago | 26 days ago | |
C++ | C | |
BSD 2-clause "Simplified" License | BSD 2-clause "Simplified" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
pe-sieve
-
PE-Sieve and Hollows Hunter v0.3.3
Releases · hasherezade/pe-sieve · GitHub
hollows_hunter
- Rileva hollow code injection in windows
-
Is it possible a spyware can hide it's processes in task manager details and in services tab?
To detect such modules we can use https://github.com/hasherezade/hollows_hunter
- Hollows Hunter – Scans all running processes
-
PE-Sieve and Hollows Hunter v0.3.3
Release v0.3.3 · hasherezade/hollows_hunter · GitHub
What are some alternatives?
Microsoft Research Detours Package - Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
mal_unpack - Dynamic unpacker based on PE-sieve
dll_to_exe - Converts a DLL into EXE
Pentest-Notes - Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)
XPEViewer - PE file viewer/editor for Windows, Linux and MacOS.
radare2 - UNIX-like reverse engineering framework and command-line toolset [Moved to: https://github.com/radareorg/radare2]
pe-bear - Portable Executable reversing tool with a friendly GUI
hem-hashes - Hiew External Module (HEM) to calculate CRC-32, MD5, SHA-1, and SHA-256 hashes of a given file/block
orbit - C/C++ Performance Profiler
YAMA - Yet Another Memory Analyzer for malware detection