Skip to content
View UIWP0's full-sized avatar
🤏
Out sick
🤏
Out sick

Block or report UIWP0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Hunter

恶意软件检测/防护/识别
39 repositories

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade analysis. Guaranteed to bring down your pafish ratings…

PowerShell 293 26 Updated Apr 9, 2023

🦆 Malduck is your ducky companion in malware analysis journeys

Python 327 30 Updated Jun 19, 2024

Collaborative forensic timeline analysis

Python 2,729 606 Updated Apr 14, 2025

Malcom - Malware Communications Analyzer

Python 1,158 216 Updated Nov 29, 2017

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

C# 1,179 142 Updated Jun 1, 2024

Cortex XDR Config Extractor

Python 131 21 Updated Mar 10, 2023

A full analysis report detailing as much as possible of a Malware or a Threat

28 2 Updated Jun 19, 2024

This project aims to compare and evaluate the telemetry of various EDR products.

Python 1,784 169 Updated Apr 11, 2025

ETW based POC to identify direct and indirect syscalls

C++ 185 21 Updated Apr 19, 2023

A dynamic unpacking tool

C++ 134 11 Updated Sep 17, 2023

Strumenti di Acquisizione e Analisi di copie Forensi

146 16 Updated Mar 23, 2024

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…

PowerShell 1,979 199 Updated Dec 11, 2024

Detect EDR's exceptions by inspecting processes' loaded modules

Rust 129 19 Updated Mar 15, 2024

A network sniffer that logs all DNS server replies for use in a passive DNS setup

C 1,692 378 Updated May 28, 2024

Memory Scaner

Python 63 7 Updated Sep 9, 2022

纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用

Java 743 86 Updated Sep 18, 2023

Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, Th…

Python 3,163 459 Updated Jan 24, 2025

Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!

Python 82 7 Updated Jun 28, 2023

An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (.tag) files.

Python 115 10 Updated Jul 12, 2024

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover su…

Python 1,324 243 Updated Nov 7, 2024

Try to find the origin IP of a webapp protected by Cloudflare.

Python 342 69 Updated Aug 8, 2024

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware pre-encryption.

507 44 Updated Dec 13, 2024

Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)

Python 68 6 Updated Sep 13, 2023

DNSWatch - DNS Traffic Sniffer and Analyzer

Python 191 35 Updated Feb 15, 2025

ICMPWatch: ICMP Packet Sniffer

Python 57 9 Updated Oct 15, 2024

Associated-Threat-Analyzer detects malicious IPv4 addresses and domain names associated with your web application using local malicious domain and IPv4 lists.

Python 39 5 Updated Aug 31, 2023

Useful resources for SOC Analyst and SOC Analyst candidates.

692 126 Updated Aug 28, 2023

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

C# 300 69 Updated Mar 20, 2024

A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using InstrumentationCallback.

C++ 26 9 Updated Sep 23, 2023

Analyzes AdminSDHolder permissions & compares with default baseline or a previous run, to detect potential backdoor/excessive persistent permission(s)

PowerShell 15 2 Updated Apr 8, 2025