Posts

Showing posts with the label Hooking

Pe-Sieve - Recognizes In Addition To Dumps A Diversity Of Potentially Malicious Implants (Replaced/Injected Pes, Shellcodes, Hooks, In-Memory Patches)

Image
PE-sieve is a light-weight tool that helps to detect malware running on the system, equally good equally to collect the potentially malicious fabric for farther analysis. Recognizes in addition to dumps diversity of implants inside the scanned process: replaced/injected PEs, shellcodes, hooks, in addition to other in-memory patches. Detects inline hooks, Process Hollowing, Process Doppelgänging, Reflective DLL Injection, etc. uses library: https://github.com/hasherezade/libpeconv.git Clone: Use recursive clone to larn the repo together alongside the submodule: git clone --recursive https://github.com/hasherezade/pe-sieve.git Latest builds*: *those builds are available for testing in addition to they may last ahead of the official release : 32-bit 64-bit Download Pe-Sieve

Efiguard - Disable Patchguard Together With Dse At Kicking Time

Image
EfiGuard is a portable x64 UEFI bootkit that patches the Windows kicking manager, kicking loader too center at kicking fourth dimension inward club to disable PatchGuard too Driver Signature Enforcement (DSE). Features Currently supports all EFI-compatible versions of Windows x64 e'er released, from Vista SP1 to Server 2019. Easy to use: tin live on booted from a USB stick via a loader application that automatically finds too boots Windows. The driver tin also live on loaded too configured manually using either the UEFI rhythm out or the loader. Makes extensive utilization of the Zydis disassembler library for fast runtime pedagogy decoding to back upwardly to a greater extent than robust analysis than what is possible amongst signature matching, which oftentimes requires changes amongst novel OS updates. Works passively: the driver does non charge or start the Windows kicking manager. Instead it acts on a charge of bootmgfw.efi yesteryear the firmware kicking ...