#

libpeconv

https://static.github-zh.com/github_avatars/hasherezade?size=40

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3.43 k
8 天前
https://static.github-zh.com/github_avatars/hasherezade?size=40

A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl

C++ 1.28 k
4 个月前
https://static.github-zh.com/github_avatars/hasherezade?size=40
C++ 815
2 年前
https://static.github-zh.com/github_avatars/hasherezade?size=40

A ready-made template for a project based on libpeconv.

C++ 46
7 个月前
https://static.github-zh.com/github_avatars/hasherezade?size=40

A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.

C 20
7 年前
https://static.github-zh.com/github_avatars/hasherezade?size=40

A ready-made template for a new project based on libPeConv library

C++ 7
7 年前
Website
Wikipedia