There are no reviews yet. Be the first to send feedback to the community and the maintainers!
MBRFilter This is a simple disk filter based on Microsoft's diskperf and classpnp example drivers. The goal of this filter is to prevent writing to Sector 0 on disks. This is useful to prevent malware that overwrites the MBR like Petya. This driver will prevent writes to sector 0 on all drives. This can cause an issue when initializing a new disk in the Disk Management application. Hit 'Cancel' when asks you to write to the MBR/GPT and it should work as expected. Alternatively, if OK was clicked, then quitting and restarting the application will allow partitoning/formatting. To install: right click the inf file, select 'install' and reboot when prompted. To access sector 0 on drive 0: boot into Safe Mode. To compile: make sure to set: MBRFilter properties -> Configuration properties -> Driver Signing -> General Sign mode: Test Sign Test certificate: generate or select one from your store. To remove MBRFilter, follow these steps: - Remove the line MBRFilter from the UpperFilters registry key in (only remove MBRFilter, there might be other disk drivers here): HKLM\System\CurrentControlSet\Control\Class\{4d36e967-e325-11ce-bfc1-08002be10318} - Reboot AccessMBR Simple program to read sector 0 on Physical drive 0 and write that sector back. Used as a testing program for MBRFilter. This overwrites your MBR, it will restore it once it's done. Nevertheless: USE WITH CAUTION. MBRFilter and AccessMbr Written by Yves Younan, Cisco Talos SCSI passthrough part of AccessMBR written by Andrea Alleivi, Cisco Talos Copyright (C) 2016 Cisco Systems Inc Thanks to Andrea Alleivi for suggested fixes. Thanks to Aaron Adams and Ilja Van Sprundel for reviewing the code. No warranty: use at your own risk.
clamav
ClamAV - Documentation is here: https://docs.clamav.netpyrebox
Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMUGhIDA
mutiny-fuzzer
moflow
Release Branches for MoFlowROPMEMU
ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.Decept
Decept Network Protocol ProxyGhidraaas
DynDataResolver
binary_function_similarity
fnc-1
Fake News ChallengeBASS
BASS - BASS Automated Signature Synthesizerfile2pcap
Barbervisor
Intel x86 bare metal hypervisor for researching snapshot fuzzing ideas.TeslaDecrypt
Decryption Toolsnort-faq
Snort FAQosquery_queries
Cisco Orbital - Osquery queries by TalosFIRST
snap_wtf_macos
WTF Snapshot fuzzing of macOS targetsFIRST-plugin-ida
Winbox_Protocol_Dissector
locky
pylocky_decryptor
cvdupdate
ClamAV Private Database Mirror Updater Toolsmi_check
Smart Install Client Scannerclamav-bytecode-compiler
ClamAV ByteCode Compilercovnavi
IOCs
Indicators of CompromiseMussels
CASC
clamav-safebrowsing
freesentry
clamav-docker
Dockerfiles for the ClamAV projectRe2Pcap
oil-pumpjack
Oil Pumpjack: open source materials to create your own oil pumpjack managed by an ArduinoFIRST-server
clamav-fuzz-corpus
Seed Corpus for clamav-devel oss-fuzz integration.flokibot
remcos-decoder
Talos Decryptor POC for Remcos RAT version 2.0.5 and earlierbadgerboard
crashdog
Daemonlogger
The Official Github Repository of Daemonloggeruseful-tools
Nim-IDA-FLIRT-Generator
Nim-IDA-FLIRT-Generatorclamav-documentation
ClamAV Documentationclamav-mussels-cookbook
snort2-docker
ida_tilegx
NibiruDecrypt
mussels-recipe-scrapbook
Threat-Round-Up
clamav-async-rs
Love Open Source and this site? Check out how you can help us