InvalidSign Logo

InvalidSign

0
Free
Visit Website

The InvalidSign tool aims to bypass endpoint solutions that block known 'malicious' signed applications by obtaining a valid signed file with a different hash, as demonstrated through the analysis of cmd.exe and the generation of test files.

FEATURES

ALTERNATIVES

Malware allows attackers to execute Windows commands from a remote environment

Wazuh is an open-source security platform offering unified XDR and SIEM protection for endpoints and cloud workloads, integrating various security functions into a single architecture.

TheHive is a case management platform for security operations teams that facilitates incident response, threat analysis, and team collaboration.

Sample security playbooks for security automation, orchestration and response (SOAR) using Microsoft Sentinel trigger

PowerGRR is a PowerShell module for the GRR API, allowing automation and scripting for incident response and remote live forensics.

A DFIR Playbook Spec based on YAML for collaborative incident response processes.

Reveelium UEBA is a French-developed User and Entity Behavior Analytics solution that uses artificial intelligence to detect abnormal behaviors and security threats by analyzing user and entity activities within an organization's network.

Automated Digital Forensics and Incident Response (DFIR) software for rapid incident response and intrusion investigations.

PINNED