Papa Shango Logo

Papa Shango

0
Free
Visit Website

Papa Shango is a Linux process injection tool that uses ptrace() to inject shellcode into a running process. It allows you to write your payloads in assembler and does not care about NULL bytes. Here is an example of how to use it: `cat papa-shango shellcode > payload chmod +x payload ./payload <pid>`

FEATURES

ALTERNATIVES

Yara module for Node.js

A framework for creating XNU based rootkits for OS X and iOS security research

A collection of YARA rules for public use, built from intelligence profiles and file work.

Explores malware interaction with Windows API and methods for detection and prevention.

Interactive incremental disassembler with data/control flow analysis capabilities.

A tool for malware analysts to search through base64-encoded samples and generate yara rules.

Yara mode for GNU Emacs to edit Yara related files

Blazingly fast Yara queries for malware analysts with an analyst-friendly web GUI.