Revoke-Obfuscation v1.0 Logo

Revoke-Obfuscation v1.0

0
Free
Updated 11 March 2025
Visit Website

Revoke-Obfuscation is a PowerShell v3.0+ compatible PowerShell obfuscation detection framework. It was designed to highlight the limitations of a purely signature-based approach to detecting attackers' usage of PowerShell. It provides a new, scalable means of generically detecting both known and unknown obfuscation techniques. Authors: Daniel Bohannon (@danielhbohannon) Lee Holmes (@Lee_Homes) Research Blog Post: https://www.fireeye.com/blog/threat-research/2017/07/revoke-obfuscation-powershell.html White Paper: https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/revoke-obfuscation-report.pdf

FEATURES

SIMILAR TOOLS

Discontinued project for file-less persistence, attacks, and anti-forensic capabilities on Windows 7 32-bit systems.

A Scriptable Android Debugger for reverse engineers and developers.

angr is a Python 3 library for binary analysis with various capabilities like symbolic execution and decompilation.

Binwalk is a tool for analyzing, reverse engineering, and extracting firmware images with security and Python 2.7 deprecation notices.

A collection of resources for beginners to learn assembly language.

Repository of YARA rules for Trellix ATR blogposts and investigations

Automated blind-xss search for Burp Suite

A blind SQL injection tool written in Golang

YARA module for supporting DCSO format bloom filters with hashlookup capabilities.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved