Revoke-Obfuscation is a PowerShell v3.0+ compatible PowerShell obfuscation detection framework. It was designed to highlight the limitations of a purely signature-based approach to detecting attackers' usage of PowerShell. It provides a new, scalable means of generically detecting both known and unknown obfuscation techniques. Authors: Daniel Bohannon (@danielhbohannon) Lee Holmes (@Lee_Homes) Research Blog Post: https://www.fireeye.com/blog/threat-research/2017/07/revoke-obfuscation-powershell.html White Paper: https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/revoke-obfuscation-report.pdf
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
VxSig is a tool to automatically generate AV byte signatures from similar binaries.
DOM XSS scanner for Single Page Applications
Tplmap is a tool for detecting and exploiting server-side template injection vulnerabilities.
A serverless, real-time, and retroactive malware detection tool that scans files with YARA rules and alerts incident response teams.
A cheat sheet for default credentials to aid in penetration testing and vulnerability assessment
A tool for malware analysts to search through base64-encoded samples and generate yara rules.