Schweiz

drakonia

Elite
@dr4k0nia

Security Researcher specializing in .NET malware analysis and tooling

NixImports. A .NET malware loader, using API-Hashing to evade static analysis

209

Origami. Packer compressing .net assemblies, (ab)using the PE format for data storage

176

XorStringsNET. Easy XOR string encryption for NET based binaries

138

MurkyStrings. A string obfuscator for .NET apps, built to evade static string analysis.

108

Unscrambler. Universal unpacker and fixer for a number of modded ConfuserEx protections

105

Simple-Costura-Decompressor. Simple tool to extract and decompress embedded resources processed by Fody Costura

80

tooling-playground. A collection of small scripts and tools for deobfuscation and malware analysis.

67

FlatUI-Midnight. FlatUI Dark Reskin for Winforms .NET 4.0

60

Greenline. Unpacker and Config Extractor for managed Redline Stealer payloads

39

yara-rules. A collection of my yara rules

34

de4dot_gui. Simple GUI app to simplify manual string decryption with de4dot

25

NoChallenge. A tool to automatically defeat .NET crackmes based on string equality comparisons

18

DontPoisonMySource. Simple tool to check visual studio project files for Exec, PreBuildEvent and PostBuildEvent

12

simple-string-encryption. Simple website to automatically generate string encryption/decryption routines for C#

10

LagSwitch. C#

9

AHK-Dumper. Dumper for compiled AutoHotKey Scripts

8

dr4k0nia.github.io. SCSS

5

de4dot. .NET deobfuscator and unpacker.

4

AsmResolver. A library for editing PE files with full .NET metadata support

2

autoit-extractor. AutoIt Extractor transferred to GitHub

2

Configuration_extractors. Python

1

pycdc. C++ python bytecode disassembler and decompiler

1
22
Apply