{"repo":"ayoubfaouzi/al-khaser","free":true,"listed":false,"github":"https://github.com/ayoubfaouzi/al-khaser","clone":"git clone https://github.com/ayoubfaouzi/al-khaser.git","description":"Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.","language":"C++","stars":7095,"topics":["anti-analysis","anti-debugging","anti-sandbox","anti-vm","anti-emulation","code-injection","malware","timing-attacks","av-bypass","sandbox-evasion"],"license":"GPL-2.0","category":"dev-tools","readme_excerpt":"Al-Khaser v0.81 Content - Introduction - Possible uses - Features - Anti-debugging attacks - Anti-Dumping - Timing Attacks - Human Interaction - Anti-VM - Anti-Disassembly - Requirements - License Introduction al-khaser is a PoC \"malware\" application with good intentions that aims to stress your anti-malware system. It performs a bunch of common malware tricks with the goal of seeing if you stay under the radar. Usage Download You can download built binaries (x86, x64) from this project's releases page. The password for the 7zs can be found here. Possible uses - You are making an anti-debug plugin and you want to check its effectiveness. - You want to ensure that your sandbox solution is hidden enough. - Or you want to ensure that your malware analysis environment is well hidden. Please, if you encounter any of the anti-analysis tricks which you have seen in a malware, don't hesitate to contribute. Features Anti-debugging attacks - IsDebuggerPresent - CheckRemoteDebuggerPresent - Process Environment Block (BeingDebugged) - Process Environment Block (NtGlobalFlag) - ProcessHeap (Flags) - ProcessHeap (ForceFlags) - Low Fragmentation Heap (LFH) - NtQueryInformationProcess (ProcessDebugPort) - NtQueryInformationProcess (ProcessDebugFlags) - NtQueryInformationProcess (ProcessDebugObject) - WudfIsAnyDebuggerPresent - WudfIsKernelDebuggerPresent - WudfIsUserDebuggerPresent - NtSetInformationThread (HideThreadFromDebugger) - NtQueryObject (ObjectTypeInformation) - NtQueryObject (Obje","default_branch":null,"files":null,"tree":[],"storefront":"/r/ayoubfaouzi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ayoubfaouzi/al-khaser/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}