SigFlip

PE file modifier

A tool for modifying signed executable files without invalidating the signature or integrity checks.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

GitHub

1k stars
20 watching
192 forks
Language: C#
last commit: about 3 years ago

Related projects:

RepositoryDescriptionStars
liip/liipimaginebundleAn image manipulation toolkit for Symfony-based projects.1,666
hiddenillusion/analyzepeAnalyzes PE files by combining data from various tools to generate a centralized report.204
dragon-dreamer/binary-valentineAn executable file analyzer tool that detects security, configuration, optimization, system, and format issues in Windows executables18
struppigel/portexA Java library for static analysis of Portable Executable files with focus on malware detection and PE malformation robustness499
espressocake/dll_imports_bofAn enumeration tool to inspect PE files and extract information about loaded DLLs and their imported functions83
samlarenn/pepackerA tool for encrypting and obfuscating .text sections of executable files.49
egebalci/amberCreates reflective PE files that can be executed in memory without being written to disk1,208
silva97/peiTools for injecting and manipulating code in PE executables30
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
0ang3el/easycsrfAn extension that automatically modifies certain HTTP requests to reveal potential CSRF vulnerabilities in web applications.160
slimm609/checksecA tool to analyze and report on the security properties of executables2,061
packing-box/pypackerdetectDetects whether an executable is packed using various methods and signatures.21
psecio/iniscanA tool to scan PHP configuration files for security practices and report results1,481
med0x2e/ntlmrelay2selfA toolset to exploit a Windows vulnerability allowing an attacker to gain elevated privileges on the local system by using NTLM authentication over HTTP.394
packing-box/peidA tool for detecting packed executables in Windows files by identifying embedded signatures130