| Name / Title | Added | Expires | Hits | Comments | Syntax | |
|---|---|---|---|---|---|---|
| _SYSTEM_MEMORY_USAGE_INFORMATION | Oct 11th, 2022 | Never | 1,179 | 0 | C | - |
| _SYSTEM_PERFORMANCE_INFORMATION | Oct 10th, 2022 | Never | 1,035 | 0 | C | - |
| BATTC.SYS!BatteryClassIoctl Kernel Memory Disclosure | Oct 23rd, 2021 | Never | 1,329 | 0 | C | - |
| nt!ObpCreateSymbolicLinkName Race Condition Write-Beyond-Boundary | Oct 14th, 2021 | Never | 7,738 | 0 | C | - |
| Reversed ObpCreateSymbolicLinkName | Oct 14th, 2021 | Never | 1,543 | 0 | C | - |
| iorate.sys DoS | May 30th, 2021 | Never | 2,092 | 0 | C | - |
| AllocAtHighestUserAddressBuffer | May 14th, 2021 | Never | 1,167 | 0 | C | - |
| Reversed nt!PiControlQueryConflictList | May 2nd, 2021 | Never | 1,658 | 0 | C | - |
| Generated Custom .LNK File | Oct 13th, 2016 | Never | 1,816 | 0 | VBScript | - |
| UNC Path Bug | Oct 10th, 2016 | Never | 498 | 0 | PowerShell | - |
| Bit9 Bug 0 | Sep 26th, 2016 | Never | 767 | 0 | C | - |
| Middle Eastern Attacks | May 18th, 2015 | Never | 693 | 0 | None | - |
| FindRefCLSIDs.py | May 3rd, 2015 | Never | 662 | 0 | Python | - |
| DumpRTFObjects.py | May 3rd, 2015 | Never | 590 | 0 | Python | - |
| CVE-2012-0158 Control Words | May 3rd, 2015 | Never | 834 | 0 | C | - |
| MagedDecrypter | May 3rd, 2015 | Never | 661 | 0 | Python | - |
| HexToFile.Py | Apr 27th, 2015 | Never | 626 | 0 | Python | - |
| Decode_njRat_3DES | Apr 25th, 2015 | Never | 640 | 0 | Python | - |
| Decoder For CyberGate XX-XX-XX-XX Resource | Apr 24th, 2015 | Never | 634 | 0 | Python | - |
| RunPE Embedded Executable Extractor | Apr 22nd, 2015 | Never | 774 | 0 | Python | - |
| Cyber Attack 6 njRat Source Code | Apr 18th, 2015 | Never | 953 | 0 | C# | - |
| Decode_njRat_GZipVersion | Apr 18th, 2015 | Never | 603 | 0 | Python | - |
| JS_Malicious_Invoice | Apr 18th, 2015 | Never | 794 | 0 | JavaScript | - |
| cIR1R2_Analytics | Apr 14th, 2015 | Never | 559 | 0 | XML | - |
| Flushupdate.com /etc/group | Apr 8th, 2015 | Never | 757 | 0 | C | - |
| Flushupdate.com /etc/hosts | Apr 8th, 2015 | Never | 879 | 0 | C | - |
| Flushupdate.com /etc/passwd | Apr 8th, 2015 | Never | 884 | 0 | C | - |
| advtravel.info | Apr 8th, 2015 | Never | 640 | 0 | C | - |
| WQL VirtualBox Detection | Apr 4th, 2015 | Never | 3,389 | 0 | VBScript | - |
| GetWriteWatch Trick | Jun 30th, 2014 | Never | 675 | 0 | C | - |
| PspProcessOpen | Nov 8th, 2013 | Never | 989 | 0 | C | - |
| INT 2E / Anti-Tracing Trick | Oct 24th, 2013 | Never | 1,048 | 0 | C | - |
| PspSetContext Nested Task EFlag Anti-Tracing Trick | Oct 19th, 2013 | Never | 1,065 | 0 | C | - |
| NtSystemDebugControl + KdPitchDebugger | Jul 3rd, 2013 | Never | 2,675 | 0 | C | - |
| KdUpdateTimeSlipEvent KernelDebugger Trick | Jul 2nd, 2013 | Never | 736 | 0 | C | - |
| NtGlobalFlag As Anti-Debug Trick | Jun 4th, 2013 | Never | 1,019 | 0 | C | - |
| PspSetContext Anti-Tracing Trick | May 9th, 2013 | Never | 932 | 0 | C | - |
| InstrumentationCallback Anti-Debug+Redirection | Apr 19th, 2013 | Never | 3,032 | 0 | C | - |
| Kernel VA Leak | Apr 18th, 2013 | Never | 976 | 0 | C | - |
| Anti-Resource Editing | Apr 3rd, 2013 | Never | 1,436 | 0 | None | - |
| Page_0x00000000 Anti-Tracing Trick | Mar 12th, 2013 | Never | 799 | 0 | C | - |
| 64-Bit ZwQueryObject (Detect Debuggers) | Feb 27th, 2013 | Never | 913 | 0 | C | - |
| Bypass Non-Killable Process | Feb 12th, 2013 | Never | 902 | 0 | C | - |
| ZwClose As Anti-Debug Trick | Feb 9th, 2013 | Never | 1,190 | 0 | C | - |
| ProcessIoPriority Bug (BSOD/Non-Killable Process) | Feb 6th, 2013 | Never | 2,787 | 0 | C | - |
| ThreadWow64Context | Feb 2nd, 2013 | Never | 610 | 0 | C | - |
| RaiseException(0x4000001f) Anti-Olly Trick | Jan 30th, 2013 | Never | 1,053 | 0 | C | - |
| Template Wow64Log.dll | Jan 25th, 2013 | Never | 1,089 | 0 | C | - |
| Injecting 64Bit Dll Into 32Bit Process | Jan 25th, 2013 | Never | 1,886 | 0 | C | - |
| Some Anti-Attaching Candidate Functions | Jan 25th, 2013 | Never | 781 | 0 | C | - |
| Kernel Bug #0 ThreadIOPriority | Jan 23rd, 2013 | Never | 1,161 | 0 | C | - |
| ProcessBasicInformation vs. New Flags | Jan 22nd, 2013 | Never | 869 | 0 | C | - |
| ProcessExecuteFlags | Jan 21st, 2013 | Never | 842 | 0 | None | - |
| LdrpIsImageSEHValidationCompatible | Jan 21st, 2013 | Never | 690 | 0 | None | - |
| ProcessInstrumentationCallback | Jan 20th, 2013 | Never | 858 | 0 | C | - |
| Wow64SharedInformation vs. Shellcode | Jan 19th, 2013 | Never | 834 | 0 | C | - |
| Enumerate Loaded Modules (64-bit) | Jan 19th, 2013 | Never | 421 | 0 | C | - |
| Get Main ThreadId Of A Process | Jan 19th, 2013 | Never | 570 | 0 | C | - |
| SystemFunction0035 | Jan 14th, 2013 | Never | 590 | 0 | C | - |
| Call64, Issue 64-bit System Calls | Jan 12th, 2013 | Never | 1,409 | 0 | C | - |
| Redirect Execution | Jan 6th, 2013 | Never | 822 | 0 | C | - |
| "Prefix+PUSHFD" Anti-Tracing Trick | Jan 4th, 2013 | Never | 731 | 0 | C | - |
| "REP: PUSHFD" Anti-Tracing Trick | Jan 4th, 2013 | Never | 709 | 0 | C | - |
| KERNEL: Creation of Thread Environment Block (TEB) | Dec 31st, 2012 | Never | 2,762 | 0 | None | - |
| Wow64-Specific Anti-Debug Trick | Dec 26th, 2012 | Never | 2,028 | 0 | C | - |
| Anti-ChildDebugging | Dec 16th, 2012 | Never | 831 | 0 | C | - |
| ZwQueryInformationThread(ThreadAmILastThread) | Dec 14th, 2012 | Never | 629 | 0 | C | - |
| ZwQueryInformationThread(ThreadLastSystemCall) | Dec 14th, 2012 | Never | 1,128 | 0 | C | - |
| ZwQueryInformationThread(ThreadTebInformation) | Dec 14th, 2012 | Never | 783 | 0 | C | - |
| SystemComPlusPackage | Dec 8th, 2012 | Never | 955 | 0 | C | - |
| SuppressDllMains --> SkipThreadAttach | Dec 7th, 2012 | Never | 1,207 | 0 | C | - |
| DebugActiveProcess(ParentProcessPid) Trick | Dec 2nd, 2012 | Never | 682 | 0 | C | - |
| DebuggerIs32Bit | Dec 1st, 2012 | Never | 744 | 0 | None | - |
| TEB.SuppressDebugMsg | Nov 22nd, 2012 | Never | 1,251 | 0 | C | - |
| OllyDbg v1.10 LoadDll.hFile Trick | Nov 21st, 2012 | Never | 608 | 0 | C | - |
| ZwCreateThreadEx/HiddenFromDebugger | Nov 21st, 2012 | Never | 2,965 | 0 | C | - |
| OllyDbg RaiseException Anti-Debug Trick | Nov 7th, 2012 | Never | 1,461 | 0 | C | - |
| VirtualBox HardDiskInfo Trick | Nov 5th, 2012 | Never | 483 | 0 | C | - |
| Reversed "BaseCreateStack" | Nov 5th, 2012 | Never | 918 | 0 | C | - |
| VirtualBox CPUID-SEP Trick | Nov 5th, 2012 | Never | 1,276 | 0 | C | - |
| Virtual PC 2007 DR7 Trick | Oct 29th, 2012 | Never | 1,006 | 0 | C | - |
| 32_Bit --> 64_bit PE Header | Oct 24th, 2012 | Never | 656 | 0 | C | - |
| SizeOfStackReserve As Anti-Attach Trick | Oct 24th, 2012 | Never | 1,793 | 0 | C | - |
| Trigger STATUS_GUARD_VIOLATION | Oct 22nd, 2012 | Never | 551 | 0 | C | - |
| VirtualBox VS. Hardware Breakpoints | Oct 21st, 2012 | Never | 614 | 0 | C | - |
| TEB As Anti-Memory Breakpoints | Oct 20th, 2012 | Never | 1,805 | 0 | C | - |
| Extract EntryPoint, ImageBase, And SizeOfImage | Oct 18th, 2012 | Never | 599 | 0 | C | - |
| VBoxSharedFolderFS | Oct 18th, 2012 | Never | 1,743 | 0 | C | - |
| ReadProcessMemory As Anti-Memory Breakpoints | Oct 18th, 2012 | Never | 2,165 | 0 | C | - |
| DebugActiveProcess(-1) | Oct 15th, 2012 | Never | 641 | 0 | C | - |
| Processors' Strings | Oct 14th, 2012 | Never | 486 | 0 | C | - |
| Resume Flag Support | Oct 14th, 2012 | Never | 432 | 0 | C | - |
| lpMinimumApplicationAddress & lpMaximumApplicationAddress | Oct 13th, 2012 | Never | 741 | 0 | C | - |
| VirtualPC CPUID TRICK | Oct 8th, 2012 | Never | 4,053 | 0 | C | - |
| Detect Hypervisor | Oct 8th, 2012 | Never | 5,978 | 0 | C | - |
| VirtualPC Reset Trick | Oct 8th, 2012 | Never | 2,917 | 0 | C | - |
| VirtualPC 0x0F 0x3F Combinations | Oct 8th, 2012 | Never | 2,097 | 0 | C | - |
| Detect VirtualPC (The "x0Fx3F" TRICK) | Oct 8th, 2012 | Never | 2,415 | 0 | C | - |
| Detect VirtualBox (Cadmus Mac Address TRICK) | Oct 7th, 2012 | Never | 3,643 | 0 | C | - |