Thread: Remora Hook
View Single Post
  #4  
Old 09-20-2026, 21:31
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 308
Rept. Given: 108
Rept. Rcvd 97 Times in 46 Posts
Thanks Given: 216
Thanks Rcvd at 432 Times in 140 Posts
Fyyre Reputation: 97
Hey cyberbob,

I've been looking at Remora. The EAT/IAT + LdrLoadDll bootstrap is a nice way to get a usable API log off packed samples without fighting the protector first. The jail is the part that isn’t holding.

Want me to open issue on Github or contact you privately with findings?

-Fyyre

Quote:
Originally Posted by cyberbob View Post
hi,

I just open-sourced my tool: Remora Hook.

Win64 API monitor that hooks a target process using Export Address Table (EAT) and Import Address Table (IAT) patching -- no code modification on API bodies, no debugger attachment. Works with both normally compiled executables and heavily obfuscated, packed binaries with multiple unpacking layers, so you get a useful API log without fighting the protector first.

There is also a short demo GIF on the website showing it in action.

https://github.com/arkup/remora
__________________
Pax in vultu, bellum in corde.

--

https://github.com/Fyyre

Last edited by Fyyre; 09-20-2026 at 21:31. Reason: because I typo!
Reply With Quote
The Following User Says Thank You to Fyyre For This Useful Post:
cyberbob (09-20-2026)