combine by mlsecproject

Tool to gather Threat Intelligence indicators from publicly available sources

updated at May 21, 2024, 8:05 p.m.

Python

90 +0

650 +1

179 +0

GitHub
nsrllookup by rjhansen

Checks with NSRL RDS servers looking for for hash matches

updated at May 22, 2024, 1:50 a.m.

C++

13 +0

108 +1

10 +0

GitHub
visualize_logs by keithjjones

A Python library and command line tools to provide interactive log visualization.

updated at May 22, 2024, 2:57 a.m.

HTML

15 +0

135 +1

36 +0

GitHub
malice by maliceio

VirusTotal Wanna Be - Now with 100% more Hipster

updated at May 22, 2024, 3:01 a.m.

Go

96 +0

1,617 +0

264 +1

GitHub
PackerAttacker by BromiumLabs

C++ application that uses memory and code hooks to detect packers

updated at May 22, 2024, 3:08 a.m.

C++

30 +0

262 +1

72 +0

GitHub
bluepill by season-lab

BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)

updated at May 22, 2024, 3:12 a.m.

C++

9 +0

117 +2

22 -3

GitHub
hackers-grep by codypierce

hackers-grep is a utility to search for strings in PE executables including imports, exports, and debug symbols

updated at May 22, 2024, 3:38 a.m.

Python

9 +0

167 +2

19 +0

GitHub
PortEx by katjahahn

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

updated at May 22, 2024, 3:57 a.m.

Java

43 +0

488 +1

95 +0

GitHub
AChoir by OMENScan

Windows Live Artifacts Acquisition Script

updated at May 22, 2024, 5:52 a.m.

C++

14 +0

177 +1

31 +0

GitHub
Limon by monnappa22

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators of Linux malware. It allows one to inspect Linux malware before execution, during execution, and after execution (post-mortem analysis) by performing static, dynamic and memory analysis using open source tools

updated at May 22, 2024, 6:44 a.m.

Python

37 +1

384 +1

114 +0

GitHub
honeytrap by honeytrap

Advanced Honeypot framework.

updated at May 22, 2024, 1 p.m.

Go

50 +0

1,194 -1

177 +0

GitHub
conpot by mushorg

ICS/SCADA honeypot

updated at May 22, 2024, 1 p.m.

Python

96 +1

1,194 +1

406 +0

GitHub
dionaea by DinoTools

Home of the dionaea honeypot

updated at May 22, 2024, 9:34 p.m.

Python

44 +0

681 -1

184 +1

GitHub
drakvuf by tklengyel

DRAKVUF Black-box Binary Analysis

updated at May 22, 2024, 11:53 p.m.

C++

61 +0

1,011 +2

246 +0

GitHub
orochi by LDO-CERT

The Volatility Collaborative GUI

updated at May 23, 2024, 2:17 a.m.

JavaScript

12 +0

205 +2

19 +0

GitHub
hachoir by vstinner

Hachoir is a Python library to view and edit a binary stream field by field

updated at May 23, 2024, 3:08 a.m.

Python

22 +0

588 +1

69 +0

GitHub
PcapViz by mateuszk87

Visualize network topologies and collect graph statistics based on pcap files

updated at May 23, 2024, 5:08 a.m.

Python

27 +0

327 +1

59 +0

GitHub
quark-engine by quark-engine

Dig Vulnerabilities in the BlackBox

updated at May 23, 2024, 5:12 a.m.

Python

41 +0

1,232 +1

163 +0

GitHub
DECAF by decaf-project

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope dynamic Android malware analysis platform. DroidScope is now an extension to DECAF.

updated at May 23, 2024, 12:05 p.m.

C

60 +0

793 +1

168 +0

GitHub
machinae by HurricaneLabs

Machinae Security Intelligence Collector

updated at May 23, 2024, 6:38 p.m.

Python

38 +0

495 -1

101 +0

GitHub