al-khaser by LordNoteworthy

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

created at Nov. 12, 2015, 6:35 p.m.

C++

242 +0

5,949 +10

1,177 -1

GitHub
ScyllaHide by x64dbg

Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide

created at Jan. 27, 2016, 5:26 a.m.

C++

91 +0

3,487 +7

434 +0

GitHub
pharos by cmu-sei

Automated static analysis tools for binary programs

created at June 12, 2015, 5:51 p.m.

C++

79 +0

1,566 +5

192 +0

GitHub
Scylla by NtQuery

Imports Reconstructor

created at Sept. 13, 2011, 6:58 p.m.

C++

55 +0

1,122 +2

232 +0

GitHub
bulk_extractor by simsong

This is the development tree. Production downloads are at:

created at April 3, 2012, 4:36 a.m.

C++

76 +0

1,121 +5

188 +0

GitHub
drakvuf by tklengyel

DRAKVUF Black-box Binary Analysis

created at Aug. 23, 2014, 10 a.m.

C++

62 +0

1,067 +1

255 +0

GitHub
IDR by crypto2011

Interactive Delphi Reconstructor

created at Feb. 16, 2016, 12:39 p.m.

C++

83 +0

968 +0

225 +1

GitHub
hashdeep by jessek

None

created at June 12, 2012, 11:35 a.m.

C++

60 +0

710 +1

132 +0

GitHub
wdbgark by swwwolf

WinDBG Anti-RootKit Extension

created at Nov. 22, 2014, 10:53 a.m.

C++

63 +0

617 +1

178 +0

GitHub
Nauz-File-Detector by horsicq

Linker/Compiler/Tool detector for Windows, Linux and MacOS.

created at Nov. 29, 2018, 2:28 p.m.

C++

28 +0

529 +3

80 +0

GitHub
PackerAttacker by BromiumLabs

C++ application that uses memory and code hooks to detect packers

created at April 15, 2015, 11:02 p.m.

C++

30 +0

268 +0

72 +0

GitHub
AChoir by OMENScan

Windows Live Artifacts Acquisition Script

created at May 25, 2015, 7:48 p.m.

C++

13 +0

183 +0

29 +0

GitHub
bluepill by season-lab

BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)

created at Nov. 24, 2019, 9:35 p.m.

C++

9 +0

122 +0

22 +0

GitHub
nsrllookup by rjhansen

Checks with NSRL RDS servers looking for for hash matches

created at March 2, 2013, 4:35 p.m.

C++

13 +0

111 +0

10 +0

GitHub
broyara by hempnall

integrating bro into yara

created at Dec. 8, 2014, 10:29 p.m.

C++

5 +0

33 +0

5 +0

GitHub