broyara by hempnall

integrating bro into yara

updated at Sept. 24, 2024, 6:44 p.m.

C++

5 +0

33 +0

5 +0

GitHub
python-icap-yara by RamadhanAmizudin

An ICAP Server with yara scanner for URL and content.

updated at Sept. 24, 2024, 6:46 p.m.

Python

6 +0

57 +0

13 +0

GitHub
python-evt by williballenthin

Pure Python parser for classic Windows Event Log files (.evt)

updated at Sept. 24, 2024, 6:49 p.m.

Python

6 +0

48 +0

11 +0

GitHub
sflock by hatching

Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.

updated at Sept. 24, 2024, 6:52 p.m.

Python

12 +0

83 +0

46 +0

GitHub
AChoir by OMENScan

Windows Live Artifacts Acquisition Script

updated at Sept. 30, 2024, 2:54 a.m.

C++

13 +0

183 +0

29 +0

GitHub
MalPipe by silascutler

Malware/IOC ingestion and processing engine

updated at Oct. 1, 2024, 7:29 p.m.

Python

11 +0

103 +0

24 +0

GitHub
bluepill by season-lab

BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)

updated at Oct. 2, 2024, 9:09 a.m.

C++

9 +0

121 +0

22 +0

GitHub
malheur by rieck

A Tool for Automatic Analysis of Malware Behavior

updated at Oct. 3, 2024, 5:11 a.m.

C

56 +0

368 +0

101 +0

GitHub
malwarehouse by sroberts

A warehouse for your malware

updated at Oct. 3, 2024, 5:11 a.m.

Python

22 +0

133 +0

43 +0

GitHub
aleph by merces

An Open Source Malware Analysis Pipeline System

updated at Oct. 3, 2024, 5:11 a.m.

CSS

35 +0

158 +0

53 +0

GitHub
python-dshield by rshipp

Pythonic interface to the Internet Storm Center / DShield API.

updated at Oct. 3, 2024, 5:11 a.m.

Python

4 +0

28 +0

13 +0

GitHub
threataggregator by jpsenior

Aggregates security threats from a number of online sources, and outputs to Syslog CEF, Snort Signatures, Iptables rules, hosts.deny, etc.

updated at Oct. 3, 2024, 5:11 a.m.

Python

12 +0

79 +0

27 +0

GitHub
MaltegoVT by michael-yip

A set of Maltego transforms for VirusTotal Public API v2.0. This set has the added functionality of caching queries on a daily basis to speed up resolutions.

updated at Oct. 3, 2024, 5:11 a.m.

Python

8 +0

79 +0

22 +0

GitHub
ThreatTracker by michael-yip

ThreatTracker is a Python script designed to monitor and generate alerts on given sets of indicators of compromise (IOCs) indexed by a set of Google Custom Search Engines.

updated at Oct. 3, 2024, 5:11 a.m.

Python

7 +0

66 +0

13 +0

GitHub
abusehelper by abusesa

A framework for receiving and redistributing abuse feeds

updated at Oct. 3, 2024, 5:12 a.m.

Python

20 +0

118 +0

18 +0

GitHub
hostintel by keithjjones

A modular Python application to collect intelligence for malicious hosts.

updated at Oct. 3, 2024, 5:12 a.m.

Python

30 +0

262 +0

51 +0

GitHub
squidmagic by ch3k1

analyze a web-based network traffic 🕶 to detect central command and control servers

updated at Oct. 3, 2024, 5:12 a.m.

Python

8 +0

78 +0

27 +0

GitHub
fileintel by keithjjones

A modular Python application to pull intelligence about malicious files

updated at Oct. 3, 2024, 5:12 a.m.

Python

17 +0

118 +0

25 +0

GitHub
cuckoo-modified-api by keithjjones

A Python library to interface with a cuckoo-modified instance

updated at Oct. 3, 2024, 5:12 a.m.

Python

6 +0

21 +0

7 +0

GitHub
visualize_logs by keithjjones

A Python library and command line tools to provide interactive log visualization.

updated at Oct. 3, 2024, 5:12 a.m.

HTML

15 +0

137 +0

30 +0

GitHub