pdfxray_lite by 9b

Lite version of PDF X-RAY that uses no backend

updated at Nov. 18, 2022, 11:52 p.m.

Python

7 +0

34 +0

9 +0

GitHub
broyara by hempnall

integrating bro into yara

updated at Nov. 22, 2022, 7:44 a.m.

C++

5 +0

31 +0

5 +0

GitHub
TotalRecall by sketchymoose

Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

updated at Sept. 28, 2023, 10:22 a.m.

Python

14 +0

49 +0

9 +0

GitHub
MalPipe by silascutler

Malware/IOC ingestion and processing engine

updated at Sept. 28, 2023, 10:49 a.m.

Python

11 +0

102 +0

24 +0

GitHub
panda by moyix

Deprecated repo for PANDA 1.0 – see PANDA 2.0 repository

updated at Oct. 23, 2023, 3:47 p.m.

C

10 +0

102 +0

42 +0

GitHub
malpdfobj by 9b

Builds json representation of PDF malware sample

updated at Nov. 11, 2023, 12:59 p.m.

Python

8 +0

51 +0

16 +0

GitHub
SMRT by pidydx

Sublime Malware Research Tool

updated at Nov. 15, 2023, 9:41 a.m.

Python

8 +0

64 +0

15 +0

GitHub
malwarehouse by sroberts

A warehouse for your malware

updated at Dec. 4, 2023, 6:08 p.m.

Python

22 +0

131 +0

43 +0

GitHub
boomerang by EmersonElectricCo

A tool designed for consistent and safe capture of off network web resources.

updated at Dec. 4, 2023, 6:09 p.m.

Python

12 +0

34 +0

6 +0

GitHub
PyIOCe by pidydx

Python OpenIOC Editor

updated at Dec. 6, 2023, 12:12 a.m.

Python

3 +0

16 +0

7 +0

GitHub
recomposer by secretsquirrel

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

updated at Dec. 6, 2023, 7:03 a.m.

Python

18 +0

130 +0

42 +0

GitHub
ThreatTracker by michael-yip

ThreatTracker is a Python script designed to monitor and generate alerts on given sets of indicators of compromise (IOCs) indexed by a set of Google Custom Search Engines.

updated at Dec. 14, 2023, 3:25 p.m.

Python

7 +0

62 +0

13 +0

GitHub
codebro by hugsy

Web based code browser using clang to provide basic code analysis.

updated at Jan. 2, 2024, 12:06 a.m.

HTML

6 +0

43 +0

6 +0

GitHub
threataggregator by jpsenior

Aggregates security threats from a number of online sources, and outputs to Syslog CEF, Snort Signatures, Iptables rules, hosts.deny, etc.

updated at Jan. 3, 2024, 2:12 p.m.

Python

12 +0

78 +0

27 +0

GitHub
ROPMEMU by Cisco-Talos

ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.

updated at Jan. 16, 2024, 4:21 p.m.

Python

31 +0

280 +0

50 +0

GitHub
abusehelper by abusesa

A framework for receiving and redistributing abuse feeds

updated at Jan. 23, 2024, 11:37 a.m.

Python

20 +0

113 +0

18 -2

GitHub
DemonHunter by RevengeComing

Distributed Honeypot

updated at Jan. 24, 2024, 1:34 a.m.

Python

9 +0

58 +0

12 +0

GitHub
tiq-test by mlsecproject

Threat Intelligence Quotient Test - Dataviz and Statistical Analysis of TI feeds

updated at Jan. 30, 2024, 4:14 a.m.

R

24 +0

165 +0

43 +0

GitHub
massive-octo-spice by csirtgadgets

DEPRECATED - USE v3 (bearded-avenger)

updated at Feb. 4, 2024, 7:58 a.m.

Perl

56 +0

227 +0

62 +0

GitHub
inVtero.net by ShaneK2

inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

updated at Feb. 5, 2024, 5:10 p.m.

C#

31 +0

276 +0

57 +0

GitHub