ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.
created at May 24, 2016, 5:04 p.m.
Differential Analysis of Malware in Memory
created at Sept. 16, 2014, 5:32 p.m.
A modular Python application to collect intelligence for malicious hosts.
created at Aug. 22, 2016, 8:25 p.m.
inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques
created at April 29, 2011, 4:37 a.m.
C++ application that uses memory and code hooks to detect packers
created at April 15, 2015, 11:02 p.m.
A machine learning tool that ranks strings based on their relevance for malware analysis.
created at Sept. 5, 2019, 1:02 p.m.
Linker/Compiler/Tool detector for Windows, Linux and MacOS.
created at Nov. 29, 2018, 2:28 p.m.
Defanged Indicator of Compromise (IOC) Extractor.
created at April 17, 2018, 5:37 p.m.
Visualize network topologies and collect graph statistics based on pcap files
created at Jan. 21, 2015, 10:57 p.m.
Malware Analysis Tool using Function Level Fuzzy Hashing
created at Sept. 18, 2015, 5:55 p.m.
Threat Intelligence Quotient Test - Dataviz and Statistical Analysis of TI feeds
created at March 30, 2014, 6:52 p.m.
ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression to match against data payloads of packets. It understands many kinds of protocols, including IPv4/6, TCP, UDP, ICMPv4/6, IGMP and Raw, across a wide variety of interface types, and understands BPF filter logic in the same fashion as more common packet sniffing tools, such as tcpdump and snoop.
created at Dec. 30, 2009, 8:14 a.m.
Minimal, consistent Python API for building integrations with malware sandboxes.
created at Jan. 16, 2018, 7:54 p.m.