ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.
created at May 24, 2016, 5:04 p.m.
Minimal, consistent Python API for building integrations with malware sandboxes.
created at Jan. 16, 2018, 7:54 p.m.
Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.
created at Oct. 10, 2013, 1:42 p.m.
Wraps around various tools and provides some additional checks/information to produce a centralized report of a PE file.
created at Jan. 16, 2013, 2:04 p.m.
Replay HTTP and HTTPS requests from a PCAP based on TLS Master Secrets.
created at July 26, 2015, 6 a.m.
Malware Analysis Tool using Function Level Fuzzy Hashing
created at Sept. 18, 2015, 5:55 p.m.
A Python library and command line tools to provide interactive log visualization.
created at Oct. 11, 2016, 3:33 p.m.
Searches various online resources to try and get as much info about an IP/domain as possible.
created at Dec. 24, 2012, 5:50 p.m.
analyze a web-based network traffic 🕶 to detect central command and control servers
created at Aug. 23, 2016, 9:45 a.m.
Aggregates security threats from a number of online sources, and outputs to Syslog CEF, Snort Signatures, Iptables rules, hosts.deny, etc.
created at Feb. 27, 2015, 1:28 a.m.
A modular Python application to pull intelligence about malicious files
created at Aug. 30, 2016, 5:35 p.m.
Reverse engineering tool for virtualization wrappers
created at June 28, 2013, 6:55 p.m.
Malware/IOC ingestion and processing engine
created at April 4, 2018, 10:05 p.m.