panda by moyix

Deprecated repo for PANDA 1.0 – see PANDA 2.0 repository

updated at Oct. 23, 2023, 3:47 p.m.

C

10 +0

102 +0

42 +0

GitHub
mac-a-mal by phdphuc

The current repository contains all the scripts needed to build kernel-mode mac-a-mal malicious activity hooking on macOS.

updated at March 1, 2024, 3:10 p.m.

C

10 +0

81 +0

24 +0

GitHub
malheur by rieck

A Tool for Automatic Analysis of Malware Behavior

updated at March 22, 2024, 4:10 p.m.

C

56 +0

362 +0

100 +0

GitHub
ngrep by jpr5

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression to match against data payloads of packets. It understands many kinds of protocols, including IPv4/6, TCP, UDP, ICMPv4/6, IGMP and Raw, across a wide variety of interface types, and understands BPF filter logic in the same fashion as more common packet sniffing tools, such as tcpdump and snoop.

updated at April 19, 2024, 4:50 p.m.

C

22 +0

847 +0

98 -2

GitHub
pyrebox by Cisco-Talos

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

updated at April 23, 2024, 3:34 p.m.

C

95 +0

1,638 +2

249 +0

GitHub
Zeus by Visgean

NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. This repository is for study purposes only, do not message me about your lame hacking attempts.

updated at April 24, 2024, 5:24 p.m.

C

138 +0

1,349 -1

692 +0

GitHub
DECAF by decaf-project

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope dynamic Android malware analysis platform. DroidScope is now an extension to DECAF.

updated at April 26, 2024, 1:03 p.m.

C

60 +0

791 +4

168 +0

GitHub
capstone by capstone-engine

Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), BPF, Ethereum VM, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, TriCore, Webassembly, XCore and X86.

updated at April 26, 2024, 10:15 p.m.

C

304 -3

7,036 +13

1,501 +4

GitHub
pafish by a0rtega

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do

updated at April 27, 2024, 4:15 p.m.

C

174 +0

3,084 +4

454 +2

GitHub
udis86 by vmt

Disassembler Library for x86 and x86-64

updated at April 28, 2024, 8:13 a.m.

C

85 +0

983 +0

309 +0

GitHub
HashCheck by gurnec

HashCheck Shell Extension for Windows with added SHA2, SHA3, and multithreading; originally from code.kliu.org

updated at April 28, 2024, 8:31 a.m.

C

72 +0

1,681 +6

193 +0

GitHub