EVTXtract by williballenthin

EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.

updated at April 14, 2024, 1:56 p.m.

Python

18 +0

173 +0

24 +0

GitHub
IPinfo by hiddenillusion

Searches various online resources to try and get as much info about an IP/domain as possible.

updated at April 14, 2024, 2:38 a.m.

Python

19 +0

95 +0

28 +0

GitHub
AnalyzePE by hiddenillusion

Wraps around various tools and provides some additional checks/information to produce a centralized report of a PE file.

updated at April 12, 2024, 11:52 p.m.

Python

19 +0

201 +0

37 +0

GitHub
nsrllookup by rjhansen

Checks with NSRL RDS servers looking for for hash matches

updated at April 12, 2024, 8:49 p.m.

C++

13 +0

107 +0

10 +0

GitHub
Ragpicker by robbyFux

Ragpicker is a Plugin based malware crawler with pre-analysis and reporting functionalities. Use this tool if you are testing antivirus products, collecting malware for another analyzer/zoo.

updated at April 12, 2024, 8:54 a.m.

Python

15 +0

90 +0

25 +0

GitHub
hpfeeds by hpfeeds

Honeynet Project generic authenticated datafeed protocol

updated at April 8, 2024, 2:49 a.m.

Python

30 +0

208 +0

110 +0

GitHub
evolve by JamesHabben

Web interface for the Volatility Memory Forensics Framework

updated at April 4, 2024, 10:44 p.m.

JavaScript

38 +0

259 +0

42 +0

GitHub
malsub by diogo-fernan

A Python RESTful API framework for online malware analysis and threat intelligence services.

updated at April 4, 2024, 3:30 a.m.

Python

36 +0

362 +0

83 +0

GitHub
jsunpack-n by urule99

Automatically exported from code.google.com/p/jsunpack-n

updated at April 3, 2024, 2:49 p.m.

Python

16 +0

157 +0

65 +0

GitHub
CryptoKnight by AbertayMachineLearningGroup

Cryptographic Dataset Generation & Modelling Framework

updated at April 2, 2024, 6:43 a.m.

Python

6 +0

38 +0

12 +0

GitHub
packerid by sooshie

None

updated at March 27, 2024, 10:19 a.m.

Python

5 +0

40 +0

9 +0

GitHub
httpreplay by hatching

Replay HTTP and HTTPS requests from a PCAP based on TLS Master Secrets.

updated at March 26, 2024, 7:46 p.m.

Python

13 +0

94 +0

33 -3

GitHub
sflock by hatching

Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.

updated at March 26, 2024, 7:45 p.m.

Python

12 +0

81 +0

48 +0

GitHub
DAMM by 504ensicsLabs

Differential Analysis of Malware in Memory

updated at March 26, 2024, 4:23 p.m.

Python

31 +0

209 +0

56 +0

GitHub
VolDiff by aim4r

VolDiff: Malware Memory Footprint Analysis based on Volatility

updated at March 26, 2024, 6:38 a.m.

Python

28 +0

192 +0

50 +0

GitHub
mnemosyne by johnnykv

Normalizer for honeypot data.

updated at March 26, 2024, 2:39 a.m.

Python

8 +0

44 +0

41 -1

GitHub
VolUtility by kevthehermit

Web App for Volatility framework

updated at March 24, 2024, 4:56 p.m.

Python

40 +0

373 +0

82 +1

GitHub
fileintel by keithjjones

A modular Python application to pull intelligence about malicious files

updated at March 20, 2024, 12:49 a.m.

Python

17 +0

113 +0

25 +0

GitHub
BoomBox by nbeede

Automatic deployment of Cuckoo Sandbox malware lab using Packer and Vagrant

updated at March 19, 2024, 10:18 a.m.

PowerShell

8 +0

231 +0

39 +0

GitHub
python-icap-yara by RamadhanAmizudin

An ICAP Server with yara scanner for URL and content.

updated at March 12, 2024, 12:41 p.m.

Python

6 +0

56 +0

13 +0

GitHub