Showing 36 of 235 projects
A browsable archive of decrypted NSA exploit tools and implants leaked by the Shadow Brokers in 2017.
A static analysis tool that automatically extracts and deobfuscates strings from malware binaries.
A comprehensive university course repository for learning malware analysis through hands-on labs and real-world samples.
A comprehensive university course repository for learning malware analysis through hands-on labs and real-world samples.
A VS Code extension that integrates Android reverse-engineering tools for APK analysis, modification, and debugging.
A testing tool that detects virtual machines and malware analysis environments using techniques observed in real malware.
An advanced malware sandbox for automated configuration and payload extraction with dynamic unpacking and anti-evasion capabilities.
GUI and console sources for Detect It Easy (DiE), a program for determining file types and packers.
Identifies compilers, packers, obfuscators, and other characteristics in Android APK and DEX files.
A dynamic network analysis tool that intercepts and simulates network services for malware analysis and penetration testing.
A PowerShell module for Blue Teams, Incident Responders, and System Administrators to hunt persistence techniques implanted in Windows machines.
A Python module for parsing and working with Portable Executable (PE) files, providing access to headers, sections, and embedded data.
A forensic evidence collection and analysis toolkit for macOS, gathering system data to investigate potential infections.
An open-source malware analysis framework that functions as a self-hosted alternative to VirusTotal.
A Python tool that generates YARA rules for malware detection by filtering out strings and opcodes that appear in goodware.
A repository of publicly-available reports and blogs on APT (Advanced Persistent Threat) campaigns, activity, and software, organized by year.
An obfuscation-neglect Android malware scoring system that analyzes APKs for malicious behavior patterns.
A collection of real-world malware samples, analysis exercises, and training resources for cybersecurity education and research.
A curated list of awesome resources for executable packing, unpacking, and detection, covering packers, tools, and literature.
A curated list of awesome resources, tools, and literature on executable packing, unpacking, and detection for malware analysis and cybersecurity.
A curated list of awesome resources (papers, tools, packers) related to executable packing, unpacking, and detection for malware analysis and cybersecurity.
A binary analysis and management framework for organizing malware samples, exploits, and research scripts.
A curated list of open-source .NET deobfuscators and unpackers for reversing protected assemblies.
A Python tool for analyzing PDF files to detect malicious content and perform security research.
A Windows tool for reconstructing import address tables (IAT) in x64/x86 executables, designed for reverse engineering and unpacking.
A portable Python script that automates malware analysis by collecting runtime indicators using Sysinternals Procmon.
A virtualization-based agentless black-box binary analysis system for stealthy execution tracing.
The largest open collection of Android malware samples for security research and analysis.
A Windows toolkit for analyzing, editing, and manipulating Portable Executable (PE) files and processes.
A collection of tools and scripts for unpacking and analyzing protected Android applications, originally presented at Defcon 22.
A malware communication analyzer that visualizes network traffic and cross-references it with known malware sources.
A virtual machine for Android application security assessment, reverse engineering, and malware analysis.
Interactive Delphi Reconstructor (IDR) is a decompiler for Delphi-compiled Windows executables and DLLs, focusing on static analysis.
A static analyzer for PE executables that identifies malicious indicators and aids in malware assessment.
Free Windows executable and binary data detector that identifies packers, compilers, protectors, and file formats.
A portable volatile memory acquisition tool for Linux that captures memory images without requiring target OS or kernel knowledge.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.