Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Malware Analysis

Malware Analysis

235 projects

Showing 36 of 235 projects

malware-jail
malware-jailJavaScript

A Node.js sandbox for semi-automatic JavaScript malware analysis, deobfuscation, and payload extraction.

#activex#angler#sandbox
Stars477
Forks98
Last commit3 years ago
drltrace
drltraceHTML

A dynamic API calls tracer for Windows and Linux applications, built on DynamoRIO for transparent malware analysis.

#dynamorio#dbi#malware-detection
Stars419
Forks71
Last commit6 years ago
Cuckoo-modified
Cuckoo-modifiedPython

A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.

#sandbox#behavioral-analysis#security-automation
Stars407
Forks175
Last commit
Limon
LimonPython

A Python sandbox that automatically collects, analyzes, and reports runtime indicators of Linux malware through static, dynamic, and memory analysis.

#sandbox#python#malware-analysis
Stars403
Forks118
Last commit10 years ago
Pyew
PyewPython

A command-line Python tool for malware analysis with hex viewing, disassembly, file format support, and plugin architecture.

#python-tool#disassembly#command-line-tool
Stars395
Forks94
Last commit6 years ago
go-yara
go-yaraGo

Go bindings for the YARA pattern matching library, providing a Go-native interface to YARA's C API.

#hacktoberfest#cgo#go-bindings
Stars389
Forks113
Last commit1 year ago
VolUtility
VolUtilityPython

A web interface for the Volatility memory forensics framework that runs plugins, stores results in MongoDB, and enables cross-plugin search.

#digital-forensics#yara-rules#security-analysis
Stars387
Forks80
Last commit6 months ago
Polichombr
PolichombrPython

A collaborative malware analysis framework for storing samples, automating analysis, and sharing insights via IDA Pro integration.

#flask#ida#python
Stars383
Forks60
Last commit7 years ago
Malheur
MalheurC

A tool for automatic analysis of malware behavior using machine learning to identify, cluster, and classify malicious software.

#sandbox-analysis#classification#malware-analysis
Stars375
Forks102
Last commit7 years ago
malsub
malsubPython

A Python RESTful API framework for querying multiple online malware analysis and threat intelligence services.

#virustotal#multi-threading#security-automation
Stars366
Forks78
Last commit2 years ago
DarunGrim
DarunGrim

A binary diffing and patch analysis tool for reverse engineering and vulnerability research.

#binary-diffing#vulnerability-research#security-tools
Stars365
Forks66
Last commit6 years ago
PE-Packer
PE-PackerC

A packer for Windows x86 executable files that transforms and encrypts PE files to obstruct reverse engineering.

#pe#assembly#educational
Stars365
Forks55
Last commit1 year ago
DC3-MWCP
DC3-MWCPPython

A framework for parsing configuration information from malware, extracting items like addresses, passwords, and filenames.

#rest-api#stix-output#cli-tool
Stars349
Forks63
Last commit7 days ago
Astral-PE
Astral-PEC#

A low-level mutator for Windows PE files that obfuscates headers and metadata to break static analysis signatures without breaking execution.

#hacktoberfest#pe-obfuscator#pe
Stars348
Forks31
Last commit1 year ago
dynStruct
dynStructC

A reverse engineering tool that uses DynamoRIO and Capstone to automatically recover data structures from ELF binaries by monitoring memory accesses.

#dynamorio#data-structure-recovery#capstone
Stars328
Forks36
Last commit7 years ago
Android Malware Sandbox
Android Malware SandboxJavaScript

A configurable sandbox for dynamic analysis of Android malware using Frida hooks to bypass anti-emulation techniques.

#anti-emulation-bypass#sandbox-environment#avd
Stars307
Forks56
Last commit
glutton
gluttonGo

A protocol-agnostic, low-interaction honeypot that intercepts and logs network traffic to analyze malicious activities.

#hacktoberfest#honeypot#tproxy
Stars306
Forks93
Last commit1 month ago
Morphine
MorphinePascal

Archive mirror of the users section from the historical rootkit.com security research website.

#web-mirror#historical-archive#rootkit
Stars305
Forks161
Last commit9 years ago
Malware Persistence
Malware Persistence

A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.

#malware-detection#red-teaming#awesome-list
Stars303
Forks22
Last commit3 months ago
File Scanning Framework
File Scanning FrameworkPython

A modular, recursive file scanning framework that extends Yara signatures to extract and analyze file objects for malware analysis and intelligence.

#file-analysis#security-automation#file-scanning
Stars294
Forks46
Last commit
PSHunt
PSHuntPowerShell

A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.

#digital-forensics#windows-security#security-automation
Stars292
Forks63
Last commit9 years ago
ROPMEMU
ROPMEMUPython

A framework to analyze, dissect, and decompile complex code-reuse attacks like ROP chains from memory dumps.

#code-emulation#security-analysis#control-flow-recovery
Stars287
Forks42
Last commit10 years ago
OllyDbg OEP finder scripts
OllyDbg OEP finder scriptsBatchfile

A collection of OllyDbg scripts for unpacking and analyzing software protections in reverse engineering.

#ctf-tools#ollydbg#debugging-scripts
Stars278
Forks105
Last commit4 years ago
Bluepot
BluepotJava

A Java-based Bluetooth honeypot for Linux that detects and analyzes Bluetooth-based attacks like BlueBugging and BlueSnarfing.

#honeypot#bluetooth-security#java
Stars277
Forks35
Last commit3 months ago
Ezuri
EzuriGo

A simple Linux ELF runtime crypter that encrypts and loads executables directly into memory to evade detection.

#runtime-encryption#evasion-techniques#penetration-testing
Stars276
Forks55
Last commit1 year ago
PackerAttacker
PackerAttackerC++

A C++ Windows malware analysis tool that uses memory and code hooks to detect and extract hidden code from packers.

#windows-security#detours#c-plus-plus
Stars275
Forks69
Last commit8 years ago
Hostintel
HostintelPython

A modular Python tool that collects threat intelligence for hosts (IPs, domains, FQDNs) from multiple sources and outputs CSV data.

#csv-output#osint#security-automation
Stars274
Forks54
Last commit5 years ago
cuckoo-modified
cuckoo-modifiedPython

A heavily modified version of Cuckoo Sandbox with enhanced malware analysis capabilities, 64-bit support, and anti-evasion techniques.

#sandbox#behavioral-analysis#anti-evasion
Stars273
Forks100
Last commit6 years ago
VolatilityBot
VolatilityBotPython

An automated memory analysis tool for malware samples and memory dumps that extracts executables, processes, injections, and artifacts.

#digital-forensics#malware-analysis#automation-tool
Stars268
Forks51
Last commit5 years ago
detux
detuxPython

A multiplatform Linux sandbox for malware traffic analysis and IOC capture using QEMU emulation.

#sandbox#multi-architecture#ioc-extraction
Stars266
Forks59
Last commit4 years ago
Tango
TangoShell

A Splunk-based platform for deploying honeypots and analyzing attacker sessions with intelligence dashboards and threat feeds.

#honeypot#splunk#sensor-management
Stars255
Forks42
Last commit7 years ago
BoomBox
BoomBoxPowerShell

Automated deployment of a Cuckoo Sandbox malware analysis lab with Windows 10 detonation using Packer and Vagrant.

#security-lab#cuckoo-sandbox#windows-10
Stars240
Forks38
Last commit3 years ago
PINdemonium
PINdemoniumC++

A Windows malware unpacker using Intel PIN for dynamic binary instrumentation and Scylla for import reconstruction.

#unpacker#security-tools#malware-analysis
Stars240
Forks69
Last commit10 years ago
hasherezade persistence demos
hasherezade persistence demosC++

Demonstrates various persistence techniques used by malware, including COM hijacking, extension hijacking, and shim injection.

#windows-security#red-teaming#malware-analysis
Stars229
Forks48
Last commit
PoisonApple
PoisonApplePython

A command-line tool for macOS persistence mechanism emulation, designed for threat hunters and security testing.

#cyber-threat-hunting#python-security#red-teaming
Stars229
Forks32
Last commit4 years ago
Mobile Audit
Mobile AuditHTML

A Django web application for static security analysis (SAST) and malware detection in Android APKs.

#virustotal#apk-analysis#code-security
Stars227
Forks51
Last commit2 months ago
PreviousPage 4 of 7

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
8 years ago
1 year ago
4 years ago
3 years ago
Next
#Reverse Engineering114
#Security Tools84
#Cybersecurity67
#Python62
#Threat Intelligence52
#Binary Analysis52
#Security Research49
#Incident Response46
#Digital Forensics30
#Malware Research29
#Static Analysis28
#Malware27