Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Malware Analysis

Malware Analysis

187 projects

Showing 36 of 187 projects

Android Linux Kernel modules
Android Linux Kernel modulesC

Loadable kernel modules for Android reversing and debugging on controlled systems and emulators.

#debugging-tools#android-lkms#kernel-modules
Stars220
Forks66
Last commit11 years ago
DAMM
DAMMPython

An open-source memory forensics tool built on Volatility for differential analysis and data reduction in malware investigations.

#digital-forensics#volatility#python
Stars214
Forks47
Last commit9 years ago
ProbeDroid
ProbeDroidC++

A dynamic Java code instrumentation SDK for Android apps to profile runtime, examine coverage, and track high-risk behaviors without source code.

#java-instrumentation#runtime-profiling#android
Stars204
Forks34
Last commit7 years ago
dorothy2
dorothy2Ruby

A Ruby framework for automated malware and botnet analysis using sandboxed virtual machines and network traffic dissection.

#network-forensics#couchdb#botnet-analysis
Stars195
Forks33
Last commit2 years ago
VolDiff
VolDiffPython

A Python script that uses Volatility to analyze malware memory footprints by comparing Windows memory images before and after infection.

#digital-forensics#security-tools#malware-analysis
Stars195
Forks45
Last commit8 years ago
Malfunction
MalfunctionPython

A Python toolset for malware analysis using function-level fuzzy hashing to catalog and compare malicious binaries.

#radare2#function-analysis#python
Stars192
Forks32
Last commit10 years ago
Malware Persistence
Malware Persistence

A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.

#windows-security#malware-detection#macos-security
Stars188
Forks16
Last commit2 months ago
VMHunt
VMHuntC++

A toolkit for extracting and simplifying virtualized binary code from 32-bit execution traces.

#execution-traces#malware-analysis#symbolic-execution
Stars180
Forks28
Last commit7 years ago
ADBHoney
ADBHoneyPython

A low-interaction honeypot that mimics Android Debug Bridge (ADB) over TCP/IP to capture malware targeting exposed port 5555.

#honeypot#tcp-ip#android-security
Stars179
Forks35
Last commit1 year ago
hackers-grep
hackers-grepPython

A Python utility to search for strings, imports, exports, and debug symbols within Windows PE executables using regular expressions.

#imports-exports#pe-files#python
Stars170
Forks15
Last commit8 years ago
TypeDB OSI - Cyber Threat Intelligence
TypeDB OSI - Cyber Threat IntelligencePython

A TypeDB schema for representing STIX 2.1 cyber threat intelligence data, enabling structured querying of threat actors, malware, and infrastructure.

#security-data-modeling#cyber#cyber-threat-intelligence
Stars168
Forks20
Last commit
Hontel
HontelPython

A Python-based Telnet honeypot that emulates a Telnet service inside a chroot environment to capture malicious activity.

#honeypot#python-2#python
Stars163
Forks44
Last commit7 years ago
Aleph
AlephCSS

An open-source malware analysis pipeline system that automates sample collection, processing, and JSON-based artifact storage.

#sample-processing#security-automation#python
Stars158
Forks55
Last commit5 years ago
CIRTKit
CIRTKitPython

A unified console for digital forensics and incident response built on the Viper Framework.

#digital-forensics#viper-framework#security-automation
Stars152
Forks23
Last commit9 years ago
CIRTkit
CIRTkitPython

A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.

#digital-forensics#viper-framework#dfir
Stars152
Forks23
Last commit9 years ago
VirtualDeobfuscator
VirtualDeobfuscatorPython

A reverse engineering tool that removes virtual machine-based obfuscation from malware by analyzing runtraces and extracting original bytecode.

#virtual-machine#python#malware-analysis
Stars150
Forks24
Last commit2 years ago
unxor
unxorPython

A tool that uses known-plaintext attacks to decrypt XOR-encoded files by deducing the original keystream.

#forensic-analysis#python#security-tools
Stars146
Forks23
Last commit6 years ago
PEiD (CLI)
PEiD (CLI)Python

Python implementation of PEiD for detecting packers in Windows PE files using signature databases.

#python-tool#peid#pe-file
Stars145
Forks15
Last commit2 years ago
Visualize_Logs
Visualize_LogsHTML

A Python library and CLI for creating interactive visualizations of security and system logs like Cuckoo JSON and ProcMon CSV.

#log-visualization#python-library#command-line-tool
Stars145
Forks31
Last commit3 years ago
binarypig
binarypigJavaScript

A scalable malware processing and analytics platform built on Hadoop Pig for binary data extraction and analysis.

#security-analytics#malware-analysis#binary-analysis
Stars144
Forks42
Last commit12 years ago
Malwarehouse
MalwarehousePython

A command-line utility for storing, tagging, and searching malware samples to help analysts manage their workflow.

#digital-forensics#sample-management#command-line-tool
Stars137
Forks41
Last commit6 months ago
Recomposer
RecomposerPython

Randomly modifies Win32/64 PE files to change their hashes for safer uploading to malware analysis sites.

#hash-evasion#sandbox-evasion#python
Stars132
Forks39
Last commit12 years ago
BluePill
BluePillC++

An open-source dynamic analysis framework that neutralizes anti-analysis behavior in evasive malware during dissection.

#windows-malware#anti-evasion#malware-analysis
Stars129
Forks24
Last commit4 years ago
Posh-VirusTotal
Posh-VirusTotalPowerShell

A PowerShell module for interacting with VirusTotal's API to analyze suspicious files, URLs, domains, and IP addresses.

#security-automation#file-scanning#malware-analysis
Stars124
Forks29
Last commit6 years ago
Fileintel
FileintelPython

A modular Python tool that collects threat intelligence from multiple sources for files identified by their hash.

#nsrl#virustotal#threatcrowd
Stars123
Forks24
Last commit5 years ago
Ember2024
Ember2024Python

A benchmark dataset with 3.2 million malicious and benign files across 6 file types for evaluating malware classifiers.

#pefile#malware-dataset#lightgbm
Stars121
Forks25
Last commit9 months ago
unpacker
unpackerPython

A WinAppDbg script that automates malware unpacking by detecting unpacking behaviors and dumping decrypted memory.

#windows-debugging#python-scripting#winappdbg
Stars121
Forks30
Last commit10 years ago
Vezir Project
Vezir Project

A pre-configured Ubuntu-based virtual machine for mobile application security testing and malware analysis.

#vulnerability-assessment#mobile-security#ios-security
Stars116
Forks21
Last commit10 years ago
MalPipe
MalPipePython

A modular malware and IOC ingestion framework that collects, enriches, and exports threat intelligence from multiple feeds.

#security-automation#security-tools#malware-analysis
Stars110
Forks22
Last commit7 years ago
Ragpicker
RagpickerPython

A plugin-based malware crawler for collecting and pre-analyzing malware samples, useful for antivirus testing and malware analysis.

#pdf-analysis#python#security-tools
Stars94
Forks25
Last commit10 years ago
BODMAS
BODMASPython

An open dataset for learning-based temporal analysis of PE malware, containing over 130,000 Windows PE files with feature vectors and metadata.

#pe-malware#malware-dataset#feature-vectors
Stars93
Forks17
Last commit2 years ago
Packware
PackwarePython

A research project investigating how packers affect the accuracy of static machine-learning malware classifiers.

#adversarial-robustness#cybersecurity-research#reproducible-research
Stars90
Forks18
Last commit2 years ago
mac-a-mal
mac-a-malC

Kernel-mode malicious activity hooking framework for macOS security analysis and malware research.

#kernel-hooking#macos-security#malware-analysis
Stars88
Forks24
Last commit7 years ago
SFlock
SFlockPython

A Python utility for securely unpacking and staging suspicious files, designed for integration with malware analysis tools like Cuckoo Sandbox.

#digital-forensics#sandbox-integration#cuckoo-sandbox
Stars85
Forks56
Last commit2 years ago
Squidmagic
SquidmagicPython

Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.

#python-tool#network-traffic#traffic-analysis
Stars81
Forks25
Last commit8 years ago
Detection Engineering with Splunk
Detection Engineering with Splunk

A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.

#text4shell#vulnerability#splunk
Stars69
Forks10
Last commit2 years ago
PreviousPage 5 of 6

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
5 months ago
Next
#Reverse Engineering93
#Security Tools64
#Cybersecurity61
#Security Research45
#Python45
#Threat Intelligence43
#Binary Analysis41
#Incident Response41
#Static Analysis26
#Digital Forensics25
#Malware Research25
#Malware24