Showing 36 of 235 projects
Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
A PE packer that compresses executables with Huffman encoding and encrypts them with XOR, executing directly from memory.
A Sublime Text 3 plugin providing malware analysis tools like encoding/decoding, XOR brute-forcing, and PE scanning.
Docker container with a CLI toolkit for generating datasets of packed executables and training ML models for packing detection.
A Python tool for patching Dalvik bytecode in DEX files to assist in static analysis of Android applications.
A GUI Windows tool with plugins to unpack, decompress, and decrypt programs protected by UPX, ASPack, FSG, ACProtect, and similar software.
A Python-based low-interaction honeypot with sophisticated emulation for malware collection and analysis.
A library for parsing and manipulating Windows Portable Executable (PE) files.
An ICAP server that scans web content and URLs using YARA rules for security filtering.
A Python-based web server honeypot and service imitation builder for faking HTTP services and recording requests.
A Windows x86 PE packer written in pure C/C++ that implements a linker for repackaging executables with in-memory decompression.
A cross-platform Python tool for detecting packers, cryptors, and compilers in PE files, serving as an alternative to PEiD.
A simple PE file packer that encrypts the .text section with XOR encryption and adds a decryption stub.
Detects packers in PE/ELF/Mach-O executables by analyzing entropy to identify compressed or encrypted bytes.
A Volatility-based script for memory forensics that runs plugins, creates timelines, and scans for malware using YARA, ClamAV, and VirusTotal.
A curated dataset of packed and unpacked PE executables for training machine learning models to detect packing.
A Docker image for running AndroGuard, a Python tool for Android application analysis.
A universal and automated unpacking system for Android applications, supporting both Dalvik and ART runtimes.
A collection of reverse engineering challenges including crackmes, keygenmes, and serialmes for educational purposes.
A framework for automated cryptographic primitive classification using dynamic binary instrumentation and deep learning.
A forensic tool that parses Java Cache IDX files to extract malware download history and binary data for incident response.
A client-minion tool for consistent and safe capture of off-network web resources during security investigations.
An adaptive unpacking tool for tracking packing behaviors and unpacking Android packed/hardened applications.
A Python-based FTP honeypot that captures credentials, malware files, and distributes honeytokens.
Detects packers in Windows PE files using multiple heuristics and PEiD's signature database.
A multithreaded YARA scanner that applies many rules to many files for incident response and malware analysis.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A Python honeyclient for detecting malicious web content through client-side emulation and analysis.
A Python library for interfacing with the cuckoo-modified malware sandbox via its API.
An Express.js honeypot that catches bots scanning for remote and local file inclusion vulnerabilities using fake URLs.
A dataset of ELF files packed with various packers for training machine learning models on executable packing detection.
Adversarial tool that alters packed executables to evade static packing detection by malware analysis tools.
Delphi bindings for the Capstone disassembler library, enabling binary code analysis and reverse engineering.
A portable PEiD implementation using YARA rules for malware analysis without requiring YARA installation.
A dataset of PE files packed with various packers for malware analysis and security research.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.