Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Malware Analysis

Malware Analysis

235 projects

Showing 36 of 235 projects

Squidmagic
SquidmagicPython

Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.

#python-tool#network-traffic#traffic-analysis
Stars81
Forks25
Last commit8 years ago
Detection Engineering with Splunk
Detection Engineering with Splunk

A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.

#text4shell#vulnerability#splunk
Stars69
Forks10
Last commit22 days ago
hXOR-Packer
hXOR-PackerC++

A PE packer that compresses executables with Huffman encoding and encrypts them with XOR, executing directly from memory.

#huffman-compression#memory-execution#windows-executable
Stars68
Forks15
Last commit4 years ago
SMRT
SMRTPython

A Sublime Text 3 plugin providing malware analysis tools like encoding/decoding, XOR brute-forcing, and PE scanning.

#encoding-decoding#security-tools#malware-analysis
Stars66
Forks15
Last commit1 year ago
Packing-Box
Packing-BoxPython

Docker container with a CLI toolkit for generating datasets of packed executables and training ML models for packing detection.

#malware-packers#pe-elf-mach-o#infosec
Stars65
Forks18
Last commit20 days ago
Dexmod
DexmodPython

A Python tool for patching Dalvik bytecode in DEX files to assist in static analysis of Android applications.

#dex#python-tool#dalvik-bytecode
Stars64
Forks11
Last commit2 years ago
FUU
FUUC++

A GUI Windows tool with plugins to unpack, decompress, and decrypt programs protected by UPX, ASPack, FSG, ACProtect, and similar software.

#assembly#plugin-system#unpacker
Stars64
Forks13
Last commit13 years ago
Amun
AmunPython

A Python-based low-interaction honeypot with sophisticated emulation for malware collection and analysis.

#honeypot#emulation#exploit-capture
Stars63
Forks24
Last commit2 years ago
PeLib
PeLibC++

A library for parsing and manipulating Windows Portable Executable (PE) files.

#retdec-integration#file-format#security-tools
Stars63
Forks29
Last commit6 years ago
Python ICAP Yara
Python ICAP YaraPython

An ICAP server that scans web content and URLs using YARA rules for security filtering.

#icap-server#squid-proxy#python-server
Stars58
Forks13
Last commit1 year ago
honeyhttpd
honeyhttpdPython

A Python-based web server honeypot and service imitation builder for faking HTTP services and recording requests.

#python-web-server#http-server#honeypot
Stars55
Forks14
Last commit2 years ago
theArk
theArkC++

A Windows x86 PE packer written in pure C/C++ that implements a linker for repackaging executables with in-memory decompression.

#c-plus-plus#security-tools#malware-analysis
Stars53
Forks11
Last commit6 years ago
packerid
packeridPython

A cross-platform Python tool for detecting packers, cryptors, and compilers in PE files, serving as an alternative to PEiD.

#python-tool#security-tools#malware-analysis
Stars50
Forks13
Last commit6 years ago
PePacker
PePackerC++

A simple PE file packer that encrypts the .text section with XOR encryption and adds a decryption stub.

#portable-executable#code-obfuscation#windows-executable
Stars50
Forks9
Last commit9 years ago
Bintropy
BintropyPython

Detects packers in PE/ELF/Mach-O executables by analyzing entropy to identify compressed or encrypted bytes.

#python-tool#entropy-analysis#pe-file
Stars50
Forks4
Last commit4 months ago
TotalRecall
TotalRecallPython

A Volatility-based script for memory forensics that runs plugins, creates timelines, and scans for malware using YARA, ClamAV, and VirusTotal.

#digital-forensics#virustotal#clamav
Stars49
Forks7
Last commit9 years ago
Dataset of Packed PE
Dataset of Packed PEPython

A curated dataset of packed and unpacked PE executables for training machine learning models to detect packing.

#upx#labeled-data#pe-file
Stars49
Forks8
Last commit6 months ago
dockerfile/androguard
dockerfile/androguard

A Docker image for running AndroGuard, a Python tool for Android application analysis.

#containerization#androguard#apk-analysis
Stars45
Forks17
Last commit6 years ago
AppSpear
AppSpearC++

A universal and automated unpacking system for Android applications, supporting both Dalvik and ART runtimes.

#dalvik#runtime-analysis#mobile-security
Stars45
Forks22
Last commit8 years ago
RCE Lab
RCE LabHTML

A collection of reverse engineering challenges including crackmes, keygenmes, and serialmes for educational purposes.

#security-training#educational-resources#software-security
Stars44
Forks16
Last commit3 years ago
CryptoKnight
CryptoKnightPython

A framework for automated cryptographic primitive classification using dynamic binary instrumentation and deep learning.

#security-analysis#deep-learning#academic-project
Stars41
Forks11
Last commit6 years ago
Java IDX Parser
Java IDX ParserPython

A forensic tool that parses Java Cache IDX files to extract malware download history and binary data for incident response.

#digital-forensics#python-tool#idx-parser
Stars40
Forks10
Last commit8 years ago
boomerang
boomerangPython

A client-minion tool for consistent and safe capture of off-network web resources during security investigations.

#client-server#rest-api#operational-security
Stars39
Forks6
Last commit9 years ago
PackerGrind
PackerGrindC

An adaptive unpacking tool for tracking packing behaviors and unpacking Android packed/hardened applications.

#runtime-analysis#mobile-security#android-security
Stars37
Forks5
Last commit4 years ago
honeypot-ftp
honeypot-ftpPython

A Python-based FTP honeypot that captures credentials, malware files, and distributes honeytokens.

#credential-capture#python#malware-analysis
Stars34
Forks13
Last commit2 years ago
PyPackerDetect (refactored)
PyPackerDetect (refactored)Python

Detects packers in Windows PE files using multiple heuristics and PEiD's signature database.

#heuristics#peid#pe-file
Stars28
Forks4
Last commit1 year ago
PyaraScanner
PyaraScannerPython

A multithreaded YARA scanner that applies many rules to many files for incident response and malware analysis.

#yara-scanner#dfir#file-scanning
Stars27
Forks4
Last commit8 years ago
Lophiid
LophiidGo

A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.

#ai#honeypot#web-security
Stars27
Forks5
Last commit2 months ago
PhoneyC
PhoneyCC

A Python honeyclient for detecting malicious web content through client-side emulation and analysis.

#honeypot#web-security#client-emulation
Stars26
Forks9
Last commit11 years ago
cuckoo-modified-api
cuckoo-modified-apiPython

A Python library for interfacing with the cuckoo-modified malware sandbox via its API.

#digital-forensics#python-library#security-automation
Stars23
Forks8
Last commit9 years ago
Express honeypot
Express honeypotJavaScript

An Express.js honeypot that catches bots scanning for remote and local file inclusion vulnerabilities using fake URLs.

#honeypot#exploit#web-security
Stars21
Forks8
Last commit1 month ago
Dataset of Packed ELF
Dataset of Packed ELF

A dataset of ELF files packed with various packers for training machine learning models on executable packing detection.

#upx#malware-packers#malware-analysis
Stars21
Forks3
Last commit6 months ago
NotPacked++
NotPacked++C++

Adversarial tool that alters packed executables to evade static packing detection by malware analysis tools.

#packing#static-detection-evasion#obfuscation
Stars21
Forks4
Last commit1 year ago
Capstone4Delphi
Capstone4DelphiPascal

Delphi bindings for the Capstone disassembler library, enabling binary code analysis and reverse engineering.

#pascal#disassembler#x86-64
Stars19
Forks4
Last commit5 years ago
PEiD (yara)
PEiD (yara)Go

A portable PEiD implementation using YARA rules for malware analysis without requiring YARA installation.

#peid#yara-rules#security-tools
Stars17
Forks7
Last commit9 years ago
PackingData
PackingData

A dataset of PE files packed with various packers for malware analysis and security research.

#pe-files#malware-analysis#binary-analysis
Stars16
Forks10
Last commit7 years ago
PreviousPage 6 of 7

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
Next
#Reverse Engineering114
#Security Tools84
#Cybersecurity67
#Python62
#Threat Intelligence52
#Binary Analysis52
#Security Research49
#Incident Response46
#Digital Forensics30
#Malware Research29
#Static Analysis28
#Malware27