Showing 34 of 142 projects
A collection of OllyDbg scripts for unpacking and analyzing software protections in reverse engineering.
A Java-based Bluetooth honeypot for Linux that detects and analyzes Bluetooth-based attacks like BlueBugging and BlueSnarfing.
A heavily modified version of Cuckoo Sandbox with enhanced malware analysis capabilities, 64-bit support, and anti-evasion techniques.
An automated memory analysis tool for malware samples and memory dumps that extracts executables, processes, injections, and artifacts.
A multiplatform Linux sandbox for malware traffic analysis and IOC capture using QEMU emulation.
A Python library for crafting and dissecting packets using SAP's proprietary network protocols and file formats.
ARMv7 payload for arbitrary code execution on MediaTek bootloaders, enabling bootloader modification and customization.
A PowerShell module for defining in-memory enums, structs, and Win32 functions without compiling C#.
Demonstrates various persistence techniques used by malware, including COM hijacking, extension hijacking, and shim injection.
A Python tool that analyzes embedded device firmware to identify potential security vulnerabilities and sensitive indicators.
A dynamic Java code instrumentation SDK for Android apps to profile runtime, examine coverage, and track high-risk behaviors without source code.
A framework for exploiting Android devices and applications for security testing and vulnerability assessment.
A Ruby framework for automated malware and botnet analysis using sandboxed virtual machines and network traffic dissection.
A security research diagram mapping attack paths to exploit GitHub Actions misconfigurations for red team engagements.
A toolkit for extracting and simplifying virtualized binary code from 32-bit execution traces.
A Torch-based deep learning project for breaking CAPTCHA systems using CNN and RNN architectures.
A binary instrumentation framework for analyzing and modifying Android app Dalvik bytecode.
An archive of Android security presentations and whitepapers from conferences with preserved references.
A Python utility to search for strings, imports, exports, and debug symbols within Windows PE executables using regular expressions.
A Python-based Telnet honeypot that emulates a Telnet service inside a chroot environment to capture malicious activity.
A community-curated collection of tips, tools, and resources for Capture The Flag (CTF) competitions and security research.
A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.
A Python CLI framework for automotive security testing, exploiting known CAN Bus vulnerabilities and fun hacks.
A reverse engineering assistant that uses a locally running LLM to analyze Hex-Rays pseudocode for improved code understanding.
An open-source dynamic analysis framework that neutralizes anti-analysis behavior in evasive malware during dissection.
A library to call functions from stripped binaries across platforms using only file name, offset, and signature.
A simple framework to extract actionable data like C&C servers and phone numbers from Android malware samples.
A kernel API fuzzer for macOS that automatically infers API models from execution logs to generate targeted fuzzers.
Kernel-mode malicious activity hooking framework for macOS security analysis and malware research.
A simulator for analyzing Tor network path selection and traffic correlation attacks under realistic adversarial models.
An RDP honeypot that captures attack telemetry by simulating Windows RDP sessions with virtual machines.
A forensic tool for dumping memory from Android devices requiring root access.
A Python tool for patching Dalvik bytecode in DEX files to assist in static analysis of Android applications.
A Python-based low-interaction honeypot with sophisticated emulation for malware collection and analysis.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.