Qiling Advanced Binary Emulation framework. Contribute to qilingframework/qiling development by creating an account on GitHub.
FileInsight-plugins: a decoding toolbox of McAfee FileInsight hex editor for malware analysis - nmantani/FileInsight-plugins A collection of hacking / penetration testing resources to make you better! - vitalysim/Awesome-Hacking-Resources Toolkit collection developed to help malware analysts dissecting and detecting the packer used by GreyEnergy samples. - NozomiNetworks/greyenergy-unpacker Ragpicker is a Plugin based malware crawler with pre-analysis and reporting functionalities. Use this tool if you are testing antivirus products, collecting malware for another analyzer/zoo. - robbyFux/Ragpicker GitHub Gist: instantly share code, notes, and snippets. PPEE (puppy) – A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail. Contribute to fireeye/flare-vm development by creating an account on GitHub.
ripPE - section extractor and profiler for PE file analysis - matonis/ripPE ClamAV implemented in C++. Contribute to sandboxshield/clamdroid development by creating an account on GitHub. .NET deobfuscator and unpacker. Contribute to 0xd4d/de4dot development by creating an account on GitHub. Portable Cleaning Lab (PCL) Scripting and Utilities For A Completely Portable Malware Removal Experience - esc0rtd3w/portable-cleaning-lab A curated list of awesome Hacking tutorials, tools and resources - carpedm20/awesome-hacking Some GitHub scripts. Contribute to eugenekolo/github-scripts development by creating an account on GitHub. Malware detection with Ossec. @ santiagobassett. Setting up a malware lab. @ santiagobassett. MW c ollection techniques. @ santiagobassett. Honeypot. Dionaea : Low interaction honeypot that emulates vulnerable network services.
https://zeltser.com/build-malware-analysis-toolkit/ https://zeltser.com/vmware-malware-analysis/ https://zeltser.com/malware-analysis-tool-frameworks/ ClamAV implemented in C++. Contribute to sandboxshield/clamdroid development by creating an account on GitHub. Some GitHub scripts. Contribute to eugenekolo/github-scripts development by creating an account on GitHub. isodump - ISO dump utility. Contribute to evild3ad/isodump development by creating an account on GitHub. A curated list of awesome Hacking tutorials, tools and resources - carpedm20/awesome-hacking A merged collection of hosts from reputable sources. #StayEnergized! - Fun4Android/Energized My curated list of awesome links, resources and tools on infosec related topics - pe3zx/my-infosec-awesome
Tools in BlackArch - Free ebook download as PDF File (.pdf), Text File (.txt) or view presentation slides online. rere
Clone or download But it seemed to me that expert users (i.e. malware analysts) could use a tool which would If you want to see some sample reports generated by the tool, feel free to try out the web It is a robust parser for PE files with a flexible plugin architecture which allows users to statically analyze files in-depth. Clone or download It can pack regularly compiled PE files into reflective payloads that can load and to bypass anti-virus, firewall, IDS, IPS products and application white-listing mitigations. docker run -it -v /tmp/:/tmp/ amber /tmp/file.exe Branch: master. New pull request. Find file. Clone or download MalScan is a simple PE File Heuristics Scanners written in python that you can use to quickly A collection of malware samples and relevant dissection information, most probably referenced from malware-samples/CVE-2018-4878-Adobe-Flash-DRM-UAF-0day/pe- "downloaded": [], "permalink": "https://www.virustotal.com/file/ 15 Jul 2019 An open source script to perform malware static analysis on Portable Executable Branch: master. New pull request. Find file. Clone or download Can be run on single or multiple PE (placed inside a directory); Output will script to perform static analysis on a Malware Binary File (portable executable). Branch: master. New pull request. Find file. Clone or download The Script uses the pefile module to read information from PE (Portable Executable) files. If you run into issues, feel free to get on touch on Twitter, check the current issues