CERT-Polska / malduck
Malduck is your ducky companion in malware analysis journeys
☆331Updated last week
Alternatives and similar repositories for malduck
Users that are interested in malduck are comparing it to the libraries listed below
Sorting:
- Malware repository component for samples & static configuration with REST API interface.☆351Updated 2 weeks ago
- A Binary Genetic Traits Lexer Framework☆490Updated 2 months ago
- Distributed malware processing framework based on Python, Redis and S3.☆419Updated last month
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆176Updated 3 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆579Updated last month
- MBC content in markdown☆441Updated last month
- YARA malware query accelerator (web frontend)☆427Updated last month
- Dynamic unpacker based on PE-sieve☆730Updated last month
- c2 traffic☆188Updated 2 years ago
- Research notes☆123Updated 5 months ago
- Automatic YARA rule generation for Malpedia☆160Updated 2 years ago
- A guide on how to write fast and memory friendly YARA rules☆142Updated 3 months ago
- A golang CLI tool to download malware from a variety of sources.☆143Updated last year
- High Octane Triage Analysis☆725Updated last week
- Generating YARA rules based on binary code☆210Updated 3 years ago
- Collection of private Yara rules.☆354Updated 3 weeks ago
- YARA Rules I come across on the internet☆339Updated last year
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆578Updated last year
- The Volatility Collaborative GUI☆242Updated this week
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆375Updated 3 years ago
- IOC from articles, tweets for archives☆313Updated last year
- ☆148Updated 2 years ago
- Ghidra scripts for malware analysis☆97Updated last year
- ☆105Updated last year
- Community modules for CAPE Sandbox☆96Updated 3 weeks ago
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆247Updated 2 years ago
- capemon: CAPE's monitor☆116Updated this week
- Collection of rules created using YARA-Signator over Malpedia☆128Updated 6 months ago
- Live hunting of code injection techniques☆382Updated 5 years ago
- Assortment of hashing algorithms used in malware☆360Updated last month