avast / yaramod
Parsing of YARA rules into AST and building new rulesets in C++.
☆120Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for yaramod
- Automatically generate AV byte signatures from sets of similar binaries.☆259Updated 9 months ago
- Trigram database written in C++, suited for malware indexing☆123Updated last month
- Generating YARA rules based on binary code☆203Updated 3 years ago
- capemon: CAPE's monitor☆102Updated last week
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆241Updated last year
- Various Yara signatures (possibly to be included in a release later).☆85Updated 5 years ago
- Automatic YARA rule generation for Malpedia☆155Updated 2 years ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆86Updated 5 months ago
- Parse YARA rules and operate over them more easily.☆174Updated 4 months ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 2 years ago
- Community modules for CAPE Sandbox☆86Updated this week
- BinSequencer is a script designed to find a common pattern of bytes within a set of samples and generate a YARA rule from the identified…☆74Updated 2 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆73Updated 10 years ago
- ☆51Updated 6 years ago
- Windows API tracer for malware (oldname: unitracer)☆116Updated 7 years ago
- zer0m0n driver for cuckoo sandbox☆87Updated 8 years ago
- A Yara rule generator for finding related samples and hunting☆157Updated 2 years ago
- Robust Automated Malware Unpacker☆84Updated last year
- A mapping of used malware names to commonly known family names☆61Updated last year
- ☆57Updated 3 years ago
- Symbol hash for ELF files☆102Updated 2 years ago
- Alternative YARA scanning engine☆67Updated 2 years ago
- ☆96Updated 4 years ago
- Modified edition of cuckoomon☆48Updated 6 years ago
- IDA python plugin to scan binary with Yara rules☆171Updated 9 months ago
- YARA Language Server☆68Updated this week
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated this week
- Smart DLL execution for malware analysis in sandbox systems☆141Updated 9 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago
- ☆112Updated 8 years ago