c3rb3ru5d3d53c / mwcfg
A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck
☆127Updated last year
Alternatives and similar repositories for mwcfg:
Users that are interested in mwcfg are comparing it to the libraries listed below
- Malware Configuration Extraction Modules☆49Updated last year
- A golang CLI tool to download malware from a variety of sources.☆142Updated last year
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆44Updated 2 years ago
- ☆104Updated last year
- Rules Shared by the Community from 100 Days of YARA 2023☆77Updated last year
- JPCERT/CC public YARA rules repository☆106Updated 3 months ago
- The Windows Malware Analysis Reversing Core Tools☆92Updated 4 years ago
- ☆13Updated last week
- Repository of Yara Rules☆103Updated last month
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆108Updated 3 years ago
- Lazarus analysis tools and research report☆55Updated last year
- YARA rule analyzer to improve rule quality and performance☆97Updated 2 months ago
- A guide on how to write fast and memory friendly YARA rules☆141Updated last month
- Unprotect is a python tool for parsing PE malware and extract evasion techniques.☆114Updated last year
- Use YARA rules on Time Travel Debugging traces☆89Updated last year
- runsc loads 32/64 bit shellcode (depending on how runsc is compiled) in a way that makes it easy to load in a debugger. This code is base…☆36Updated 2 years ago
- Yara Rules for Modern Malware☆73Updated last year
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆58Updated 2 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- Python based CLI for MalwareBazaar☆36Updated 4 months ago
- Simple PowerShell script to enable process scanning with Yara.☆92Updated 2 years ago
- Scripts and tools accompanying HP Threat Research blog posts and reports.☆50Updated 11 months ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- A C# based tool for analysing malicious OneNote documents☆111Updated last year
- Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.☆73Updated 4 years ago
- Malware Samples that could be used for teaching students about malware analysis.☆53Updated 11 months ago
- Malware similarity platform with modularity in mind.☆78Updated 3 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆41Updated last year
- A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...☆139Updated last year