csvl / SEMALinks
SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create representative signatures based on System Call Dependency graph (SCDG). Those SCDGs can be exploited in machine learning modules to do classification/detection.
☆119Updated 10 months ago
Alternatives and similar repositories for SEMA
Users that are interested in SEMA are comparing it to the libraries listed below
Sorting:
- ☆85Updated 5 months ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆96Updated 3 weeks ago
- Dynamic-Static binary instrumentation framework on top of GDB☆50Updated 2 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆83Updated 3 years ago
- Slides, recordings and materials of my public presentations, talks and workshops.☆81Updated 2 months ago
- ☆116Updated 3 years ago
- ELF binary forensics tool for APT, virus, backdoor and rootkit detection☆51Updated last year
- A tool for firmware cartography☆165Updated 2 months ago
- Leveraging CVEs as North Stars in vulnerability discovery and comprehension.☆71Updated last year
- Hardening code obfuscation against automated attacks☆152Updated 2 years ago
- ☆74Updated last year
- Leveraging patch diffing to discover new vulnerabilities☆139Updated last year
- Rerousces related to time-travel debugging (TTD)☆28Updated last month
- Static Binary Instrumentation tool for Windows x64 executables☆207Updated 4 months ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆119Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- IDA Pro plugin to aid with the analysis of native IIS modules☆21Updated last year
- ☆15Updated 2 years ago
- FLARE Team's Binary Navigator☆304Updated last month
- How to retro theme your Ghidra☆35Updated 3 months ago
- ☆149Updated 2 years ago
- Powershell script deobfuscation using AST in Python☆73Updated 4 months ago
- CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- p…☆135Updated 3 weeks ago
- ☆24Updated last year
- ☆84Updated last year
- Get information about stripped rust executables☆42Updated 8 months ago
- ☆69Updated 6 months ago
- UnpacMe IDA Byte Search☆29Updated 2 years ago
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆86Updated 8 months ago
- Writeups for CTF challenges☆35Updated 2 years ago