SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create representative signatures based on System Call Dependency graph (SCDG). Those SCDGs can be exploited in machine learning modules to do classification/detection.
☆122Mar 10, 2025Updated last year
Alternatives and similar repositories for SEMA
Users that are interested in SEMA are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Translation of SSH3 project (from commit c39bb79cdce479f6095ab154a32a168e14d73b57) to Python 3 library. Check the original project for mo…☆14Jan 7, 2024Updated 2 years ago
- This tool presents a novel approach to bolstering network protocol verification by integrating the Shadow network simulator with the Ivy …☆42Updated this week
- BountyDrive is a comprehensive tool designed for penetration testers and cybersecurity researchers. It integrates various modules for per…☆18Jul 15, 2024Updated 2 years ago
- Common User Passwords Profiler (CUPP) in Rust☆28Aug 8, 2024Updated 2 years ago
- BountyDork is a comprehensive tool designed for penetration testers and cybersecurity researchers. It integrates various modules for perf…☆26Jun 25, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Federated Learning based Android Malware Classification System☆28Feb 15, 2024Updated 2 years ago
- ☆14May 30, 2022Updated 4 years ago
- Official Repository of "Robust Malware Classification via Deep Graph Networks on Call Graph Topologies" (ESANN 2021)☆14Jun 16, 2023Updated 3 years ago
- Found resources in my malware researching adventure.☆17Dec 18, 2022Updated 3 years ago
- Lightweight PDB symbol parser and resolver☆30Oct 28, 2024Updated last year
- ☆12Mar 23, 2019Updated 7 years ago
- BinRec: Dynamic Binary Lifting and Recompilation☆150Sep 18, 2023Updated 3 years ago
- A Unit-Based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes☆49Sep 6, 2026Updated 2 weeks ago
- [code] "CFGExplainer: Explaining Graph Neural Network-Based Malware Classification from Control Flow Graphs" by Jerome Dinal Herath, Prit…☆41Aug 2, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An optimizing decompiler (modified to use remill semantics)☆30Jan 4, 2019Updated 7 years ago
- Detection and identification of bat species in audio recordings by applying multi-label Machine Learning techniques.☆16Aug 29, 2023Updated 3 years ago
- IDA plugin for analyzing, filtering and tracing functions and call flows☆17Nov 6, 2023Updated 2 years ago
- ☆10Jul 9, 2020Updated 6 years ago
- Documents the reverse engineering and partial disabling of Steam's CEG anti-tamper protections in T6SP, while preserving its anti-piracy …☆59May 6, 2025Updated last year
- Exemplary LLVM function pass implementing Control Flow Flattening.☆17May 2, 2018Updated 8 years ago
- Self-hosting binary instrumentation framework for security research☆12Apr 10, 2023Updated 3 years ago
- Linux Kernel Rookit Hooking Mechanism☆33Oct 9, 2025Updated 11 months ago
- ☆13Jan 30, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- API Hooking Engine on Windows 10☆12May 10, 2024Updated 2 years ago
- Python bindings for the Icicle emulator.☆43Nov 6, 2025Updated 10 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆101Jul 28, 2024Updated 2 years ago
- BE-PUM (Binary Emulation for PUshdown Model) is a project for analyzing and detecting binary files. Its main focus is on generating CFG (…☆20Dec 25, 2017Updated 8 years ago
- A post-processing script for TinyTracer☆40Mar 22, 2023Updated 3 years ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆97Jul 7, 2025Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆86May 31, 2025Updated last year
- Dataset of packed ELF samples☆22Jan 24, 2026Updated 7 months ago
- Obfuscat is a tool and framework for obfuscation with predictable size and runtime overhead.☆39Jan 15, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A cross platform framework to recover driver's communication interface.☆11Mar 26, 2021Updated 5 years ago
- A small tool to unmap PE memory dumps.☆11Nov 9, 2023Updated 2 years ago
- A collection of Proof-of-Concept implementations of various anti-disassembly techniques for ARM32 and ARM64 architectures.☆81Apr 18, 2025Updated last year
- Sys, but no longer in Haskell☆20Mar 14, 2022Updated 4 years ago
- LLVM Graph View for VSCode☆40Mar 25, 2025Updated last year
- ☆13Mar 28, 2022Updated 4 years ago
- Control-Flow Graph (CFG) Visualizer for VSCode☆68Jun 29, 2026Updated 2 months ago