csvl / SEMALinks
SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create representative signatures based on System Call Dependency graph (SCDG). Those SCDGs can be exploited in machine learning modules to do classification/detection.
☆119Updated 9 months ago
Alternatives and similar repositories for SEMA
Users that are interested in SEMA are comparing it to the libraries listed below
Sorting:
- ☆85Updated 4 months ago
- ☆110Updated 3 years ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆96Updated last week
- Dynamic-Static binary instrumentation framework on top of GDB☆50Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- ☆16Updated 2 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆82Updated 3 years ago
- Writeups for CTF challenges☆34Updated 2 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆76Updated 7 months ago
- FLARE Team's Binary Navigator☆297Updated last week
- A tool for firmware cartography☆161Updated 3 weeks ago
- This repository contains an IDA processor for loading and disassembling compiled yara rules.☆43Updated 11 months ago
- Rerousces related to time-travel debugging (TTD)☆24Updated last month
- Powershell script deobfuscation using AST in Python☆72Updated 3 months ago
- Dataset of packed PE samples☆41Updated last year
- Slides, recordings and materials of my public presentations, talks and workshops.☆81Updated last month
- How to retro theme your Ghidra☆35Updated 2 months ago
- Tools developed by the Zscaler ThreatLabz Threat Intelligence team☆90Updated 3 weeks ago
- ☆74Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆86Updated 6 months ago
- Get information about stripped rust executables☆40Updated 7 months ago
- A collection of ready-to-use library code and symbols for the MinHash-based Code Relationship & Investigation Toolkit (MCRIT)☆12Updated 2 weeks ago
- ☆15Updated 2 years ago
- ☆61Updated 5 months ago
- ☆32Updated 3 years ago
- IDA Pro plugin to aid with the analysis of native IIS modules☆21Updated last year
- ELF binary forensics tool for APT, virus, backdoor and rootkit detection☆50Updated last year
- A headless, extendable, multi-session, IDA Pro MCP framework.☆84Updated 3 months ago
- CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- p…☆135Updated last week
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆46Updated 2 years ago