cylance / rogers
Python command-line tool that uses nearest neighbor search methods for malware similarity analysis
☆16Updated 6 years ago
Alternatives and similar repositories for rogers:
Users that are interested in rogers are comparing it to the libraries listed below
- Handy scripts to speed up malware analysis☆35Updated last year
- Work Fast With the pattern matching swiss knife for malware researchers.☆38Updated 9 years ago
- Volatility Framework plugin to detect various types of hooks as performed by banking Trojans☆41Updated 6 years ago
- revised "peHash: A Novel Approach to Fast Malware Clustering"☆21Updated 8 years ago
- Yara rules for detecting malware☆23Updated 8 months ago
- Generate bulk YARA rules from YAML input☆22Updated 5 years ago
- Malware analyses and helpful scripts☆29Updated 2 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Command-line Interface for Binar.ly☆37Updated 8 years ago
- This repository regroups the Yara Rules for the Unprotect Project☆25Updated 4 years ago
- A collection of Volatility Framework plugins.☆26Updated 11 years ago
- QEMU with rVMI extensions☆25Updated 7 years ago
- API Tracker by Cysinfo Team☆22Updated 8 years ago
- pure Python binary analysis framework☆23Updated 6 years ago
- Proof-of-concept automated baremetal malware analysis framework.☆14Updated 9 years ago
- Plugins for the Viper Framework☆14Updated 5 years ago
- Resolves DLL API entrypoints for a process w/ remote query capabilities.☆55Updated 7 years ago
- Linux-KVM with rVMI extensions☆22Updated 7 years ago
- Emu-strings project - JScript/VBScript automated dropper analysis system☆18Updated 4 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Updated 4 years ago
- Yara rules for quick reverse engineering of malware.☆19Updated 9 years ago
- Automatically exported from code.google.com/p/verify-sigs☆18Updated 8 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- Maltego transforms to pivot between PE files based on their VirusTotal codeblocks☆18Updated 3 years ago
- A tool to generate yara signatures from function blocks☆19Updated 10 years ago
- Analysis PE file or Shellcode☆49Updated 8 years ago
- ☆13Updated 9 years ago
- ☆32Updated 10 months ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- ☆13Updated 4 years ago