decalage2 / balbuzardLinks
Balbuzard is a package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domain names, known file headers, interesting strings, etc). It can also crack malware obfuscation such as XOR, ROL, etc by bruteforcing and checking for those patterns.
☆140Updated 6 years ago
Alternatives and similar repositories for balbuzard
Users that are interested in balbuzard are comparing it to the libraries listed below
Sorting:
- A modern Python-3-based alternative to RegRipper☆205Updated 10 months ago
- ☆85Updated 6 years ago
- Set of Yara rules for finding files using magics headers☆142Updated 5 years ago
- Various scripts for different malware families☆106Updated 4 years ago
- Yet another registry parser☆138Updated 3 years ago
- repository of tools & resources of the MMD team☆138Updated 3 years ago
- Miscellaneous Malware RE☆195Updated 3 years ago
- Malquarium - Modern Malware Repository☆47Updated last week
- Collection of various files from infected hosts☆76Updated 3 years ago
- ☆128Updated 11 months ago
- VSCode extension for the YARA pattern matching language☆63Updated 2 years ago
- A VBA parser and emulation engine to analyze malicious macros.☆97Updated last month
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆122Updated last year
- unXOR will search a XORed file and try to guess the key using known-plaintext attacks.☆145Updated 5 years ago
- Malware similarity platform with modularity in mind.☆80Updated 4 years ago
- A curated list of malware repositories, trackers and malware analysis tools☆94Updated 2 years ago
- Various capabilities for static malware analysis.☆79Updated last year
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆206Updated 10 months ago
- PE Import Hash Generator☆79Updated 8 years ago
- Lazy Office Analyzer☆121Updated 8 years ago
- MAEC Schemas and Schema Development☆89Updated 6 years ago
- Community modules for FAME☆65Updated last month
- Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.☆85Updated 2 years ago
- Tool to help analyze PDF files☆190Updated 11 years ago
- Extract common Windows artifacts from source images and VSCs☆63Updated 4 years ago
- Process HTTP Pcaps With YARA☆108Updated 12 years ago
- ☆136Updated 7 years ago
- c2 traffic☆193Updated 2 years ago
- Set of tools for interacting with Malshare☆159Updated 5 years ago
- Generate a Yara rule to find base64-encoded files containg a specific keyword☆40Updated 7 years ago