decalage2 / balbuzardLinks
Balbuzard is a package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domain names, known file headers, interesting strings, etc). It can also crack malware obfuscation such as XOR, ROL, etc by bruteforcing and checking for those patterns.
☆140Updated 5 years ago
Alternatives and similar repositories for balbuzard
Users that are interested in balbuzard are comparing it to the libraries listed below
Sorting:
- A modern Python-3-based alternative to RegRipper☆198Updated 7 months ago
- A curated list of malware repositories, trackers and malware analysis tools☆88Updated 2 years ago
- ☆84Updated 5 years ago
- Various scripts for different malware families☆106Updated 4 years ago
- repository of tools & resources of the MMD team☆136Updated 3 years ago
- Malware similarity platform with modularity in mind.☆78Updated 4 years ago
- Set of Yara rules for finding files using magics headers☆141Updated 5 years ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆200Updated 7 months ago
- Miscellaneous Malware RE☆196Updated 3 years ago
- Various capabilities for static malware analysis.☆79Updated last year
- A VBA parser and emulation engine to analyze malicious macros.☆96Updated last week
- VSCode extension for the YARA pattern matching language☆63Updated last year
- Yet another registry parser☆136Updated 3 years ago
- ☆128Updated 9 months ago
- MAEC Schemas and Schema Development☆88Updated 5 years ago
- Collection of various files from infected hosts☆75Updated 3 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆121Updated last year
- PE Import Hash Generator☆79Updated 8 years ago
- Lazy Office Analyzer☆122Updated 8 years ago
- unXOR will search a XORed file and try to guess the key using known-plaintext attacks.☆144Updated 5 years ago
- Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect …☆142Updated 3 years ago
- ☆135Updated 6 years ago
- Malquarium - Modern Malware Repository☆47Updated last month
- CLI tool to analyze PE files☆89Updated last year
- Set of tools for interacting with Malshare☆158Updated 5 years ago
- This repository maintains the SaltStack state files for the REMnux distro.☆54Updated this week
- Extract common Windows artifacts from source images and VSCs☆65Updated 4 years ago
- c2 traffic☆191Updated 2 years ago
- Automatic YARA rule generation for Malpedia☆164Updated 3 years ago
- A taxonomy and dictionary of malware behaviors.☆43Updated 6 years ago