Balbuzard is a package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domain names, known file headers, interesting strings, etc). It can also crack malware obfuscation such as XOR, ROL, etc by bruteforcing and checking for those patterns.
☆143Jan 10, 2020Updated 6 years ago
Alternatives and similar repositories for balbuzard
Users that are interested in balbuzard are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ExeFilter is an open-source tool and framework to filter file formats in e-mails, web pages or files. It detects many common file formats…☆73Dec 13, 2021Updated 4 years ago
- Tool to help guess a files 256 byte XOR key by using frequency analysis☆91Jun 11, 2018Updated 8 years ago
- unXOR will search a XORed file and try to guess the key using known-plaintext attacks.☆145Apr 23, 2020Updated 6 years ago
- A VBA parser and emulation engine to analyze malicious macros.☆1,124Jul 10, 2024Updated 2 years ago
- A GC link parser for both linkfiles and jumplists.☆18Oct 28, 2016Updated 9 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Yara rules for malware families seen as part of targeted threats project☆145Nov 17, 2016Updated 9 years ago
- hopefully a source-to-source deobfuscator, aiming at deobfuscating common scripts languages such as Powershell, VBA and Javascript. Curre…☆41Aug 17, 2019Updated 7 years ago
- FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.☆4,141Updated this week
- Yara rules for quick reverse engineering of malware.☆18Dec 9, 2015Updated 10 years ago
- Malware.lu configuration extractor☆26Mar 27, 2014Updated 12 years ago
- oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware a…☆3,408Feb 14, 2026Updated 6 months ago
- APIInfo Plugin (x86) - A Plugin For x64dbg☆52Jul 17, 2018Updated 8 years ago
- Set of Yara rules for finding files using magics headers☆142Sep 8, 2020Updated 5 years ago
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆37Jan 2, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆164Dec 15, 2024Updated last year
- Tools for parsing Forensic images☆41Dec 14, 2018Updated 7 years ago
- A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.☆13Apr 1, 2019Updated 7 years ago
- Volatility plugin for extracts configuration data of known malware☆498Dec 22, 2023Updated 2 years ago
- MAEC Schemas and Schema Development☆89Jan 29, 2020Updated 6 years ago
- Carve Windows Prefetch files from arbitrary binary data☆16Jun 11, 2017Updated 9 years ago
- Listing of YARA rules I wrote for Live and Retro hunts. Includes Jupyter infostealer, suspicious powershell, dll hijacking, vbs downloade…☆17Jun 26, 2026Updated 2 months ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆345Jun 25, 2022Updated 4 years ago
- Noriben - Portable, Simple, Malware Analysis Sandbox☆1,299Mar 26, 2026Updated 5 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆390May 11, 2022Updated 4 years ago
- A machine learning tool that ranks strings based on their relevance for malware analysis.☆762Jul 24, 2026Updated last month
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆25Sep 26, 2023Updated 2 years ago
- A collection of YARA rules for public use. Built from information in intelligence profiles, dossiers and file work.☆18Sep 10, 2023Updated 2 years ago
- A python script for easy static analysis and automatic signature generation of malware.☆12Sep 30, 2013Updated 12 years ago
- Malware similarity platform with modularity in mind.☆79Jul 18, 2021Updated 5 years ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux☆519Oct 21, 2022Updated 3 years ago
- PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.☆628Aug 8, 2022Updated 4 years ago
- Malware analysis tool☆22Apr 27, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A taxonomy and dictionary of malware behaviors.☆43Aug 20, 2019Updated 7 years ago
- Windows Live Artifacts Acquisition Script☆193Jun 20, 2022Updated 4 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆120Apr 27, 2026Updated 4 months ago
- IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228☆15Dec 19, 2021Updated 4 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆41Jul 29, 2020Updated 6 years ago
- Builds malware analysis Windows VMs so that you don't have to.☆1,046Aug 23, 2021Updated 5 years ago
- Decoders for 7ev3n ransomware☆17Oct 24, 2016Updated 9 years ago