A YARA & Malware Analysis Toolkit written in Rust.
☆114Jul 24, 2026Updated this week
Alternatives and similar repositories for MalChela
Users that are interested in MalChela are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell toolkit for AMSI/Defender detection-boundary analysis — maps byte offsets to detection triggers in scripts and binaries. Compa…☆36Updated this week
- Forensic tool for extracting and analyzing Google DriveFS cached files and metadata.☆23May 9, 2025Updated last year
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- Chrome Logs Events and Protobuf Parser☆40Dec 13, 2022Updated 3 years ago
- Run TTPs, with AI!☆140Feb 23, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆343Dec 3, 2025Updated 7 months ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆331Feb 26, 2026Updated 5 months ago
- A tool for fetching DFIR and other GitHub tools.☆29Aug 2, 2025Updated 11 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated 10 months ago
- Windows Forensics Environment Builder☆189May 19, 2026Updated 2 months ago
- A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight,…☆46Oct 24, 2025Updated 9 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Jun 27, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Windows forensics Engine☆109Updated this week
- PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.☆36Jan 9, 2025Updated last year
- ☆37Mar 19, 2026Updated 4 months ago
- ☆83Oct 2, 2025Updated 9 months ago
- ☆36Jul 1, 2025Updated last year
- A professional Red Team / Pentest tool for assessing the external perimeter of a company in a complete "black box" mode (zero knowledge, …☆29Feb 15, 2026Updated 5 months ago
- It’s an OSINT reconnaissance poc powered by Local LLMs (Ollama). You can feed it an email, domain, or IP, and it automatically performs m…☆85Nov 20, 2025Updated 8 months ago
- This repository provides a comprehensive Digital Footprint Checklist to help individuals manage their online presence and enhance privacy…☆18Dec 25, 2024Updated last year
- BitUnlocker is a minimal, interactive Bash script that helps unlock BitLocker volumes and either decrypt them to an image file or mount t…☆15Aug 21, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆49Jun 3, 2026Updated last month
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 3 years ago
- macOS forensic acquisition made simple☆288Jun 2, 2026Updated last month
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆296Jun 6, 2026Updated last month
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆54Updated this week
- Fork this repo! Do a Pull Request! As many times as you want! Learn the ins and outs of how to contribute to GitHub! Make your mistakes h…☆15Jun 21, 2024Updated 2 years ago
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- A GeoIP lookup utility utilizing ipinfo.io services.☆30Dec 1, 2023Updated 2 years ago
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆182Updated this week
- yara detection rules for hunting with the threathunting-keywords project☆166May 11, 2025Updated last year
- A DFIR Incident Response AI bot using local Ollama LLM to derrive automated findings from logs☆16Jan 17, 2026Updated 6 months ago
- ☆22Dec 22, 2020Updated 5 years ago
- shellcode transformation tool for YARA evasion☆62Dec 17, 2025Updated 7 months ago
- Rolling Timeline for Incident Recorder.☆14Dec 4, 2023Updated 2 years ago
- IoC Ninja is a Binary Ninja plugin that can improve the QoL of malware analysts.☆17Nov 18, 2025Updated 8 months ago