google / vxsig
Automatically generate AV byte signatures from sets of similar binaries.
☆268Updated 4 months ago
Alternatives and similar repositories for vxsig:
Users that are interested in vxsig are comparing it to the libraries listed below
- SMDA is a minimalist recursive disassembler library that is optimized for accurate Control Flow Graph (CFG) recovery from memory dumps.☆231Updated this week
- Generating YARA rules based on binary code☆208Updated 3 years ago
- Parsing of YARA rules into AST and building new rulesets in C++.☆124Updated last week
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆249Updated 2 years ago
- Trigram database written in C++, suited for malware indexing☆125Updated 5 months ago
- grap: define and match graph patterns within binaries☆154Updated 2 years ago
- ☆113Updated 8 years ago
- Symbol hash for ELF files☆108Updated 3 years ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 3 years ago
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆91Updated last month
- capemon: CAPE's monitor☆115Updated this week
- IDA python plugin to scan binary with Yara rules☆172Updated last year
- Windows API tracer for malware (oldname: unitracer)☆117Updated 7 years ago
- Automatically rebuild Import Address Table for dumped PE file. With python bindings!☆118Updated 6 years ago
- scripts/plugins for IDA Pro☆172Updated 3 months ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- Binee: binary emulation environment☆515Updated 2 years ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- Set of antianalysis techniques found in malware☆132Updated last year
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆70Updated 11 months ago
- ☆226Updated last year
- Tools for instrumenting Windows Defender's mpengine.dll☆294Updated 6 years ago
- Static unpacker for FinSpy VM☆100Updated 3 years ago
- Robust Automated Malware Unpacker☆84Updated last year
- Yara rule making tool (IDA Pro & Binary Ninja & Cutter & Ghidra Plugin)☆231Updated 6 months ago
- A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3☆302Updated 6 years ago
- Toolkit for enriching and speeding up static malware analysis☆168Updated 3 years ago
- A tool to detect and crash Cuckoo Sandbox☆293Updated 8 months ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆181Updated 4 years ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆161Updated 4 months ago