kn0wl3dge / mozitools
Mozi Botnet related tools helping to unpack a sample, decode a configuration and track active Mozi nodes using DHT.
☆44Updated 2 years ago
Alternatives and similar repositories for mozitools:
Users that are interested in mozitools are comparing it to the libraries listed below
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆91Updated 3 weeks ago
- Generating YARA rules based on binary code☆207Updated 3 years ago
- Static based decoders for malware samples☆92Updated 4 years ago
- Robust Automated Malware Unpacker☆84Updated last year
- This project fully automates the process of analyzing and exploiting IoT malware to find live CnC servers.☆41Updated 8 months ago
- Automatic YARA rule generation for Malpedia☆159Updated 2 years ago
- c2 traffic☆188Updated 2 years ago
- ☆98Updated 4 years ago
- This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultim…☆103Updated 7 months ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- ☆58Updated 4 years ago
- Symbol hash for ELF files☆108Updated 3 years ago
- IDA python plugin to scan binary with Yara rules☆172Updated last year
- Community modules for CAPE Sandbox☆92Updated last week
- Malware Configuration Extraction Modules☆49Updated last year
- Automatically generate AV byte signatures from sets of similar binaries.☆267Updated 3 months ago
- Quickly debug shellcode extracted during malware analysis☆595Updated last year
- Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.☆225Updated 5 years ago
- My scripts to deobfuscate APT32 malware☆26Updated 2 years ago
- ☆31Updated 6 years ago
- Linux EDR written in Golang and based on eBPF.☆236Updated 2 years ago
- POC for cve-2019-1458☆172Updated 3 years ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆101Updated this week
- Telsy CTI Research Team☆57Updated 4 years ago
- ☆105Updated last year
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago
- Sandfly Linux Stealth Rootkit Decloaking Utility☆100Updated 2 years ago
- A tool for de-obfuscating PowerShell scripts☆68Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago