mandiant / capa-testfiles
Data to test capa's code and rules.
☆41Updated last week
Alternatives and similar repositories for capa-testfiles:
Users that are interested in capa-testfiles are comparing it to the libraries listed below
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆37Updated last year
- Ghidra plugin for https://analyze.intezer.com☆70Updated 2 years ago
- Symbol hash for ELF files☆107Updated 2 years ago
- Cockroach is your primitive & immortal swiss army knife.☆47Updated 3 years ago
- VSCode extension for the YARA pattern matching language☆63Updated last year
- Unprotect is a python tool for parsing PE malware and extract evasion techniques.☆112Updated last year
- FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.☆50Updated 10 months ago
- Capa analysis importer for Ghidra.☆61Updated 4 years ago
- ☆43Updated 6 years ago
- Malware similarity platform with modularity in mind.☆76Updated 3 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆63Updated 3 years ago
- ☆47Updated 5 years ago
- Various Yara signatures (possibly to be included in a release later).☆86Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 3 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆67Updated 9 months ago
- A script that extracts embedded images from Office Open XML (OOXML) documents and generates image hash similarity graphs that cluster vis…☆20Updated 3 years ago
- Commandline utility to interact with the Malpedia service☆22Updated 5 years ago
- Malware Configuration And Payload Extraction☆18Updated 4 years ago
- Merge all Yara rules from official Yara github repository in one .yar file☆28Updated 6 years ago
- Documentation and parsers for different anti-virus quarantine formats.☆42Updated 4 years ago
- Malware Muncher is a proof-of-concept Python script that utilizes the Frida framework for binary instrumentation and API hooking, enablin…☆43Updated last year
- A powershell parser for https://github.com/ufrisk/MemProcFS☆44Updated 3 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆72Updated last month
- ☆66Updated last year
- Malware Configuration Extraction Modules☆48Updated last year
- TA505 unpacker Python 2.7☆47Updated 4 years ago
- ☆56Updated 3 months ago
- CLI tool to analyze PE files