nsacyber / BAM
The Binary Analysis Metadata tool gathers information about Windows binaries to aid in their analysis. #nsacyber
☆158Updated last year
Alternatives and similar repositories for BAM:
Users that are interested in BAM are comparing it to the libraries listed below
- Automatically generate AV byte signatures from sets of similar binaries.☆271Updated 5 months ago
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆151Updated 4 years ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆161Updated 4 months ago
- ☆65Updated 5 years ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆249Updated 2 years ago
- Ghidra scripts for malware analysis☆97Updated last year
- repository of tools & resources of the MMD team☆131Updated 2 years ago
- CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- p…☆128Updated 2 weeks ago
- A malware analysis and classification tool.☆190Updated 3 years ago
- Symbol hash for ELF files☆110Updated 3 years ago
- ☆105Updated 5 years ago
- PeaceMaker Threat Detection is a Windows kernel-based application that detects advanced techniques used by malware.☆420Updated 4 years ago
- Binee: binary emulation environment☆517Updated 2 years ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- Robust Automated Malware Unpacker☆84Updated 2 years ago
- Generating YARA rules based on binary code☆209Updated 3 years ago
- DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior☆272Updated 5 years ago
- MoP - "Master of Puppets" - Advanced malware tracking framework☆80Updated 8 months ago
- ☆225Updated 2 years ago
- Malduck is your ducky companion in malware analysis journeys☆330Updated this week
- A modern Python-3-based alternative to RegRipper☆194Updated last month
- Driver Initial Reconnaissance Tool☆123Updated 5 years ago
- Ghidra plugin for https://analyze.intezer.com☆70Updated 2 years ago
- Unprotect is a python tool for parsing PE malware and extract evasion techniques.☆115Updated last year
- Ghidra scripts such as a RC4 decrypter, Yara search, stack string decoder, etc.☆159Updated 5 years ago
- Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber☆55Updated 6 years ago
- ☆49Updated 2 years ago
- MAEC Schemas and Schema Development☆87Updated 5 years ago
- Set of Yara rules for finding files using magics headers☆137Updated 4 years ago
- An AFF4 C++ implementation.☆200Updated 2 years ago