sandflysecurity / sandfly-entropyscanLinks
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
☆167Updated last year
Alternatives and similar repositories for sandfly-entropyscan
Users that are interested in sandfly-entropyscan are comparing it to the libraries listed below
Sorting:
- YaraScanner is a file pattern-matching tool based on YARA rules.☆59Updated 2 years ago
- IOCs published by Black Lotus Labs☆124Updated 2 months ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆29Updated 3 months ago
- Data visualization for blue teams☆127Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulatio…☆141Updated 10 months ago
- Harvest Linux forensic data for operational triage of an event.☆52Updated last month
- LOKI2 - Simple IOC and YARA Scanner☆109Updated 6 months ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.☆119Updated 2 years ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆147Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection☆164Updated 3 years ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆170Updated 3 years ago
- Initial triage of Windows Event logs☆105Updated last year
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆133Updated 3 years ago
- Yara Rules for Modern Malware☆78Updated last year
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆106Updated 3 years ago
- yara detection rules for hunting with the threathunting-keywords project☆156Updated 7 months ago
- Forensic Artifact Collection Tool Matrix☆91Updated last year
- A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.☆137Updated last year
- simple YARA-based IOC scanner☆172Updated 3 weeks ago
- Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.☆144Updated last week
- Linux Evidence Acquisition Framework☆117Updated last year
- C2 Active Scanner☆60Updated last year
- Lightweight Python-Based Malware Analysis Pipeline☆36Updated 3 weeks ago
- firedrill is a malware simulation harness for evaluating your security controls☆195Updated last year
- Signature based honeypot detector tool written in Golang☆107Updated 9 months ago
- Blueteam operational triage registry hunting/forensic tool.☆150Updated 3 months ago
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆79Updated 2 years ago