sandflysecurity / sandfly-entropyscan
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
☆153Updated 9 months ago
Alternatives and similar repositories for sandfly-entropyscan:
Users that are interested in sandfly-entropyscan are comparing it to the libraries listed below
- A guide on how to write fast and memory friendly YARA rules☆141Updated last month
- Automated YARA Rule Standardization and Quality Assurance Tool☆200Updated last week
- Visually inspect and force decode YARA and regex matches found in both binary and text data. With Colors.☆118Updated 3 months ago
- Initial triage of Windows Event logs☆97Updated 9 months ago
- simple YARA-based IOC scanner☆169Updated last month
- Rules Shared by the Community from 100 Days of YARA 2023☆76Updated last year
- LOKI2 - Simple IOC and YARA Scanner☆88Updated 8 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆146Updated last year
- A ProcessMonitor visualization application written in rust.☆177Updated last year
- Elastic Security Labs releases☆61Updated this week
- ☆126Updated 3 weeks ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆101Updated this week
- Collection of rules created using YARA-Signator over Malpedia☆126Updated 4 months ago
- Linux Evidence Acquisition Framework☆114Updated 6 months ago
- A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...☆139Updated last year
- JA4TScan is an active TCP server fingerprinting tool.☆72Updated 7 months ago
- yara detection rules for hunting with the threathunting-keywords project☆113Updated 3 weeks ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆165Updated 2 years ago
- ELFEN: Automated Linux Malware Analysis Sandbox☆122Updated 8 months ago
- BlackBerry Threat Research & Intelligence☆98Updated last year
- Let's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-host…☆119Updated this week
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 3 years ago
- Valhalla API Client☆68Updated 2 years ago
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆245Updated 2 years ago
- Forensic Artifact Collection Tool Matrix☆83Updated 4 months ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆106Updated 2 years ago
- Anything Sysmon related from the MSTIC R&D team☆151Updated 9 months ago
- Repository with selected IOCs and YARA rules for threat hunting.☆35Updated 3 months ago
- This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.☆114Updated last year
- Data visualization for blue teams☆125Updated 2 years ago