sandflysecurity / sandfly-entropyscanLinks
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
☆167Updated last year
Alternatives and similar repositories for sandfly-entropyscan
Users that are interested in sandfly-entropyscan are comparing it to the libraries listed below
Sorting:
- YaraScanner is a file pattern-matching tool based on YARA rules.☆59Updated 2 years ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆29Updated 2 months ago
- Linux Evidence Acquisition Framework☆117Updated last year
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- IOCs published by Black Lotus Labs☆124Updated last month
- A Self-Contained Open-Source Cyberattack Experimentation Testbed☆43Updated 6 months ago
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆106Updated last year
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- Data visualization for blue teams☆126Updated 2 years ago
- Linux #rootkit and #malware revealer☆28Updated last year
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆257Updated 2 years ago
- LOKI2 - Simple IOC and YARA Scanner☆107Updated 5 months ago
- Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulatio…☆141Updated 9 months ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- Golang Parser for Microsoft Event Logs☆105Updated last month
- Tool to analyze and detect MITM phishing toolkits on the web.☆83Updated 4 years ago
- Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.☆143Updated 2 months ago
- QuickSand document and PDF malware analysis tool written in Python☆133Updated last month
- simple YARA-based IOC scanner☆170Updated last week
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆106Updated 3 years ago
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection☆164Updated 3 years ago
- A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...☆141Updated 2 years ago
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆79Updated 2 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆75Updated 3 years ago
- Yara Rules for Modern Malware☆78Updated last year
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆170Updated 3 years ago
- A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.☆137Updated last year
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- ELFEN: Automated Linux Malware Analysis Sandbox☆128Updated 3 months ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆113Updated 7 months ago