sandflysecurity / sandfly-entropyscanLinks
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
☆167Updated last year
Alternatives and similar repositories for sandfly-entropyscan
Users that are interested in sandfly-entropyscan are comparing it to the libraries listed below
Sorting:
- IOCs published by Black Lotus Labs☆124Updated 3 weeks ago
- YaraScanner is a file pattern-matching tool based on YARA rules.☆59Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆29Updated last month
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- LOKI2 - Simple IOC and YARA Scanner☆106Updated 4 months ago
- Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.☆143Updated 2 months ago
- Data visualization for blue teams☆126Updated 2 years ago
- QuickSand document and PDF malware analysis tool written in Python☆135Updated 3 weeks ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- simple YARA-based IOC scanner☆170Updated last month
- Automated YARA Rule Standardization and Quality Assurance Tool☆257Updated last week
- A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...☆140Updated 2 years ago
- Linux #rootkit and #malware revealer☆28Updated last year
- yara detection rules for hunting with the threathunting-keywords project☆153Updated 6 months ago
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆107Updated last year
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆257Updated 2 years ago
- ELFEN: Automated Linux Malware Analysis Sandbox☆129Updated 3 months ago
- Signature based honeypot detector tool written in Golang☆106Updated 8 months ago
- Forensic Artifact Collection Tool Matrix☆91Updated last year
- File analysis and management framework.☆90Updated 2 years ago
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection☆163Updated 3 years ago
- Collection of rules created using YARA-Signator over Malpedia☆141Updated last year
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆109Updated 6 months ago
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆133Updated 3 years ago
- A minimalistic cross-platform malware scanner with non-blocking realtime filesystem monitoring using YARA rules.☆230Updated 3 years ago
- Golang Parser for Microsoft Event Logs☆105Updated 2 weeks ago
- Linux Evidence Acquisition Framework☆118Updated last year
- firedrill is a malware simulation harness for evaluating your security controls☆194Updated last year
- Harvest Linux forensic data for operational triage of an event.☆51Updated last year