sandflysecurity / sandfly-entropyscanLinks
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
☆167Updated last year
Alternatives and similar repositories for sandfly-entropyscan
Users that are interested in sandfly-entropyscan are comparing it to the libraries listed below
Sorting:
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆29Updated 3 months ago
- YaraScanner is a file pattern-matching tool based on YARA rules.☆60Updated 2 years ago
- BSidesRoc 2022 Linux Malware/Forensics Course☆75Updated 3 years ago
- Harvest Linux forensic data for operational triage of an event.☆51Updated last month
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- Data visualization for blue teams☆126Updated 3 years ago
- A Self-Contained Open-Source Cyberattack Experimentation Testbed☆43Updated 7 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆149Updated 2 years ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆105Updated 3 years ago
- Rip Raw is a small tool to analyse the memory of compromised Linux systems.☆134Updated 3 years ago
- Linux Evidence Acquisition Framework☆117Updated last year
- Signature based honeypot detector tool written in Golang☆107Updated 9 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- Linux #rootkit and #malware revealer☆30Updated last year
- Rapidly Search and Hunt through Linux Forensics Artifacts☆201Updated 2 years ago
- File analysis and management framework.☆92Updated 2 years ago
- IOCs published by Black Lotus Labs☆124Updated 2 months ago
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection☆164Updated 3 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- QuickSand document and PDF malware analysis tool written in Python☆134Updated 2 months ago
- simple YARA-based IOC scanner☆175Updated last week
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆79Updated 2 years ago
- This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.☆120Updated 2 years ago
- A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.☆136Updated last year
- WhiteBeam: Transparent endpoint security☆101Updated 2 years ago
- Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.☆144Updated last month
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆107Updated last year
- yara detection rules for hunting with the threathunting-keywords project☆157Updated 8 months ago
- Enhance your malware detection with WAF + YARA (WAFARAY)☆108Updated 3 years ago