seifreed / yaraastLinks
A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation
☆50Updated last month
Alternatives and similar repositories for yaraast
Users that are interested in yaraast are comparing it to the libraries listed below
Sorting:
- This repository contains an IDA processor for loading and disassembling compiled yara rules.☆44Updated last year
- Golem automates C/C++ vulnerability discovery with SemGrep+LLVM+LLM☆96Updated 7 months ago
- BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience☆17Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆76Updated 5 months ago
- ☆74Updated last year
- ☆89Updated 11 months ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- Extract data of TTD trace file to a minidump☆31Updated 2 years ago
- Rule Engine for Dynamic Malware Analysis and Research☆25Updated 9 months ago
- ☆24Updated last year
- Binary Exploitation Phrack CTF Challenge☆70Updated 5 months ago
- Open Source eBPF Malware Analysis Framework☆54Updated last year
- ☆35Updated 11 months ago
- IDA Python scripts☆40Updated 9 months ago
- Reverse engineering assistant that extracts strings and related pseudocode from a binary file.☆91Updated this week
- Proof-of-concept modular implant platform leveraging v8☆54Updated 10 months ago
- A collection of ready-to-use library code and symbols for the MinHash-based Code Relationship & Investigation Toolkit (MCRIT)☆12Updated last month
- Authenticated 0-click RCE against Linux 6.1.45 for CVE-2023-52440 and CVE-2023-4130☆52Updated 4 months ago
- ☆85Updated 5 months ago
- ☆31Updated 10 months ago
- ☆39Updated last year
- This repository contains the public work I produced, wheter it is research, post, slides, sometimes videos, and materials of my talks.☆52Updated 5 months ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated 2 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆48Updated 9 months ago
- Scriptable CLI debugger for windows, inspired by pwndbg ❤☆96Updated 3 months ago
- Linux BPF plugins for Volatility3☆23Updated 2 years ago
- Diaphora Machine Learning tools and datasets☆23Updated last year
- How to retro theme your Ghidra☆35Updated 3 months ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆43Updated last year
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated 2 years ago