zRapha / FAMELinks
Framework for Adversarial Malware Evaluation.
☆34Updated 7 months ago
Alternatives and similar repositories for FAME
Users that are interested in FAME are comparing it to the libraries listed below
Sorting:
- This project fully automates the process of analyzing and exploiting IoT malware to find live CnC servers.☆43Updated last year
- Embed an executable as a PE resource, drops and launches it in runtime.☆64Updated 4 years ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆62Updated 2 years ago
- ☆13Updated 2 years ago
- Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"☆17Updated 8 months ago
- Defense from the 2020 Microsoft Evasion Competition☆17Updated 4 years ago
- This is a repository that is meant to hold detections for various process injection techniques.☆34Updated 5 years ago
- Windows (ShadowMove) Socket Duplication☆87Updated 5 years ago
- (Sim)ulate (Ba)zar Loader☆29Updated 4 years ago
- Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.☆75Updated 4 years ago
- Mem2Img: Memory-Resident Malware Detection via Convolution Neural Network☆25Updated 4 years ago
- A small utility to deal with malware embedded hashes.☆52Updated 2 years ago
- MultiAV scanner with Python and JSON REST API using Malice Docker AV Containers and Docker-Machine based Autoscaling☆69Updated last year
- Unpacking and decryption tools for the Emotet malware☆45Updated 3 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated last year
- Code for the paper "EMBERSim: A Large-Scale Databank for Boosting Similarity Search in Malware Analysis"☆31Updated 2 years ago
- All in one - Malware + Analysis by Cylance☆11Updated 6 years ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated 2 years ago
- ☆102Updated 3 years ago
- An attempt to detect malware using Opcodes and Hexadecimal Instructions.☆32Updated 4 years ago
- ☆40Updated last year
- ☆26Updated 2 years ago
- This tool parses NTDLL.DLL, extracts all the syscall numbers and helps in making direct syscalls, in order to help evasion.☆15Updated 3 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago
- Repository of Yara rules created by the Stratosphere team☆28Updated 4 years ago
- A simple tool to inject shellcode into the remote process with the ability to spoof parent process.☆16Updated 4 years ago
- ☆53Updated last year
- ☆16Updated last year
- My Malware Analysis Reports☆23Updated 3 years ago
- Dataset of packed ELF samples☆20Updated 2 years ago