Tìm thấy 565 ứng dụng & công cụ phù hợp
Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.
Pure-Rust Android decompiler and security-audit suite. DEX → Java, Hermes → JavaScript. Cross-layer taint across the React Native bridge. CycloneDX SBOM + OpenVEX. CLI and MCP. Bytecode is not a secur
A repository for all resources related to malware analysis, reverse engineering, and system internals. This collection is tailored for professionals and learners aiming to deepen their understanding o
🔍 "2015 Microsoft Malware Classification Challenge" - Using machine learning to classify malware into different families based on Windows PE structures, disassembly scripts and machine code(“2015微软恶意软
Collection of malware analysis, binary exploitation and reverse engineering related resources
🦅 Falcon Malware Sandbox APIv2 Connector
ssdeep cluster analysis for malware files
A personalized COLLECTION of technical research papers focused on malware analysis. Covers static/dynamic analysis, sandboxing, behavioral classification, threat intelligence extraction, and anti-evas
Ctrl+Scroll font zoom for all IDA views — Disassembly, Pseudocode, Hex View, Imports, Exports, Functions, Strings, and more. Compatible IDA Pro 8.x — 9.3+.
Packer detection and unpacking workflow for malware analysis: UPX, ASPack, Themida, VMProtect, PE and ELF.
Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across MalwareBazaar, ThreatFox, URLhaus, Feodo, URLScan & VirusTotal — straight from Claude. BYOK,
MalStatWare automates malware analysis with Python. Extract key details like file size, type, hash, path, and digital signature. It analyzes headers, APIs, and strings, giving quick insights for threa
FlipperZero - Mix of random flipper zero ducky scripts
File entropy calculator - Golang
An AI-driven MCP server that autonomously interfaces with Malware Bazaar, delivering real-time threat intel and sample metadata for authorized cybersecurity research workflows.
A tool to help malware analysts signature unique parts of RTF documents
AssemblyLine4 documentation
Corana is a Dynamic Symbolic Execution Engine for ARM Cortex-M aiming to incrementally reconstruct the precise Control Flow Graph (CFG) of IoT malware under the presence of obfuscation techniques e.g.
Discover which process execute a hunted binary inside macOS
Configuration Extractor for BlackCat Ransomware
Collection of windows rootkits
A structured repository designed for cybersecurity professionals and enthusiasts. Covers topics such as OSINT, NMAP, WAPT, PTES, IDS/IPS, SIEM, malware analysis, privilege escalation, and more. Ideal
An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern threat‑analysis pipelines.
PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer Detection