pafish

VM/SAE detector

A tool to detect virtual machines and malware analysis environments by analyzing system behavior similar to malware detection methods.

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do

GitHub

3k stars
176 watching
465 forks
Language: C
last commit: about 2 years ago
Linked from 1 awesome list

analysis-environmentsmalwaremalware-analysismalware-familiesmalware-researchrdtscreverse-engineeringsandboxvirtual-machine

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
joesecurity/pafishmacroAn Office document designed to test and analyze malware detection systems278
nsmfoo/antivmdetectionA tool to create templates making VirtualBox VM detection harder717
gosecure/malboxesAutomates malware analysis on Windows VMs for research and testing purposes.1,036
3coresec/automataAutomated tool to detect errors in security monitoring and measure effectiveness of SIEM rules against various behaviors.53
idiom/pftriageTool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.77
navytitanium/fake-sandbox-artifactsCreates artificial artifacts to evade malware detection and analysis252
sophos/sorel-20mA large-scale dataset and codebase for training machine learning models to detect malicious software646
exeinfoasl/aslAn executable file detector software that identifies packers, protectors, compilers, .NET obfuscators, and other types of malware or unwanted code.772
csvl/semaAnalyzes malware by extracting and comparing system call dependencies to classify and detect malicious behavior101
aau-network-security/haaukinsA platform providing automated virtualization environments for security education and vulnerability testing188
withsecureopensource/seeAn environment for building secure and isolated test automation frameworks for analyzing and testing malware816
hasherezade/hollows_hunterAnalyzes running processes to detect and dump malicious code2,047
mhaggis/hunt-detect-preventA collection of resources and tools for detecting and preventing malicious activity on Windows systems.162
rajiv2790/falconeyeA real-time detection software for Windows process injections291
stvemillertime/conventionengineDetects and identifies suspicious PDB paths in malware files using Yara rules.37