DC3-MWCP

Malware parser

A framework for parsing configuration information from malware to facilitate analysis and automation.

DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, filenames, and mutex names.

GitHub

305 stars
43 watching
59 forks
Language: Python
last commit: over 2 years ago
Linked from 1 awesome list

automationconfig-dumpframeworkmalware-analysismalware-automationpython

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
cert-polska/mwdb-coreAutomated malware collection and analysis system with storage, tracking, and visualization capabilities330
tomchop/malcomAnalyzes network traffic to detect malware communication and behavior1,158
cert-ee/cuckoo3Automated malware analysis tool that tests suspicious files or links in a sandboxed environment652
jpcertcc/malconfscanTools to extract configuration data from known malware samples in memory images.483
misterch0c/malsploitbaseA repository of publicly available malware exploits targeting specific infrastructure.537
cert-polska/kartonA framework for building flexible and lightweight malware analysis pipelines395
mdudek-ics/trisis-triton-hatmanRepository containing malware samples and decompiled code to aid in security research and development of defense solutions233
silascutler/malpipeAn ingestion and processing framework for malware and indicator data from various feeds.104
mr-un1k0d3r/powerlessshellA tool for generating malware payloads using MSBuild and PowerShell, allowing for conditional execution based on user domain or registry conditions.1,480
mitrecnd/malchiveA collection of reusable scripts and tools for analyzing malicious software75
kevoreilly/capev2A tool to extract configuration and payload from malware by analyzing its behavior in a sandboxed environment.2,043
ajpc500/relayrumblerA tool to extract configuration from F-Secure C3 Relay executable memory dumps16
cidrblock/netcopaAn engine for parsing network device configurations and converting them to structured data in YAML135
weisong-ucr/mab-malwareAn open-source reinforcement learning framework to generate adversarial examples for malware classification models.41
nysol/mcmdA set of commands for high-speed processing of large-scale CSV data33