peframe

Malware analyzer

Analyzes Portable Executable malware and malicious MS Office documents for various suspicious features

PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

GitHub

612 stars
53 watching
139 forks
Language: YARA
last commit: about 4 years ago
Linked from 2 awesome lists


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
justicerage/manalyzeAnalyzes PE files for security vulnerabilities and suspicious behavior1,024
cyb3rmx/qu1cksc0peAn all-in-one malware analysis tool that provides detailed information about suspicious files and executables.1,348
struppigel/portexA Java library for static analysis of Portable Executable files with focus on malware detection and PE malformation robustness499
telekom-security/malware_analysisAn analysis repository providing scripts, signatures, and IOCs for detecting and analyzing malware.110
kevoreilly/capev2A tool to extract configuration and payload from malware by analyzing its behavior in a sandboxed environment.2,043
hiddenillusion/analyzepeAnalyzes PE files by combining data from various tools to generate a centralized report.204
phra/pezorA tool for obfuscating and packing executable files to evade antivirus detection and security measures1,869
dragon-dreamer/binary-valentineAn executable file analyzer tool that detects security, configuration, optimization, system, and format issues in Windows executables18
diogo-fernan/malsubA Python framework that provides an API interface to multiple online services for analyzing malware and threat intelligence368
trustedsec/pplfaultdumpbofTools for analyzing PPLFault-related malware behavior on Windows 10134
mandiant/capaAn executable file analysis tool that identifies capabilities and potential malicious behaviors.4,944
tomchop/malcomAnalyzes network traffic to detect malware communication and behavior1,158
joxeankoret/pyewA command-line tool for analyzing malware and disassembling binary files386
uppusaikiran/generic-parserAnalyzes malware files to detect suspicious behavior by extracting meta information and features.1