awesome-malware-analysis

Malware toolkit

A curated collection of malware analysis tools and resources.

Defund the Police.

GitHub

12k stars
702 watching
3k forks
last commit: over 2 years ago
Linked from 17 awesome lists

analysis-frameworkautomated-analysisawesomeawesome-listchinesechinese-translationdomain-analysisdrop-icedynamic-analysislistmalware-analysismalware-collectionmalware-researchmalware-samplesnetwork-trafficstatic-analysisthreat-intelligencethreat-sharingthreatintel

Awesome Malware Analysis / Malware Collection / Anonymizers

Anonymouse.orgA free, web based anonymizer
OpenVPNVPN software and hosting solutions
PrivoxyAn open source proxy server with some privacy features
TorThe Onion Router, for browsing the web without leaving traces of the client IP

Awesome Malware Analysis / Malware Collection / Honeypots

Conpot1,258over 2 years agoICS/SCADA honeypot
Cowrie5,260almost 2 years agoSSH honeypot, based on Kippo
DemoHunter61over 8 years agoLow interaction Distributed Honeypots
Dionaea719about 2 years agoHoneypot designed to trap malware
Glastopf564about 2 years agoWeb application honeypot
HoneydCreate a virtual honeynet
HoneyDriveHoneypot bundle Linux distro
Honeytrap1,226almost 3 years agoOpensource system for running, monitoring and managing honeypots
MHN2,441almost 2 years agoMHN is a centralized server for management and data collection of honeypots. MHN allows you to deploy sensors quickly and to collect data immediately, viewable from a neat web interface
Mnemosyne46over 11 years agoA normalizer for honeypot data; supports Dionaea
Thug998almost 2 years agoLow interaction honeyclient, for investigating malicious websites

Awesome Malware Analysis / Malware Collection / Malware Corpora

Clean MXRealtime database of malware and malicious domains
ContagioA collection of recent malware samples and analyses
Exploit DatabaseExploit and shellcode samples
Infosec - CERT-PAMalware samples collection and analysis
InQuest LabsEvergrowing searchable corpus of malicious Microsoft documents
Javascript Mallware Collection684about 2 years agoCollection of almost 40.000 javascript malware samples
MalpediaA resource providing rapid identification and actionable context for malware investigations
MalshareLarge repository of malware actively scrapped from malicious sites
Ragpicker94about 11 years agoPlugin based malware crawler with pre-analysis and reporting functionalities
theZoo11,409over 2 years agoLive malware samples for analysts
Tracker h3xAgregator for malware corpus tracker and malicious download sites
vduddu malware repoCollection of various malware files and source code
VirusBayCommunity-Based malware repository and social network
ViruSignMalware database that detected by many anti malware programs except ClamAV
VirusShareMalware repository, registration required
VX VaultActive collection of malware samples
Zeltser's SourcesA list of malware sample sources put together by Lenny Zeltser
Zeus Source Code1,428almost 6 years agoSource for the Zeus trojan leaked in 2011
VX UndergroundMassive and growing collection of free malware samples

Awesome Malware Analysis / Open Source Threat Intelligence / Tools

AbuseHelper121almost 7 years agoAn open-source framework for receiving and redistributing abuse feeds and threat intel
AlienVault Open Threat ExchangeShare and collaborate in developing Threat Intelligence
Combine657over 7 years agoTool to gather Threat Intelligence indicators from publicly available sources
Fileintel119almost 6 years agoPull intelligence per file hash
Hostintel264over 5 years agoPull intelligence per host
IntelMQ- A tool for CERTs for processing incident data using a message queue
IOC Editor- A free editor for XML IOC files
iocextract513about 2 years agoAdvanced Indicator of Compromise (IOC) extractor, Python library and command-line tool
ioc_writer201over 3 years agoPython library for working with OpenIOC objects, from Mandiant
MalPipe104almost 8 years agoMalware/IOC ingestion and processing engine, that enriches collected data
Massive Octo Spice228over 8 years ago- Previously known as CIF (Collective Intelligence Framework). Aggregates IOCs from various lists. Curated by the
MISP5,435almost 2 years agoMalware Information Sharing Platform curated by
PulsediveFree, community-driven threat intelligence platform collecting IOCs from open-source feeds
PyIOCe18over 10 years agoA Python OpenIOC editor
RiskIQResearch, connect, tag and share IPs and domains. (Was PassiveTotal.)
threataggregator80over 10 years ago- Aggregates security threats from a number of sources, including some of those listed below in
ThreatConnectTC Open allows you to see and share open source threat data, with support and validation from our free community
ThreatCrowdA search engine for threats, with graphical visualization
ThreatIngestor836over 2 years agoBuild automated threat intel pipelines sourcing from Twitter, RSS, GitHub, and more
ThreatTracker66over 11 years agoA Python script to monitor and generate alerts based on IOCs indexed by a set of Google Custom Search Engines
TIQ-test173almost 11 years agoData visualization and statistical analysis of Threat Intelligence feeds

Awesome Malware Analysis / Open Source Threat Intelligence / Other Resources

Autoshun( ) - Snort plugin and blocklist
Bambenek Consulting Feeds- OSINT feeds based on malicious DGA algorithms
Fidelis Barncat- Extensive malware config database (must request access)
CI Army( ) - Network security blocklists
Critical Stack- Free Intel MarketFree intel aggregator with deduplication featuring 90+ feeds and over 1.2M indicators
Cybercrime trackerMultiple botnet active tracker
FireEye IOCs465over 7 years agoIndicators of Compromise shared publicly by FireEye
FireHOL IP ListsAnalytics for 350+ IP lists with a focus on attacks, malware and abuse. Evolution, Changes History, Country Maps, Age of IPs listed, Retention Policy, Overlaps
HoneyDBCommunity driven honeypot sensor data collection and aggregation
hpfeeds213almost 3 years agoHoneypot feed protocol
Infosec - CERT-PA lists( - - ) - Blocklist service
InQuest REPdbContinuous aggregation of IOCs from a variety of open reputation sources
InQuest IOCdbContinuous aggregation of IOCs from a variety of blogs, Github repos, and Twitter
Internet Storm Center (DShield)Diary and searchable incident database, with a web . ( )
malc0deSearchable incident database
Malware Domain ListSearch and share malicious URLs
MetaDefender Threat Intelligence Feed- List of the most looked up file hashes from MetaDefender Cloud
OpenIOCFramework for sharing threat intelligence
Proofpoint Threat Intelligence- Rulesets and more. (Formerly Emerging Threats.)
Ransomware overview- A list of ransomware overview with details, detection and prevention
STIX - Structured Threat Information eXpression- Standardized language to represent and share cyber threat information. Related efforts from :

Awesome Malware Analysis / Open Source Threat Intelligence / Other Resources / STIX - Structured Threat Information eXpression

CAPEC - Common Attack Pattern Enumeration and Classification
CybOX - Cyber Observables eXpression
MAEC - Malware Attribute Enumeration and Characterization
TAXII - Trusted Automated eXchange of Indicator Information

Awesome Malware Analysis / Open Source Threat Intelligence / Other Resources

SystemLookupSystemLookup hosts a collection of lists that provide information on the components of legitimate and potentially unwanted programs
ThreatMinerData mining portal for threat intelligence, with search
threatRECONSearch for indicators, up to 1000 free per month
ThreatShareC2 panel tracker
Yara rules4,215over 2 years agoYara rules repository
YETI1,766almost 2 years agoYeti is a platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository
ZeuS TrackerZeuS blocklists

Awesome Malware Analysis / Detection and Classification

AnalyzePE204over 12 years agoWrapper for a variety of tools for reporting on Windows PE files
AssemblylineA scalable file triage and malware analysis system integrating the cyber security community's best tools
BinaryAlert1,415almost 3 years agoAn open source, serverless AWS pipeline that scans and alerts on uploaded files based on a set of YARA rules
capa4,944almost 2 years agoDetects capabilities in executable files
chkrootkitLocal Linux rootkit detection
ClamAVOpen source antivirus engine
Detect It Easy(DiE)7,800almost 2 years agoA program for determining types of files
Exeinfo PEPacker, compressor detector, unpack info, internal exe tools
ExifToolRead, write and edit file metadata
File Scanning Framework290about 5 years ago- Modular, recursive file scanning solution
fn2yara1,569about 2 years agoFN2Yara is a tool to generate Yara signatures for matching functions (code) in an executable program
Generic File Parser1about 8 years agoA Single Library Parser to extract meta information,static analysis and detect macros within the files
hashdeep715almost 2 years agoCompute digest hashes with a variety of algorithms
HashCheck1,776over 4 years agoWindows shell extension to compute hashes with a variety of algorithms
Loki3,419almost 2 years agoHost based scanner for IOCs
Malfunction192almost 11 years agoCatalog and compare malware at a function level
Manalyze1,024over 2 years agoStatic analyzer for PE executables
MASTIFF175over 6 years agoStatic analysis framework
MultiScanner618almost 7 years agoModular file scanning/analysis framework
Nauz File Detector(NFD)531almost 2 years agoLinker/Compiler/Tool detector for Windows, Linux and MacOS
nsrllookup112over 5 years agoA tool for looking up hashes in NIST's National Software Reference Library database
packerid42over 6 years agoA cross-platform Python alternative to PEiD
PE-bearReversing tool for PE files
PEframe612about 4 years agoPEframe is an open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents
PEVA multiplatform toolkit to work with PE files, providing feature-rich tools for proper analysis of suspicious binaries
PortEx499almost 2 years agoJava library to analyse PE files with a special focus on malware analysis and PE malformation robustness
Quark-Engine1,342almost 2 years agoAn Obfuscation-Neglect Android Malware Scoring System
Rootkit HunterDetect Linux rootkits
ssdeepCompute fuzzy hashes
totalhash.py- Python script for easy searching of the database
TrIDFile identifier
YARAPattern matching tool for analysts
Yara rules generator1,569over 2 years agoGenerate yara rules based on a set of malware samples. Also contains a good strings DB to avoid false positives
Yara Finder2about 8 years agoA simple tool to yara match the file against various yara rules to find the indicators of suspicion

Awesome Malware Analysis / Online Scanners and Sandboxes

anlyz.ioOnline sandbox
any.runOnline interactive sandbox
AndroTotalFree online analysis of APKs against multiple mobile antivirus apps
BoomBox235over 3 years agoAutomatic deployment of Cuckoo Sandbox malware lab using Packer and Vagrant
CryptamAnalyze suspicious office documents
Cuckoo SandboxOpen source, self hosted sandbox and automated analysis system
cuckoo-modified271about 7 years agoModified version of Cuckoo Sandbox released under the GPL. Not merged upstream due to legal concerns by the author
cuckoo-modified-api22almost 10 years agoA Python API used to control a cuckoo-modified sandbox
DeepVizMulti-format file analyzer with machine-learning classification
detux261over 4 years agoA sandbox developed to do traffic analysis of Linux malwares and capturing IOCs
DRAKVUF1,074almost 2 years agoDynamic malware analysis system
filescan.ioStatic malware analysis, VBA/Powershell/VBS/JS Emulation
firmware.reUnpacks, scans and analyzes almost any firmware package
HaboMalHunter734over 3 years agoAn Automated Malware Analysis Tool for Linux ELF Files
Hybrid AnalysisOnline malware analysis tool, powered by VxSandbox
IntezerDetect, analyze, and categorize malware by identifying code reuse and code similarities
IRMAAn asynchronous and customizable analysis platform for suspicious files
Joe SandboxDeep malware analysis with Joe Sandbox
JottiFree online multi-AV scanner
Limon390over 10 years agoSandbox for Analyzing Linux Malware
Malheur369over 7 years agoAutomatic sandboxed analysis of malware behavior
malice.io1,658over 3 years agoMassively scalable malware analysis framework
malsub368over 2 years agoA Python RESTful API framework for online malware and URL analysis services
Malware configExtract, decode and display online the configuration settings from common malwares
MalwareAnalyser.ioOnline malware anomaly-based static analyser with heuristic detection engine powered by data mining and machine learning
MalwrFree analysis with an online Cuckoo Sandbox instance
MetaDefender CloudScan a file, hash, IP, URL or domain address for malware for free
NetworkTotalA service that analyzes pcap files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware using Suricata configured with EmergingThreats Pro
Noriben1,130almost 3 years agoUses Sysinternals Procmon to collect information about malware in a sandboxed environment
PacketTotalPacketTotal is an online engine for analyzing .pcap files, and visualizing the network traffic within
PDF ExaminerAnalyse suspicious PDF files
ProcDotA graphical malware analysis tool kit
Recomposer130almost 13 years agoA helper script for safely uploading binaries to sandbox sites
sandboxapi138over 2 years agoPython library for building integrations with several open source and commercial malware sandboxes
SEE816almost 6 years agoSandboxed Execution Environment (SEE) is a framework for building test automation in secured Environments
SEKOIA Dropper AnalysisOnline dropper analysis (Js, VBScript, Microsoft Office, PDF)
VirusTotalFree online analysis of malware samples and URLs
Visualize_Logs139over 3 years agoOpen source visualization library and command line tools for logs. (Cuckoo, Procmon, more to come...)
Zeltser's ListFree automated sandboxes and services, compiled by Lenny Zeltser

Awesome Malware Analysis / Domain Analysis

AbuseIPDBAbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet
badips.comCommunity based IP blacklist service
boomerang38over 9 years agoA tool designed for consistent and safe capture of off network web resources
CymonThreat intelligence tracker, with IP/domain/hash search
Desenmascara.meOne click tool to retrieve as much metadata as possible for a website and to assess its good standing
DigFree online dig and other network tools
dnstwist4,949almost 2 years agoDomain name permutation engine for detecting typo squatting, phishing and corporate espionage
IPinfo100over 12 years agoGather information about an IP or domain by searching online resources
Machinae505over 2 years agoOSINT tool for gathering information about URLs, IPs, or hashes. Similar to Automator
mailchecker1,646almost 2 years agoCross-language temporary email detection library
MaltegoVT80almost 11 years agoMaltego transform for the VirusTotal API. Allows domain/IP research, and searching for file hashes and scan reports
Multi rblMultiple DNS blacklist and forward confirmed reverse DNS lookup over more than 300 RBLs
NormShield ServicesFree API Services for detecting possible phishing domains, blacklisted ip addresses and breached accounts
PhishStatsPhishing Statistics with search for IP, domain and website title
Spysesubdomains, whois, realted domains, DNS, hosts AS, SSL/TLS info,
SecurityTrailsHistorical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools
SpamCopIP based spam block list
SpamHausBlock list based on domains and IPs
Sucuri SiteCheckFree Website Malware and Security Scanner
Talos IntelligenceSearch for IP, domain or network owner. (Previously SenderBase.)
TekDefense AutomaterOSINT tool for gathering information about URLs, IPs, or hashes
URLhausA project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution
URLQueryFree URL Scanner
urlscan.ioFree URL Scanner & domain information
WhoisDomainTools free online whois search
Zeltser's ListFree online tools for researching malicious websites, compiled by Lenny Zeltser
ZScalar ZuluZulu URL Risk Analyzer

Awesome Malware Analysis / Browser Malware

Bytecode Viewer14,733almost 2 years agoCombines multiple Java bytecode viewers and decompilers into one tool, including APK/DEX support
FirebugFirefox extension for web development
Java DecompilerDecompile and inspect Java apps
Java IDX Parser39over 8 years agoParses Java IDX cache files
JSDetoxJavaScript malware analysis tool
jsunpack-n163over 11 years agoA javascript unpacker that emulates browser functionality
Krakatau2,003almost 2 years agoJava decompiler, assembler, and disassembler
MalzillaAnalyze malicious web pages
RABCDAsm431over 3 years agoA "Robust ActionScript Bytecode Disassembler."
SWF Investigator- Static and dynamic analysis of SWF applications
swftoolsTools for working with Adobe Flash files
xxxswfA Python script for analyzing Flash files

Awesome Malware Analysis / Documents and Shellcode

AnalyzePDF178over 12 years agoA tool for analyzing PDFs and attempting to determine whether they are malicious
box-js622almost 2 years agoA tool for studying JavaScript malware, featuring JScript/WScript support and ActiveX emulation
diStormDisassembler for analyzing malicious shellcode
InQuest Deep File InspectionUpload common malware lures for Deep File Inspection and heuristical analysis
JS BeautifierJavaScript unpacking and deobfuscation
libemuLibrary and tools for x86 shellcode emulation
malpdfobj53over 15 years agoDeconstruct malicious PDFs into a JSON representation
OfficeMalScannerScan for malicious traces in MS Office documents
olevbaA script for parsing OLE and OpenXML documents and extracting useful information
Origami PDFA tool for analyzing malicious PDFs, and more
PDF Toolspdfid, pdf-parser, and more from Didier Stevens
PDF X-Ray Lite35almost 15 years agoA PDF analysis tool, the backend-free version of PDF X-RAY
peepdfPython tool for exploring possibly malicious PDFs
QuickSandQuickSand is a compact C framework to analyze suspected malware documents to identify exploits in streams of different encodings and to locate and extract embedded executables
Spidermonkey- Mozilla's JavaScript engine, for debugging malicious JS

Awesome Malware Analysis / File Carving

bulk_extractor1,129almost 2 years agoFast file carving tool
EVTXtract191over 6 years agoCarve Windows Event Log files from raw binary data
ForemostFile carving tool designed by the US Air Force
hachoir3623about 2 years agoHachoir is a Python library to view and edit a binary stream field by field
Scalpel628over 2 years agoAnother data carving tool
SFlock82almost 3 years agoNested archive extraction/unpacking (used in Cuckoo Sandbox)

Awesome Malware Analysis / Deobfuscation

BalbuzardA malware analysis tool for reversing obfuscation (XOR, ROL, etc) and more
de4dot7,002about 6 years ago.NET deobfuscator and unpacker
ex_pe_xor& - Two tools from Alexander Hanel for working with single-byte XOR encoded files
FLOSS3,337almost 2 years agoThe FireEye Labs Obfuscated String Solver uses advanced static analysis techniques to automatically deobfuscate strings from malware binaries
NoMoreXOR86over 8 years agoGuess a 256 byte XOR key using frequency analysis
PackerAttacker270over 8 years agoA generic hidden code extractor for Windows malware
PyInstaller Extractor3,033almost 2 years ago- A Python script to extract the contents of a PyInstaller generated Windows executable file. The contents of the pyz file (usually pyc files) present inside the executable are also extracted and automatically fixed so that a Python bytecode decompiler will recognize it
uncompyle63,836almost 2 years agoA cross-version Python bytecode decompiler. Translates Python bytecode back into equivalent Python source code
un{i}packer666almost 2 years agoAutomatic and platform-independent unpacker for Windows binaries based on emulation
unpacker118over 10 years agoAutomated malware unpacker for Windows malware based on WinAppDbg
unxor142over 6 years agoGuess XOR keys using known-plaintext attacks
VirtualDeobfuscator133about 3 years ago- Reverse engineering tool for virtualization wrappers
XORBruteForcer- A Python script for brute forcing single-byte XOR keys
XORSearch & XORStrings- A couple programs from Didier Stevens for finding XORed data
xortool1,402over 3 years agoGuess XOR key length, as well as the key itself

Awesome Malware Analysis / Debugging and Reverse Engineering

angr7,647almost 2 years agoPlatform-agnostic binary analysis framework developed at UCSB's Seclab
bamfdetectIdentifies and extracts information from bots and other malware
BAP2,079about 2 years agoMultiplatform and open source (MIT) binary analysis framework developed at CMU's Cylab
BARF1,413almost 7 years agoMultiplatform, open source Binary Analysis and Reverse engineering Framework
binnavi2,877almost 6 years agoBinary analysis IDE for reverse engineering based on graph visualization
Binary ninjaA reversing engineering platform that is an alternative to IDA
Binwalk11,530almost 2 years agoFirmware analysis tool
BluePill123over 4 years agoFramework for executing and debugging evasive malware and protected executables
Capstone7,674almost 2 years agoDisassembly framework for binary analysis and reversing, with support for many architectures and bindings in several languages
codebro44about 9 years agoWeb based code browser using  clang to provide basic code analysis
CutterGUI for Radare2
DECAF (Dynamic Executable Code Analysis Framework)808almost 2 years ago- A binary analysis platform based   on QEMU. DroidScope is now an extension to DECAF
dnSpy26,802over 5 years ago.NET assembly editor, decompiler and debugger
dotPeekFree .NET Decompiler and Assembly Browser
Evan's Debugger (EDB)A modular debugger with a Qt GUI
Fibratus2,246almost 2 years agoTool for exploration and tracing of the Windows kernel
FPortReports open TCP/IP and UDP ports in a live system and maps them to the owning application
GDBThe GNU debugger
GEF7,088almost 2 years agoGDB Enhanced Features, for exploiters and reverse engineers
Ghidra52,492almost 2 years agoA software reverse engineering (SRE) framework created and maintained by the National Security Agency Research Directorate
hackers-grep170about 8 years agoA utility to search for strings in PE executables including imports, exports, and debug symbols
HopperThe macOS and Linux Disassembler
IDA ProWindows disassembler and debugger, with a free evaluation version
IDR975about 3 years agoInteractive Delphi Reconstructor is a decompiler of Delphi executable files and dynamic libraries
Immunity DebuggerDebugger for malware analysis and more, with a Python API
ILSpyILSpy is the open-source .NET assembly browser and decompiler
Kaitai StructDSL for file formats / network protocols / data structures reverse engineering and dissection, with code generation for C++, C#, Java, JavaScript, Perl, PHP, Python, Ruby
LIEFLIEF provides a cross-platform library to parse, modify and abstract ELF, PE and MachO formats
ltraceDynamic analysis for Linux executables
mac-a-mal85almost 8 years agoAn automated framework for mac malware hunting
objdumpPart of GNU binutils, for static analysis of Linux binaries
OllyDbgAn assembly-level debugger for Windows executables
OllyDumpExDump memory from (unpacked) malware Windows process and store raw or rebuild PE file. This is a plugin for OllyDbg, Immunity Debugger, IDA Pro, WinDbg, and x64dbg
PANDA104almost 10 years agoPlatform for Architecture-Neutral Dynamic Analysis
PEDA5,911about 2 years agoPython Exploit Development Assistance for GDB, an enhanced display with added commands
pestudioPerform static analysis of Windows executables
Pharos1,569about 2 years agoThe Pharos binary analysis framework can be used to perform automated static analysis of binaries
plasma3,050about 5 years agoInteractive disassembler for x86/ARM/MIPS
PPEE (puppy)A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail
Process Explorer- Advanced task manager for Windows
Process HackerTool that monitors system resources
Process Monitor- Advanced monitoring tool for Windows programs
PSToolsWindows command-line tools that help manage and investigate live systems
Pyew386about 7 years agoPython tool for malware analysis
PyREBox1,656over 2 years agoPython scriptable reverse engineering sandbox by the Talos team at Cisco
Qiling FrameworkCross platform emulation and sanboxing framework with instruments for binary analysis
QKD50almost 5 years agoQEMU with embedded WinDbg server for stealth debugging
Radare2Reverse engineering framework, with debugger support
RegShotRegistry compare utility that compares snapshots
RetDecRetargetable machine-code decompiler with an and that you can use in your tools
ROPMEMU285over 10 years agoA framework to analyze, dissect and decompile complex code-reuse attacks
Scylla Imports Reconstructor1,124over 3 years agoFind and fix the IAT of an unpacked / dumped PE32 malware
ScyllaHide3,509over 2 years agoAn Anti-Anti-Debug library and plugin for OllyDbg, x64dbg, IDA Pro, and TitanEngine
SMRT66almost 2 years agoSublime Malware Research Tool, a plugin for Sublime 3 to aid with malware analyis
straceDynamic analysis for Linux executables
StringSifter688about 2 years agoA machine learning tool that automatically ranks strings based on their relevance for malware analysis
TritonA dynamic binary analysis (DBA) framework
Udis861,028over 3 years agoDisassembler library and tool for x86 and x86_64
Vivisect944almost 2 years agoPython tool for malware analysis
WinDbgmultipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps
X64dbgAn open-source x64/x32 debugger for windows

Awesome Malware Analysis / Network

BroProtocol analyzer that operates at incredible scale; both file and network protocols
BroYara33almost 12 years agoUse Yara rules from Bro
CapTipper714over 3 years agoMalicious HTTP traffic explorer
chopshop489over 3 years agoProtocol analysis and decoding framework
CloudSharkWeb-based tool for packet analysis and malware traffic detection
FakeNet-NG1,824almost 2 years agoNext generation dynamic network analysis tool
FiddlerIntercepting web proxy designed for "web debugging."
Hale188over 4 years agoBotnet C&C monitor
HakaAn open source security oriented language for describing protocols and applying security policies on (live) captured traffic
HTTPReplay95almost 5 years agoLibrary for parsing and reading out PCAP files, including TLS streams using TLS Master Secrets (used in Cuckoo Sandbox)
INetSimNetwork service emulation, useful when building a malware lab
Laika BOSS743almost 2 years agoLaika BOSS is a file-centric malware analysis and intrusion detection system
Malcolm368almost 2 years agoMalcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs
Malcom1,158almost 9 years agoMalware Communications Analyzer
Maltrail6,642almost 2 years agoA malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface
mitmproxyIntercept network traffic on the fly
Moloch6,418almost 2 years agoIPv4 traffic capturing, indexing and database system
NetworkMinerNetwork forensic analysis tool, with a free version
ngrep907almost 2 years agoSearch through network traffic like grep
PcapViz346over 3 years agoNetwork topology and traffic visualizer
Python ICAP Yara57about 5 years agoAn ICAP Server with yara scanner for URL or content
Squidmagic78about 8 years agosquidmagic is a tool designed to analyze a web-based network traffic to detect central command and control (C&C) servers and malicious sites, using Squid proxy server and Spamhaus
TcpdumpCollect network traffic
tcpickTrach and reassemble TCP streams from network traffic
tcpxtractExtract files from network traffic
WiresharkThe network traffic analysis tool

Awesome Malware Analysis / Memory Forensics

BlackLightWindows/MacOS forensics client supporting hiberfil, pagefile, raw memory analysis
DAMM211over 9 years agoDifferential Analysis of Malware in Memory, built on Volatility
evolve259almost 9 years agoWeb interface for the Volatility Memory Forensics Framework
FindAESFind AES encryption keys in memory
inVtero.net281almost 3 years agoHigh speed memory analysis framework developed in .NET supports all Windows x64, includes code integrity and write support
Muninn52almost 9 years agoA script to automate portions of analysis using Volatility, and create a readable report. - Orochi is an open source framework for collaborative forensic memory dump analysis
RekallMemory analysis framework, forked from Volatility in 2013
TotalRecall49over 9 years agoScript based on Volatility for automating various malware analysis tasks
VolDiff194about 9 years agoRun Volatility on memory images before and after malware execution, and report changes
Volatility7,412over 3 years agoAdvanced memory forensics framework
VolUtility381almost 2 years agoWeb Interface for Volatility Memory Analysis framework
WDBGARK618about 6 years ago- WinDBG Anti-RootKit Extension
WinDbg- Live memory inspection and kernel debugging for Windows systems

Awesome Malware Analysis / Windows Artifacts

AChoir184about 4 years agoA live incident response script for gathering Windows artifacts
python-evt49about 3 years agoPython library for parsing Windows Event Logs
python-registryPython library for parsing registry files
RegRipper( ) - Plugin-based registry analysis tool

Awesome Malware Analysis / Storage and Workflow

Aleph158over 5 years agoOpen Source Malware Analysis Pipeline System
CRITsCollaborative Research Into Threats, a malware and threat repository
FAMEA malware analysis framework featuring a pipeline that can be extended with custom modules, which can be chained and interact with each other to perform end-to-end analysis
Malwarehouse134over 13 years agoStore, tag, and search malware
Polichombr376over 7 years agoA malware analysis platform designed to help analysts to reverse malwares collaboratively
stoQDistributed content analysis framework with extensive plugin support, from input to output, and everything in between
ViperA binary management and analysis framework for analysts and researchers

Awesome Malware Analysis / Miscellaneous

al-khaser5,990almost 2 years agoA PoC malware with good intentions that aimes to stress anti-malware systems
CryptoKnight39over 6 years agoAutomated cryptographic algorithm reverse engineering and classification framework
DC3-MWCP305over 2 years ago- The Defense Cyber Crime Center's Malware Configuration Parser framework
FLARE VM6,686almost 2 years agoA fully customizable, Windows-based, security distribution for malware analysis
MalSploitBase537about 7 years agoA database containing exploits used by malware
Malware MuseumCollection of malware programs that were distributed in the 1980s and 1990s
Malware Organiser1about 8 years agoA simple tool to organise large malicious/benign files into a organised Structure
Pafish3,443about 2 years agoParanoid Fish, a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do
REMnuxLinux distribution and docker images for malware reverse engineering and analysis
Tsurugi LinuxLinux distribution designed to support your DFIR investigations, malware analysis and OSINT (Open Source INTelligence) activities
Santoku LinuxLinux distribution for mobile forensics, malware analysis, and security

Resources / Books

Learning Malware AnalysisLearning Malware Analysis: Explore the concepts, tools, and techniques to analuze and investigate Windows malware
Malware Analyst's Cookbook and DVD- Tools and Techniques for Fighting Malicious Code
Mastering Malware AnalysisMastering Malware Analysis: The complete malware analyst's guide to combating malicious software, APT, cybercime, and IoT attacks
Mastering Reverse EngineeringMastering Reverse Engineering: Re-engineer your ethical hacking skills
Practical Malware AnalysisThe Hands-On Guide to Dissecting Malicious Software
Practical Reverse Engineering- Intermediate Reverse Engineering
Real Digital ForensicsComputer Security and Incident Response
Rootkits and BootkitsRootkits and Bootkits: Reversing Modern Malware and Next Generation Threats
The Art of Memory ForensicsDetecting Malware and Threats in Windows, Linux, and Mac Memory
The IDA Pro BookThe Unofficial Guide to the World's Most Popular Disassembler
The Rootkit ArsenalThe Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System

Resources / Other

APT Notes1,665about 2 years agoA collection of papers and notes related to Advanced Persistent Threats
Ember962almost 2 years agoEndgame Malware BEnchmark for Research, a repository that makes it easy to (re)create a machine learning model that can be used to predict a score for a PE file based on static analysis
File Formats posters10,579over 2 years agoNice visualization of commonly used file format (including PE & ELF)
Honeynet ProjectHoneypot tools, papers, and other resources
Kernel ModeAn active community devoted to malware analysis and kernel development
Malicious SoftwareMalware blog and resources by Lenny Zeltser
Malware Analysis Search- Custom Google search engine from
Malware Analysis Tutorials- The Malware Analysis Tutorials by Dr. Xiang Fu, a great resource for learning practical malware analysis
Malware Analysis, Threat Intelligence and Reverse Engineering- Presentation introducing the concepts of malware analysis, threat intelligence and reverse engineering. Experience or prior knowledge is not required. Labs link in description
Malware Persistence165almost 2 years agoCollection of various information focused on malware persistence: detection (techniques), response, pitfalls and the log collection (tools)
Malware Samples and TrafficThis blog focuses on network traffic related to malware infections
Malware Search+++Firefox extension allows you to easily search some of the most popular malware databases
Practical Malware Analysis Starter Kit- This package contains most of the software referenced in the Practical Malware Analysis book
RPISEC Malware Analysis3,776about 4 years agoThese are the course materials used in the Malware Analysis course at at Rensselaer Polytechnic Institute during Fall 2015
WindowsIR: MalwareHarlan Carvey's page on Malware
Windows Registry specification331almost 8 years ago- Windows registry file format specification
/r/csirt_toolsSubreddit for CSIRT tools and resources, with a flair
/r/MalwareThe malware subreddit
/r/ReverseEngineering- Reverse engineering subreddit, not limited to just malware
Android Security8,270almost 2 years ago
AppSec6,372about 2 years ago
CTFs9,929about 2 years ago
Executable Packing1,228almost 2 years ago
Forensics4,030almost 2 years ago
"Hacking"13,321over 2 years ago
Honeypots8,732about 2 years ago
Industrial Control System Security1,655almost 3 years ago
Incident-Response7,728about 2 years ago
Infosec5,221over 2 years ago
PCAP Tools3,143over 2 years ago
Pentesting22,116almost 2 years ago
Security12,563about 2 years ago
Threat Intelligence8,211about 2 years ago
YARA3,598almost 2 years ago

Backlinks from these awesome lists:

More related projects: