malcom
Traffic analyzer
Analyzes network traffic to detect malware communication and behavior
Malcom - Malware Communications Analyzer
1k stars
131 watching
215 forks
Language: Python
last commit: almost 7 years ago
Linked from 1 awesome list
dfirinfosecmalwaremalware-analysisnetwork-trafficpcapthreat-intelligence
Related projects:
Repository | Description | Stars |
---|---|---|
telekom-security/malware_analysis | An analysis repository providing scripts, signatures, and IOCs for detecting and analyzing malware. | 110 |
idaholab/malcolm | A powerful tool suite for analyzing and visualizing network traffic data | 360 |
cyb3rmx/qu1cksc0pe | A comprehensive tool for analyzing suspicious files and detecting malware characteristics. | 1,320 |
ch3k1/squidmagic | Analyzes web-based network traffic to detect malicious command and control servers using Squid proxy server and Spamhaus | 78 |
cisagov/malcolm | A network traffic analysis tool suite that accepts various data formats and provides visualization and incident response capabilities. | 1,962 |
zhengmin1989/droidanalytics | An Android malware analysis system designed to collect and analyze malware signatures using machine learning techniques. | 29 |
michoo/pci | Analyzes network traffic to investigate packet interactions and visualize connections on a graph-based platform. | 90 |
detuxsandbox/detux | Analyzes and captures malware traffic on Linux sandboxed environments using QEMU hypervisor and various CPU architectures. | 260 |
mandiant/flare-fakenet-ng | A tool for intercepting and redirecting network traffic to analyze malware functionality | 1,803 |
activecm/rita | A framework for detecting malicious communication patterns in network traffic by analyzing Zeek logs. | 194 |
hatriot/zarp | A network attack tool designed to manage and analyze local networks | 1,446 |
mandiant/capa | An executable file analysis tool that identifies capabilities and potential malicious behaviors. | 4,873 |
advanced-threat-research/dotdumper | An automated tool for analyzing .NET-based malware samples by logging function calls and dumping memory segments. | 248 |
joxeankoret/pyew | A command-line tool for analyzing malware and disassembling binary files | 383 |
idiom/pftriage | Tool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators. | 77 |