Skip to content
58

Awesome Malware Analysis

Defund the Police.

14k stars2,689 forks386 entriesLast push Jun 7, 2024 (2 years ago)License Other

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Malware Collection >Anonymizers

Anonymouse.org

A free, web based anonymizer.

OpenVPN

VPN software and hosting solutions.

In 7 listsDetails

Privoxy

An open source proxy server with some privacy features.

Tor

The Onion Router, for browsing the web without leaving traces of the client IP.

In 14 listsDetails

Malware Collection >Honeypots

Conpot

ICS/SCADA honeypot.

Cowrie

SSH honeypot, based on Kippo.

In 2 lists

DemoHunter

Low interaction Distributed Honeypots.

Dionaea

Honeypot designed to trap malware.

Glastopf

Web application honeypot.

Honeyd

Create a virtual honeynet.

HoneyDrive

Honeypot bundle Linux distro.

Honeytrap

Opensource system for running, monitoring and managing honeypots.

In 2 lists

MHN

MHN is a centralized server for management and data collection of honeypots. MHN allows you to deploy sensors quickly and to collect data immediately, viewable from a neat web interface.

Mnemosyne

A normalizer for honeypot data; supports Dionaea.

Thug

Low interaction honeyclient, for investigating malicious websites.

Malware Collection >Malware Corpora

Clean MX

Realtime database of malware and malicious domains.

Contagio

A collection of recent malware samples and analyses.

Exploit Database

Exploit and shellcode samples.

In 8 listsDetails

Infosec - CERT-PA

Malware samples collection and analysis.

InQuest Labs

Evergrowing searchable corpus of malicious Microsoft documents.

In 3 lists

Javascript Mallware Collection

Collection of almost 40.000 javascript malware samples

Malpedia

A resource providing rapid identification and actionable context for malware investigations.

In 2 lists

Malshare

Large repository of malware actively scrapped from malicious sites.

In 4 listsDetails

Ragpicker

Plugin based malware crawler with pre-analysis and reporting functionalities

theZoo

Live malware samples for analysts.

In 5 listsDetails

Tracker h3x

Agregator for malware corpus tracker and malicious download sites.

vduddu malware repo

Collection of various malware files and source code.

VirusBay

Community-Based malware repository and social network.

ViruSign

Malware database that detected by many anti malware programs except ClamAV.

VirusShare

Malware repository, registration required.

In 3 lists

VX Vault

Active collection of malware samples.

Zeltser's Sources

A list of malware sample sources put together by Lenny Zeltser.

Zeus Source Code

Source for the Zeus trojan leaked in 2011.

VX Underground

Massive and growing collection of free malware samples.

Open Source Threat Intelligence >Tools

AbuseHelper

An open-source framework for receiving and redistributing abuse feeds and threat intel.

AlienVault Open Threat Exchange

Share and collaborate in developing Threat Intelligence.

In 6 listsDetails

Combine

Tool to gather Threat Intelligence indicators from publicly available sources.

In 3 lists

Fileintel

Pull intelligence per file hash.

In 2 lists

Hostintel

Pull intelligence per host.

In 2 lists

IntelMQ

A tool for CERTs for processing incident data using a message queue.

IOC Editor

A free editor for XML IOC files.

iocextract

Advanced Indicator of Compromise (IOC) extractor, Python library and command-line tool.

In 2 lists

ioc_writer

Python library for working with OpenIOC objects, from Mandiant.

MalPipe

Malware/IOC ingestion and processing engine, that enriches collected data.

Massive Octo Spice

Previously known as CIF (Collective Intelligence Framework). Aggregates IOCs from various lists. Curated by the CSIRT Gadgets Foundation.

In 2 lists

MISP

Malware Information Sharing Platform curated by The MISP Project.

In 3 lists

Pulsedive

Free, community-driven threat intelligence platform collecting IOCs from open-source feeds.

In 7 listsDetails

PyIOCe

A Python OpenIOC editor.

RiskIQ

Research, connect, tag and share IPs and domains. (Was PassiveTotal.)

In 2 lists

threataggregator

Aggregates security threats from a number of sources, including some of those listed below in other resources.

ThreatConnect

TC Open allows you to see and share open source threat data, with support and validation from our free community.

ThreatCrowd

A search engine for threats, with graphical visualization.

In 4 listsDetails

ThreatIngestor

Build automated threat intel pipelines sourcing from Twitter, RSS, GitHub, and more.

In 5 listsDetails

ThreatTracker

A Python script to monitor and generate alerts based on IOCs indexed by a set of Google Custom Search Engines.

TIQ-test

Data visualization and statistical analysis of Threat Intelligence feeds.

Open Source Threat Intelligence >Other Resources

Autoshun

(list) - Snort plugin and blocklist.

In 2 lists

Bambenek Consulting Feeds

OSINT feeds based on malicious DGA algorithms.

Fidelis Barncat

Extensive malware config database (must request access).

CI Army

(list) - Network security blocklists.

Critical Stack- Free Intel Market

Free intel aggregator with deduplication featuring 90+ feeds and over 1.2M indicators.

Cybercrime tracker

Multiple botnet active tracker.

FireEye IOCs

Indicators of Compromise shared publicly by FireEye.

In 2 lists

FireHOL IP Lists

Analytics for 350+ IP lists with a focus on attacks, malware and abuse. Evolution, Changes History, Country Maps, Age of IPs listed, Retention Policy, Overlaps.

HoneyDB

Community driven honeypot sensor data collection and aggregation.

hpfeeds

Honeypot feed protocol.

Infosec - CERT-PA lists

(IPs - Domains - URLs) - Blocklist service.

InQuest REPdb

Continuous aggregation of IOCs from a variety of open reputation sources.

InQuest IOCdb

Continuous aggregation of IOCs from a variety of blogs, Github repos, and Twitter.

Internet Storm Center (DShield)

Diary and searchable incident database, with a web API. (unofficial Python library).

In 2 lists

malc0de

Searchable incident database.

Malware Domain List

Search and share malicious URLs.

MetaDefender Threat Intelligence Feed

List of the most looked up file hashes from MetaDefender Cloud.

OpenIOC

Framework for sharing threat intelligence.

Proofpoint Threat Intelligence

Rulesets and more. (Formerly Emerging Threats.)

Ransomware overview

A list of ransomware overview with details, detection and prevention.

STIX - Structured Threat Information eXpression

Standardized language to represent and share cyber threat information. Related efforts from MITRE:

CAPEC - Common Attack Pattern Enumeration and Classification

CybOX - Cyber Observables eXpression

MAEC - Malware Attribute Enumeration and Characterization

TAXII - Trusted Automated eXchange of Indicator Information

SystemLookup

SystemLookup hosts a collection of lists that provide information on the components of legitimate and potentially unwanted programs.

ThreatMiner

Data mining portal for threat intelligence, with search.

In 4 listsDetails

threatRECON

Search for indicators, up to 1000 free per month.

ThreatShare

C2 panel tracker

Yara rules

Yara rules repository.

In 4 lists

YETI

Yeti is a platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository.

In 3 lists

ZeuS Tracker

ZeuS blocklists.

Detection and Classification

AnalyzePE

Wrapper for a variety of tools for reporting on Windows PE files.

Assemblyline

A scalable file triage and malware analysis system integrating the cyber security community's best tools..

BinaryAlert

An open source, serverless AWS pipeline that scans and alerts on uploaded files based on a set of YARA rules.

In 3 lists

capa

Detects capabilities in executable files.

In 2 lists

chkrootkit

Local Linux rootkit detection.

In 4 listsDetails

ClamAV

Open source antivirus engine.

In 2 lists

Detect It Easy(DiE)

A program for determining types of files.

In 3 lists

Exeinfo PE

Packer, compressor detector, unpack info, internal exe tools.

ExifTool

Read, write and edit file metadata.

In 3 lists

File Scanning Framework

Modular, recursive file scanning solution.

In 2 lists

fn2yara

FN2Yara is a tool to generate Yara signatures for matching functions (code) in an executable program.

In 3 lists

Generic File Parser

A Single Library Parser to extract meta information,static analysis and detect macros within the files.

hashdeep

Compute digest hashes with a variety of algorithms.

HashCheck

Windows shell extension to compute hashes with a variety of algorithms.

In 3 lists

Loki

Host based scanner for IOCs.

In 4 lists

Malfunction

Catalog and compare malware at a function level.

Manalyze

Static analyzer for PE executables.

In 3 lists

MASTIFF

Static analysis framework.

In 2 lists

MultiScanner

Modular file scanning/analysis framework

In 4 lists

Nauz File Detector(NFD)

Linker/Compiler/Tool detector for Windows, Linux and MacOS.

In 3 lists

nsrllookup

A tool for looking up hashes in NIST's National Software Reference Library database.

packerid

A cross-platform Python alternative to PEiD.

In 2 lists

PE-bear

Reversing tool for PE files.

PEframe

PEframe is an open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

In 2 lists

PEV

A multiplatform toolkit to work with PE files, providing feature-rich tools for proper analysis of suspicious binaries.

PortEx

Java library to analyse PE files with a special focus on malware analysis and PE malformation robustness.

In 2 lists

Quark-Engine

An Obfuscation-Neglect Android Malware Scoring System

In 4 listsDetails

Rootkit Hunter

Detect Linux rootkits.

In 5 lists

ssdeep

Compute fuzzy hashes.

totalhash.py

Python script for easy searching of the TotalHash.cymru.com database.

TrID

File identifier.

YARA

Pattern matching tool for analysts.

Yara rules generator

Generate yara rules based on a set of malware samples. Also contains a good strings DB to avoid false positives.

In 4 lists

Yara Finder

A simple tool to yara match the file against various yara rules to find the indicators of suspicion.

Online Scanners and Sandboxes

anlyz.io

Online sandbox.

any.run

Online interactive sandbox.

In 6 listsDetails

AndroTotal

Free online analysis of APKs against multiple mobile antivirus apps.

BoomBox

Automatic deployment of Cuckoo Sandbox malware lab using Packer and Vagrant.

Cryptam

Analyze suspicious office documents.

Cuckoo Sandbox

Open source, self hosted sandbox and automated analysis system.

In 2 lists

cuckoo-modified

Modified version of Cuckoo Sandbox released under the GPL. Not merged upstream due to legal concerns by the author.

cuckoo-modified-api

A Python API used to control a cuckoo-modified sandbox.

In 2 lists

DeepViz

Multi-format file analyzer with machine-learning classification.

detux

A sandbox developed to do traffic analysis of Linux malwares and capturing IOCs.

DRAKVUF

Dynamic malware analysis system.

filescan.io

Static malware analysis, VBA/Powershell/VBS/JS Emulation

In 2 lists

firmware.re

Unpacks, scans and analyzes almost any firmware package.

HaboMalHunter

An Automated Malware Analysis Tool for Linux ELF Files.

Hybrid Analysis

Online malware analysis tool, powered by VxSandbox.

In 6 listsDetails

Intezer

Detect, analyze, and categorize malware by identifying code reuse and code similarities.

In 3 lists

IRMA

An asynchronous and customizable analysis platform for suspicious files.

Joe Sandbox

Deep malware analysis with Joe Sandbox.

Jotti

Free online multi-AV scanner.

Limon

Sandbox for Analyzing Linux Malware.

Malheur

Automatic sandboxed analysis of malware behavior.

In 3 lists

malice.io

Massively scalable malware analysis framework.

In 2 lists

malsub

A Python RESTful API framework for online malware and URL analysis services.

Malware config

Extract, decode and display online the configuration settings from common malwares.

In 2 lists

MalwareAnalyser.io

Online malware anomaly-based static analyser with heuristic detection engine powered by data mining and machine learning.

Malwr

Free analysis with an online Cuckoo Sandbox instance.

MetaDefender Cloud

Scan a file, hash, IP, URL or domain address for malware for free.

In 4 listsDetails

NetworkTotal

A service that analyzes pcap files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware using Suricata configured with EmergingThreats Pro.

Noriben

Uses Sysinternals Procmon to collect information about malware in a sandboxed environment.

PacketTotal

PacketTotal is an online engine for analyzing .pcap files, and visualizing the network traffic within.

In 2 lists

PDF Examiner

Analyse suspicious PDF files.

ProcDot

A graphical malware analysis tool kit.

Recomposer

A helper script for safely uploading binaries to sandbox sites.

sandboxapi

Python library for building integrations with several open source and commercial malware sandboxes.

In 3 lists

SEE

Sandboxed Execution Environment (SEE) is a framework for building test automation in secured Environments.

SEKOIA Dropper Analysis

Online dropper analysis (Js, VBScript, Microsoft Office, PDF).

VirusTotal

Free online analysis of malware samples and URLs

In 13 listsDetails

Visualize_Logs

Open source visualization library and command line tools for logs. (Cuckoo, Procmon, more to come...)

In 3 lists

Zeltser's List

Free automated sandboxes and services, compiled by Lenny Zeltser.

Domain Analysis

AbuseIPDB

AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.

In 5 listsDetails

badips.com

Community based IP blacklist service.

boomerang

A tool designed for consistent and safe capture of off network web resources.

Cymon

Threat intelligence tracker, with IP/domain/hash search.

In 2 lists

Desenmascara.me

One click tool to retrieve as much metadata as possible for a website and to assess its good standing.

Dig

Free online dig and other network tools.

dnstwist

Domain name permutation engine for detecting typo squatting, phishing and corporate espionage.

In 4 lists

IPinfo

Gather information about an IP or domain by searching online resources.

Machinae

OSINT tool for gathering information about URLs, IPs, or hashes. Similar to Automator.

mailchecker

Cross-language temporary email detection library.

In 3 lists

MaltegoVT

Maltego transform for the VirusTotal API. Allows domain/IP research, and searching for file hashes and scan reports.

Multi rbl

Multiple DNS blacklist and forward confirmed reverse DNS lookup over more than 300 RBLs.

NormShield Services

Free API Services for detecting possible phishing domains, blacklisted ip addresses and breached accounts.

PhishStats

Phishing Statistics with search for IP, domain and website title

In 3 lists

Spyse

subdomains, whois, realted domains, DNS, hosts AS, SSL/TLS info,

In 5 listsDetails

SecurityTrails

Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.

In 6 listsDetails

SpamCop

IP based spam block list.

SpamHaus

Block list based on domains and IPs.

Sucuri SiteCheck

Free Website Malware and Security Scanner.

In 2 lists

Talos Intelligence

Search for IP, domain or network owner. (Previously SenderBase.)

In 4 listsDetails

TekDefense Automater

OSINT tool for gathering information about URLs, IPs, or hashes.

URLhaus

A project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.

In 3 lists

URLQuery

Free URL Scanner.

In 2 lists

urlscan.io

Free URL Scanner & domain information.

In 7 listsDetails

Whois

DomainTools free online whois search.

In 6 listsDetails

Zeltser's List

Free online tools for researching malicious websites, compiled by Lenny Zeltser.

ZScalar Zulu

Zulu URL Risk Analyzer.

Browser Malware

Bytecode Viewer

Combines multiple Java bytecode viewers and decompilers into one tool, including APK/DEX support.

In 4 listsDetails

Firebug

Firefox extension for web development.

Java Decompiler

Decompile and inspect Java apps.

Java IDX Parser

Parses Java IDX cache files.

JSDetox

JavaScript malware analysis tool.

jsunpack-n

A javascript unpacker that emulates browser functionality.

Krakatau

Java decompiler, assembler, and disassembler.

In 4 listsDetails

Malzilla

Analyze malicious web pages.

In 3 lists

RABCDAsm

A "Robust ActionScript Bytecode Disassembler."

In 2 lists

SWF Investigator

Static and dynamic analysis of SWF applications.

swftools

Tools for working with Adobe Flash files.

In 2 lists

xxxswf

A Python script for analyzing Flash files.

Documents and Shellcode

AnalyzePDF

A tool for analyzing PDFs and attempting to determine whether they are malicious.

box-js

A tool for studying JavaScript malware, featuring JScript/WScript support and ActiveX emulation.

diStorm

Disassembler for analyzing malicious shellcode.

InQuest Deep File Inspection

Upload common malware lures for Deep File Inspection and heuristical analysis.

JS Beautifier

JavaScript unpacking and deobfuscation.

In 2 lists

libemu

Library and tools for x86 shellcode emulation.

malpdfobj

Deconstruct malicious PDFs into a JSON representation.

OfficeMalScanner

Scan for malicious traces in MS Office documents.

olevba

A script for parsing OLE and OpenXML documents and extracting useful information.

Origami PDF

A tool for analyzing malicious PDFs, and more.

PDF Tools

pdfid, pdf-parser, and more from Didier Stevens.

In 2 lists

PDF X-Ray Lite

A PDF analysis tool, the backend-free version of PDF X-RAY.

peepdf

Python tool for exploring possibly malicious PDFs.

QuickSand

QuickSand is a compact C framework to analyze suspected malware documents to identify exploits in streams of different encodings and to locate and extract embedded executables.

Spidermonkey

Mozilla's JavaScript engine, for debugging malicious JS.

File Carving

bulk_extractor

Fast file carving tool.

In 6 listsDetails

EVTXtract

Carve Windows Event Log files from raw binary data.

Foremost

File carving tool designed by the US Air Force.

In 2 lists

hachoir3

Hachoir is a Python library to view and edit a binary stream field by field.

Scalpel

Another data carving tool.

In 3 lists

SFlock

Nested archive extraction/unpacking (used in Cuckoo Sandbox).

Deobfuscation

Balbuzard

A malware analysis tool for reversing obfuscation (XOR, ROL, etc) and more.

de4dot

.NET deobfuscator and unpacker.

In 3 lists

ex_pe_xor

& iheartxor - Two tools from Alexander Hanel for working with single-byte XOR encoded files.

FLOSS

The FireEye Labs Obfuscated String Solver uses advanced static analysis techniques to automatically deobfuscate strings from malware binaries.

In 2 lists

NoMoreXOR

Guess a 256 byte XOR key using frequency analysis.

PackerAttacker

A generic hidden code extractor for Windows malware.

In 2 lists

PyInstaller Extractor

A Python script to extract the contents of a PyInstaller generated Windows executable file. The contents of the pyz file (usually pyc files) present inside the executable are also extracted and automatically fixed so that a Python bytecode decompiler will recognize it.

In 2 lists

uncompyle6

A cross-version Python bytecode decompiler. Translates Python bytecode back into equivalent Python source code.

In 3 lists

un{i}packer

Automatic and platform-independent unpacker for Windows binaries based on emulation.

In 2 lists

unpacker

Automated malware unpacker for Windows malware based on WinAppDbg.

unxor

Guess XOR keys using known-plaintext attacks.

VirtualDeobfuscator

Reverse engineering tool for virtualization wrappers.

XORBruteForcer

A Python script for brute forcing single-byte XOR keys.

XORSearch & XORStrings

A couple programs from Didier Stevens for finding XORed data.

xortool

Guess XOR key length, as well as the key itself.

In 3 lists

Debugging and Reverse Engineering

angr

Platform-agnostic binary analysis framework developed at UCSB's Seclab.

In 5 listsDetails

bamfdetect

Identifies and extracts information from bots and other malware.

BAP

Multiplatform and open source (MIT) binary analysis framework developed at CMU's Cylab.

In 3 lists

BARF

Multiplatform, open source Binary Analysis and Reverse engineering Framework.

In 2 lists

binnavi

Binary analysis IDE for reverse engineering based on graph visualization.

In 2 lists

Binary ninja

A reversing engineering platform that is an alternative to IDA.

In 3 lists

Binwalk

Firmware analysis tool.

In 3 lists

BluePill

Framework for executing and debugging evasive malware and protected executables.

Capstone

Disassembly framework for binary analysis and reversing, with support for many architectures and bindings in several languages.

In 4 lists

codebro

Web based code browser using clang to provide basic code analysis.

Cutter

GUI for Radare2.

In 2 lists

DECAF (Dynamic Executable Code Analysis Framework)

A binary analysis platform based on QEMU. DroidScope is now an extension to DECAF.

In 2 lists

dnSpy

.NET assembly editor, decompiler and debugger.

In 3 lists

dotPeek

Free .NET Decompiler and Assembly Browser.

In 3 lists

Evan's Debugger (EDB)

A modular debugger with a Qt GUI.

In 3 lists

Fibratus

Tool for exploration and tracing of the Windows kernel.

In 8 listsDetails

FPort

Reports open TCP/IP and UDP ports in a live system and maps them to the owning application.

GDB

The GNU debugger.

In 2 lists

GEF

GDB Enhanced Features, for exploiters and reverse engineers.

In 3 lists

Ghidra

A software reverse engineering (SRE) framework created and maintained by the National Security Agency Research Directorate.

In 6 listsDetails

hackers-grep

A utility to search for strings in PE executables including imports, exports, and debug symbols.

In 2 lists

Hopper

The macOS and Linux Disassembler.

In 5 listsDetails

IDA Pro

Windows disassembler and debugger, with a free evaluation version.

In 2 lists

IDR

Interactive Delphi Reconstructor is a decompiler of Delphi executable files and dynamic libraries.

In 2 lists

Immunity Debugger

Debugger for malware analysis and more, with a Python API.

In 2 lists

ILSpy

ILSpy is the open-source .NET assembly browser and decompiler.

Kaitai Struct

DSL for file formats / network protocols / data structures reverse engineering and dissection, with code generation for C++, C#, Java, JavaScript, Perl, PHP, Python, Ruby.

In 3 lists

LIEF

LIEF provides a cross-platform library to parse, modify and abstract ELF, PE and MachO formats.

ltrace

Dynamic analysis for Linux executables.

In 3 lists

mac-a-mal

An automated framework for mac malware hunting.

objdump

Part of GNU binutils, for static analysis of Linux binaries.

OllyDbg

An assembly-level debugger for Windows executables.

In 5 listsDetails

OllyDumpEx

Dump memory from (unpacked) malware Windows process and store raw or rebuild PE file. This is a plugin for OllyDbg, Immunity Debugger, IDA Pro, WinDbg, and x64dbg.

PANDA

Platform for Architecture-Neutral Dynamic Analysis.

In 2 lists

PEDA

Python Exploit Development Assistance for GDB, an enhanced display with added commands.

In 5 listsDetails

pestudio

Perform static analysis of Windows executables.

fn2yara

FN2Yara is a tool to generate Yara signatures for matching functions (code) in an executable program.

In 3 lists

plasma

Interactive disassembler for x86/ARM/MIPS.

In 2 lists

PPEE (puppy)

A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail.

Process Explorer

Advanced task manager for Windows.

Process Hacker

Tool that monitors system resources.

Process Monitor

Advanced monitoring tool for Windows programs.

PSTools

Windows command-line tools that help manage and investigate live systems.

Pyew

Python tool for malware analysis.

PyREBox

Python scriptable reverse engineering sandbox by the Talos team at Cisco.

In 2 lists

Qiling Framework

Cross platform emulation and sanboxing framework with instruments for binary analysis.

QKD

QEMU with embedded WinDbg server for stealth debugging.

In 2 lists

Radare2

Reverse engineering framework, with debugger support.

In 2 lists

RegShot

Registry compare utility that compares snapshots.

RetDec

Retargetable machine-code decompiler with an online decompilation service and API that you can use in your tools.

ROPMEMU

A framework to analyze, dissect and decompile complex code-reuse attacks.

Scylla Imports Reconstructor

Find and fix the IAT of an unpacked / dumped PE32 malware.

ScyllaHide

An Anti-Anti-Debug library and plugin for OllyDbg, x64dbg, IDA Pro, and TitanEngine.

In 3 lists

SMRT

Sublime Malware Research Tool, a plugin for Sublime 3 to aid with malware analyis.

strace

Dynamic analysis for Linux executables.

In 2 lists

StringSifter

A machine learning tool that automatically ranks strings based on their relevance for malware analysis.

In 3 lists

Triton

A dynamic binary analysis (DBA) framework.

In 2 lists

Udis86

Disassembler library and tool for x86 and x86_64.

Vivisect

Python tool for malware analysis.

WinDbg

multipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps.

X64dbg

An open-source x64/x32 debugger for windows.

In 2 lists

Network

Bro

Protocol analyzer that operates at incredible scale; both file and network protocols.

BroYara

Use Yara rules from Bro.

CapTipper

Malicious HTTP traffic explorer.

In 3 lists

chopshop

Protocol analysis and decoding framework.

In 4 lists

CloudShark

Web-based tool for packet analysis and malware traffic detection.

FakeNet-NG

Next generation dynamic network analysis tool.

Fiddler

Intercepting web proxy designed for "web debugging."

In 4 listsDetails

Hale

Botnet C&C monitor.

Haka

An open source security oriented language for describing protocols and applying security policies on (live) captured traffic.

In 2 lists

HTTPReplay

Library for parsing and reading out PCAP files, including TLS streams using TLS Master Secrets (used in Cuckoo Sandbox).

INetSim

Network service emulation, useful when building a malware lab.

Laika BOSS

Laika BOSS is a file-centric malware analysis and intrusion detection system.

In 3 lists

Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs.

Malcom

Malware Communications Analyzer.

Maltrail

A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.

In 5 listsDetails

mitmproxy

Intercept network traffic on the fly.

In 10 listsDetails

Moloch

IPv4 traffic capturing, indexing and database system.

In 3 lists

NetworkMiner

Network forensic analysis tool, with a free version.

In 3 lists

ngrep

Search through network traffic like grep.

In 2 lists

PcapViz

Network topology and traffic visualizer.

Python ICAP Yara

An ICAP Server with yara scanner for URL or content.

In 2 lists

Squidmagic

squidmagic is a tool designed to analyze a web-based network traffic to detect central command and control (C&C) servers and malicious sites, using Squid proxy server and Spamhaus.

Tcpdump

Collect network traffic.

In 5 listsDetails

tcpick

Trach and reassemble TCP streams from network traffic.

In 2 lists

tcpxtract

Extract files from network traffic.

In 2 lists

Wireshark

The network traffic analysis tool.

In 20 listsDetails

Memory Forensics

BlackLight

Windows/MacOS forensics client supporting hiberfil, pagefile, raw memory analysis.

DAMM

Differential Analysis of Malware in Memory, built on Volatility.

evolve

Web interface for the Volatility Memory Forensics Framework.

In 2 lists

FindAES

Find AES encryption keys in memory.

inVtero.net

High speed memory analysis framework developed in .NET supports all Windows x64, includes code integrity and write support.

In 3 lists

Muninn

A script to automate portions of analysis using Volatility, and create a readable report. Orochi - Orochi is an open source framework for collaborative forensic memory dump analysis.

Rekall

Memory analysis framework, forked from Volatility in 2013.

In 4 lists

TotalRecall

Script based on Volatility for automating various malware analysis tasks.

VolDiff

Run Volatility on memory images before and after malware execution, and report changes.

In 2 lists

Volatility

Advanced memory forensics framework.

In 8 listsDetails

VolUtility

Web Interface for Volatility Memory Analysis framework.

In 2 lists

WDBGARK

WinDBG Anti-RootKit Extension.

WinDbg

Live memory inspection and kernel debugging for Windows systems.

Windows Artifacts

AChoir

A live incident response script for gathering Windows artifacts.

In 2 lists

python-evt

Python library for parsing Windows Event Logs.

In 2 lists

python-registry

Python library for parsing registry files.

RegRipper

(GitHub) - Plugin-based registry analysis tool.

Storage and Workflow

Aleph

Open Source Malware Analysis Pipeline System.

CRITs

Collaborative Research Into Threats, a malware and threat repository.

In 2 lists

FAME

A malware analysis framework featuring a pipeline that can be extended with custom modules, which can be chained and interact with each other to perform end-to-end analysis.

Malwarehouse

Store, tag, and search malware.

Polichombr

A malware analysis platform designed to help analysts to reverse malwares collaboratively.

In 2 lists

stoQ

Distributed content analysis framework with extensive plugin support, from input to output, and everything in between.

Viper

A binary management and analysis framework for analysts and researchers.

Miscellaneous

al-khaser

A PoC malware with good intentions that aimes to stress anti-malware systems.

In 2 lists

CryptoKnight

Automated cryptographic algorithm reverse engineering and classification framework.

DC3-MWCP

The Defense Cyber Crime Center's Malware Configuration Parser framework.

FLARE VM

A fully customizable, Windows-based, security distribution for malware analysis.

In 4 lists

MalSploitBase

A database containing exploits used by malware.

Malware Museum

Collection of malware programs that were distributed in the 1980s and 1990s.

In 2 lists

Malware Organiser

A simple tool to organise large malicious/benign files into a organised Structure.

Pafish

Paranoid Fish, a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do.

In 4 listsDetails

REMnux

Linux distribution and docker images for malware reverse engineering and analysis.

In 5 listsDetails

Tsurugi Linux

Linux distribution designed to support your DFIR investigations, malware analysis and OSINT (Open Source INTelligence) activities.

In 5 listsDetails

Santoku Linux

Linux distribution for mobile forensics, malware analysis, and security.

In 3 lists

Books

Learning Malware Analysis

Learning Malware Analysis: Explore the concepts, tools, and techniques to analuze and investigate Windows malware

Malware Analyst's Cookbook and DVD

Tools and Techniques for Fighting Malicious Code.

Mastering Malware Analysis

Mastering Malware Analysis: The complete malware analyst's guide to combating malicious software, APT, cybercime, and IoT attacks

Mastering Reverse Engineering

Mastering Reverse Engineering: Re-engineer your ethical hacking skills

Practical Malware Analysis

The Hands-On Guide to Dissecting Malicious Software.

Practical Reverse Engineering

Intermediate Reverse Engineering.

Real Digital Forensics

Computer Security and Incident Response.

Rootkits and Bootkits

Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats

The Art of Memory Forensics

Detecting Malware and Threats in Windows, Linux, and Mac Memory.

The IDA Pro Book

The Unofficial Guide to the World's Most Popular Disassembler.

The Rootkit Arsenal

The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System

Other

APT Notes

A collection of papers and notes related to Advanced Persistent Threats.

In 3 lists

Ember

Endgame Malware BEnchmark for Research, a repository that makes it easy to (re)create a machine learning model that can be used to predict a score for a PE file based on static analysis.

In 3 lists

File Formats posters

Nice visualization of commonly used file format (including PE & ELF).

Honeynet Project

Honeypot tools, papers, and other resources.

Kernel Mode

An active community devoted to malware analysis and kernel development.

Malicious Software

Malware blog and resources by Lenny Zeltser.

Malware Analysis Search

Custom Google search engine from Corey Harrell.

Malware Analysis Tutorials

The Malware Analysis Tutorials by Dr. Xiang Fu, a great resource for learning practical malware analysis.

Malware Analysis, Threat Intelligence and Reverse Engineering

Presentation introducing the concepts of malware analysis, threat intelligence and reverse engineering. Experience or prior knowledge is not required. Labs link in description.

Malware Persistence

Collection of various information focused on malware persistence: detection (techniques), response, pitfalls and the log collection (tools).

In 3 lists

Malware Samples and Traffic

This blog focuses on network traffic related to malware infections.

In 2 lists

Malware Search+++

Firefox extension allows you to easily search some of the most popular malware databases

Practical Malware Analysis Starter Kit

This package contains most of the software referenced in the Practical Malware Analysis book.

RPISEC Malware Analysis

These are the course materials used in the Malware Analysis course at at Rensselaer Polytechnic Institute during Fall 2015.

In 4 lists

WindowsIR: Malware

Harlan Carvey's page on Malware.

Windows Registry specification

Windows registry file format specification.

/r/csirt_tools

Subreddit for CSIRT tools and resources, with a malware analysis flair.

/r/Malware

The malware subreddit.

/r/ReverseEngineering

Reverse engineering subreddit, not limited to just malware.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed today
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Network Automation

networktocode/awesome-network-automation

Curated Awesome list about Network Automation

Fresh★ 2.9k334 entriesPushed yesterday