#2Tools for observing malware behavior in isolated environments to understand its actions and impact.
Kitploit recommended

Drltrace is a library calls tracer for Windows and Linux applications.
An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android…

Policy-driven, layered isolation and containment

DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

⚡️ Multiple target ZAP Scanning

Reverse engineering analysis of PureRAT RAT abusing msbuild.exe, extracting C2 infrastructure, .NET evasion APIs, file system manipulation, and…

Main repo for hosting release binaries

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Sandboxie Plus & Classic

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Windows memory hacking library

Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!

A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…