
manticore
Symbolic execution tool

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Binary Ninja plugin to identify obfuscated code and other interesting code constructs

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Karonte is a static analysis tool to detect multi-binary vulnerabilities in embedded firmware

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

A tool to detect and crash Cuckoo Sandbox

Linux Kernel Runtime Integrity with eBPF

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

A dynamic unpacking tool

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

A script to detect stack-strings by using emulation (leveraging Unicorn)

An eBPF program to detect attacks on CVE-2022-0847

Detect images that likely exploit CVE-2022-44268