
PEpper
An open source script to perform malware static analysis on Portable Executable

An open source script to perform malware static analysis on Portable Executable

PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.


Web shell scanner and analyzer.

Automatically create YARA rules from malicious documents.

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

More than a ReClass port to the .NET platform.

FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Fast and accurate AI powered file content types detection

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…