
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Multi-engine threat hunting tool for triaging malware samples, URLs, IPs, and IOCs across 20+ services including VirusTotal, Hybrid Analysis, and…

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Automated phishing email analysis tool integrating TheHive, Cortex, and MISP to extract observables, run analyzers, calculate verdicts, and notify…

A tool for studying JavaScript malware.

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

Live usermode Windows memory analysis tool that detects malware IOCs by scanning process memory regions, filtering false positives, and dumping…

CLI tool to search, aggregate, and store IOCs from multiple open security feeds and APIs, enabling local threat intelligence database creation and…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

SAP NetWeaver vulnerability and compromise assessment tool that detects CVE-2025-31324/42999, scans for IOCs, analyzes HTTP access and Java trace…

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…