
awesome-malware-analysis
Defund the Police.

Defund the Police.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

An strace-like program for the Windows 'native' API

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

An API hooking framework for intercepting and monitoring Windows applications

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

.NET deobfuscator and unpacker.

x64 Dynamic Reverse Engineering Toolkit

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Golang bindings for PE-sieve

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

A script to detect stack-strings by using emulation (leveraging Unicorn)

Remote access trojan created using WinRar with firefox installer and python Reverse Shell embedded.

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

MAPS cloud scanner and response parser for Microsoft Defender research.

DNSChef - DNS proxy for Penetration Testers and Malware Analysts