
ATMMalScan
Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Command-line DFIR tool for scanning Windows ATM systems to detect malware traces in process memory and disk, with automated memory dump creation for…

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware…

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

Detect potentially malicious PHP files

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Binary Ninja plugin to identify obfuscated code and other interesting code constructs

Yet another static code analyzer for malicious Android applications

Detect and respond to Cobalt Strike beacons using ETW.

PHP-based anti-virus anti-trojan anti-malware solution.

wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

A tool to detect and crash Cuckoo Sandbox

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…


Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…