
capa
Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

A python library to parse OneNote (.one) files

YARA rule analyzer to improve rule quality and performance

A Simple PE File Heuristics Scanners

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…


YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

Web shell scanner and analyzer.


Detect potentially malicious PHP files

Automatically create YARA rules from malicious documents.

YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js


Stack overflow in LibXMP

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X,…