
maltrieve
A tool to retrieve malware directly from the source for security researchers.

Modular file scanning/analysis framework

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…



OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Sandboxed Execution Environment

YARA malware query accelerator (web frontend)

A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.

Extract Windows Defender database from vdm files and unpack it

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

An example sandbox using AppContainer (Windows 8+)

Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts

SAFE embeddings to match functions in yara
