
pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

Scan files or process memory for CobaltStrike beacons and parse their configuration

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Defanged Indicator of Compromise (IOC) Extractor.

A malware analysis and classification tool.

Scripts and utilities to help your hacking needs

Centralized repository for malware samples, threat intelligence, IOCs, and security tooling logs to support threat research and incident response…

Web shell scanner and analyzer.

Visually inspect and force decode YARA and regex matches found in both binary and text data with colors. Lots of colors.

Native YARA scanner X-Tension for X-Ways Forensics, enabling in-snapshot file scanning with multi-threaded RVS support, report table output, and no…

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Public repository of Sigma and YARA rules created by Synacktiv