Pinned Repositories
Ablation
Ablation is a tool for augmenting static analysis by extracting information at runtime, and importing it into IDA. It can resolve virtual calls, reveal interesting code, exclude heavily traversed regions, identify untested or undocumented features, visually diff samples, or perform root cause analysis simply by running samples. My favourite however is the virtual call resolution with fully interactive x-refs. It's simple, elegant, and disassembled C++ reads like C! It helps me time and time again.
CyBot
Open Source Threat Intelligence Chat Bot
eBPF_processor
An IDA processor for eBPF bytecode
IntroductionToMachineLearningForSecurityPros
Example code for our book Introduction to Artificial Intelligence for Security Professionals
macos-arm64-emulation
A guide for emulating macOS arm64e on an x86-based host.
MarkovObfuscate
Use Markov Chains to obfuscate data as other data
mitmcanary
Tool/service to detect Man in the Middle attacks with Canary Requests
NMAP-Cluster
Clustering NMAP XML results to help make sense of large scan results.
SMBTrap
Tools developed to test the Redirect to SMB issue
winapi-deobfuscation
Towards Generic Deobfuscation of Windows API Calls
Cylance's Repositories
cylance/CyBot
Open Source Threat Intelligence Chat Bot
cylance/macos-arm64-emulation
A guide for emulating macOS arm64e on an x86-based host.
cylance/IntroductionToMachineLearningForSecurityPros
Example code for our book Introduction to Artificial Intelligence for Security Professionals
cylance/SMBTrap
Tools developed to test the Redirect to SMB issue
cylance/mitmcanary
Tool/service to detect Man in the Middle attacks with Canary Requests
cylance/MarkovObfuscate
Use Markov Chains to obfuscate data as other data
cylance/winapi-deobfuscation
Towards Generic Deobfuscation of Windows API Calls
cylance/Ablation
Ablation is a tool for augmenting static analysis by extracting information at runtime, and importing it into IDA. It can resolve virtual calls, reveal interesting code, exclude heavily traversed regions, identify untested or undocumented features, visually diff samples, or perform root cause analysis simply by running samples. My favourite however is the virtual call resolution with fully interactive x-refs. It's simple, elegant, and disassembled C++ reads like C! It helps me time and time again.
cylance/eBPF_processor
An IDA processor for eBPF bytecode
cylance/NMAP-Cluster
Clustering NMAP XML results to help make sense of large scan results.
cylance/PyPackerDetect
A malware dataset curation tool which helps identify packed samples.
cylance/GetNETGUIDs
Extract GUIDs from .NET assemblies
cylance/python-cyapi
This Library provides python bindings to interact with the Cylance API.
cylance/IDPanel
Identify botnet panels with Ensembled Decision Trees
cylance/rogers
Python command-line tool that uses nearest neighbor search methods for malware similarity analysis
cylance/CyLR
CyLR - Live Response Collection Tool
cylance/GeneralizedConvolutionalNeuralNets
Generalized convolutional neural network algorithm for use with point cloud data with arbitrary spatial features.
cylance/improving-malware-detection-accuracy-by-extracting-icon-information
Code for the paper "Improving Malware Detection Accuracy by Extracting Icon Information"
cylance/CyShell
A Powershell module to interface with Cylance APIs
cylance/lazy-stochastic-principal-component-analysis
Code for the paper "Lazy stochastic principal component analysis"
cylance/REcon2016
BBS-Era Exploitation for Fun and Anachronism
cylance/perturbed-sequence-model
cylance/Prangster
Black-Box Assessment of Pseudorandom Algorithms
cylance/IOCs
cylance/amazon-athena-cross-account-catalog
🌉 Reference implementation for granting cross-account AWS Glue Data Catalog access from Amazon Athena
cylance/cloud-custodian
Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
cylance/petastorm
Petastorm library enables single machine or distributed training and evaluation of deep learning models from datasets in Apache Parquet format. It supports ML frameworks such as Tensorflow, Pytorch, and PySpark and can be used from pure Python code.
cylance/smart_open
Utils for streaming large files (S3, HDFS, gzip, bz2...)
cylance/talus
cylance/talus_client