functure's Stars
hfiref0x/UACME
Defeating Windows User Account Control
microsoft/Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
lief-project/LIEF
LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
InQuest/awesome-yara
A curated list of awesome YARA rules, tools, and people.
lifting-bits/mcsema
Framework for lifting x86, amd64, aarch64, sparc32, and sparc64 program binaries to LLVM bitcode
BinaryAnalysisPlatform/bap
Binary Analysis Platform
mstorsjo/llvm-mingw
An LLVM/Clang/LLD based mingw-w64 toolchain
eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations
Neo23x0/yarGen
yarGen is a generator for YARA rules
andrivet/ADVobfuscator
Obfuscation library based on C++11/14 and metaprogramming
GoSecure/malboxes
Builds malware analysis Windows VMs so that you don't have to.
ctxis/CAPE
Malware Configuration And Payload Extraction
unipacker/unipacker
Automatic and platform-independent unpacker for Windows binaries based on emulation
mitre/multiscanner
Modular file scanning/analysis framework
InQuest/iocextract
Defanged Indicator of Compromise (IOC) Extractor.
FiligranHQ/zotprime
Full packaged on-premise Zotero platform
dchad/malware-detection
Malware Detection and Classification Using Machine Learning
cuckoosandbox/community
Repository of modules and signatures contributed by the community
therealdreg/anticuckoo
A tool to detect and crash Cuckoo Sandbox
therealdreg/DbgChild
Debug Child Process Tool (auto attach)
PayloadSecurity/VxAPI
A generic interface and CLI for all endpoints of the Falcon Sandbox API
doomedraven/Tools
Combination of different utilities, have fun!
koemeet/rtti-obfuscator
Obfuscates all RTTI (Run-time type information) inside a binary
yazhiwang/ollvm-tll
Ollvm+Armariris+LLVM 6.0.0
roachspray/opcde2017
Slides and very basic examples
urwithajit9/ClaMP
A Malware classifier dataset built with header fields’ values of Portable Executable files
ocatak-zz/malware_api_class
Malware dataset for security researchers, data scientists. Public malware dataset generated by Cuckoo Sandbox based on Windows OS API calls analysis for cyber security researchers
nihilboy/anti
Automated Integration of anti-Reversing methods in PE executables
deadbits/yara-rules
Collection of YARA signatures from individual research
juju4/ansible-cuckoo-sandbox
Cuckoo sandbox ansible role