Change the repository type filter
All
Repositories list
34 repositories
LLM-DGA-lab
PublicMALVADA
PublicMALVADA: Malware Execution Traces Dataset generation.MalGraphIQ
PublicTransform your malware sandbox reports and execution traces into behavior and category graphs and plot their Windows Behavior Catalog (WBC) behavior identification.rme-Python-toolkit
PublicKeyReaper
PublicAPOTHEOSIS
PublicA specialized implementation of the Hierarchical Navigable Small World (HNSW) data structure adapted for efficient nearest neighbor lookup of approximate matching hashesRAMPAGE
PublicRAMPAGE is a framework aimed at training and comparing machine learning models for the detection of Algorithmically Generated Domains.synoptic
PublicSynoptic: Concolic execution for network protocol inferencewinapi-categories
PublicWindows API (WinAPI) functions and system calls with categories in JSON format, including arguments (SAL notation) and more.windows-behavior-catalog
PublicWindows Behavior Catalog (WBC) is a collection of fundamental behaviors for Windows OS, represented as a sequence of Windows API and/or syscalls.heaplist
PublicVolatility 3 plugin to extract the heap from Windows memory imagesMANTILLA
Publiccapemon
Publiccape-hook-generator
PublicCAPEv2 (capemon) hook skeleton generator (hookdefs) for your malware analysis needs.winesap
PublicVolatility plugin to search for all Autostart Extensibility Points (AESPs)MOSTO-Modbus-simulator
Publicprocessfuzzyhash
PublicVolatility plugin to calculate and compare Windows processes fuzzy hashes- Volatility plugin to yield and compare similarity digest of modules on execution.
windows-memory-extractor
PublicEvalMe
PublicpinVMShield
PublicA pintool for protecting a sandbox application of common anti-virtualmachine and anti-sandbox detection techniquesSecure_Socket
PublicC++ Sockets implementing hybrid encryptionmalscan
PublicVolatility plugin to detect malicious code thanks to ClamAVsigcheck
PublicVolatility plugin to validate Authenticode-signed processes, either with embedded signature or catalog-signedmodex
PublicVolatility 3 plugins to extract a module as complete as possiblerop3
PublicA tool to search for gadgets, operations, and ROP chains using a backtracking algorithm in a tree-like structurechiton
Publicsum-plugin
PublicVolatility 2.6 plugin to undo modifications done by relocation process on modules- Tool to find memory artifacts present in instant messaging applications.