#malware


  1. yara-x

    A pure Rust implementation of YARA

    v1.19.0 64K #regex #malware #yara #forensics

  2. malwaredb

    Service for storing malicious, benign, or unknown files and related metadata and relationships

    v0.3.6 #malware #forensics #malware-research #security

  3. aws-sdk-guardduty

    AWS SDK for Amazon GuardDuty

    v1.126.0 9.7K #aws-sdk #amazon-s3 #malware #guard-duty #ec2-instance #web-services #dns #api-calls #amazon-ec2 #threat-intelligence

  4. reknife

    A reverse engineer’s binary Swiss-army knife: parse, triage, and disassemble PE/ELF/Mach-O. Installs as knife.

    v1.3.0 #reverse-engineering #pe #disassembly #malware #security

  5. virustotal-rs

    Rust SDK for VirusTotal API v3

    v0.4.4 #malware #threat-intelligence #security #api-security #api

  6. libscemu

    x86 32/64bits and system internals emulator, for securely emulating malware and other stuff

    v0.19.4 17K #emulation #malware #shellcode #x86-64 #pe #64bits #exe

  7. fast-flirt

    Fast, thread-safe FLIRT (Fast Library Identification and Recognition Technology) signature parser and matcher

    v0.2.2 160 #malware #signature #flirt #flare #reverse-engineering

  8. mwemu-mcp

    Model Context Protocol (MCP) server for the mwemu x86/x64/arm64 emulator (libmwemu). Open a binary, configure, prepare memory and emulate step by step over MCP.

    v0.1.0 #emulation #x86-64 #malware #mcp #reverse-engineering #emulator

  9. injectum

    The modern, type-safe process injection framework for Red Teams and Offensive Security in Rust

    v0.2.4 #malware #mitre #redteam #security #windows

  10. packguard-policy

    PackGuard policy engine: offset rules, pins, recommended-version computation

    v0.6.5 #malware #packguard #policy-engine #react #cve #supply-chain-security #dashboard #pin #typosquat #governance

  11. syara-x

    Super YARA — extends YARA-compatible rules with semantic, classifier, and LLM-based matching

    v0.4.0 #yara #malware #semantic #security

  12. malwaredb-virustotal

    Logic and datatypes for interacting with VirusTotal

    v0.5.4 500 #virus-total #malware-analysis #malware #security

  13. nimrod

    Parse and inspect Nim-compiled native binaries

    v0.3.0 #reverse-engineering #nim #malware #binary-analysis #malware-analysis

  14. unquarantine

    Unquarantine/decrypt/extract quarantined files from ~40 AV products

    v0.3.1 #malware #quarantine #forensics

  15. apk-info

    APK full-featured parser

    v1.0.11 #android #malware #apk #arsc #axml

  16. sigil-cli

    Automated security auditing for AI agent code - quarantine-first scanning for pip, npm, git repos, and MCP servers

    v1.1.2 #supply-chain-security #ai-agent #malware #security-scanning #scanning

  17. vaas

    Check files and hashes for malicious content

    v7.1.1 #malware #antivirus #security #api-bindings

  18. packguard-intel

    PackGuard vulnerability intel: OSV + GHSA fetchers, parsers, dedup

    v0.6.5 #malware #packguard #react #vulnerabilities #osv #cve #dashboard #supply-chain-security #advisory #governance

  19. packguard-store

    PackGuard SQLite store: migrations, persistence, fingerprinting

    v0.6.5 #malware #packguard #dashboard #cve #scan #supply-chain-security #sqlite-store #governance #git #modes

  20. scanii

    Minimal-dependency Rust SDK for the Scanii content security API

    v1.3.0 #sdk #malware #content-moderation #security

  21. assemblyline-models

    Data models for the Assemblyline malware analysis platform

    v0.8.1 #malware #malware-analysis #assemblyline #model #component

  22. packguard-server

    PackGuard HTTP server: REST API + job runner backing the dashboard

    v0.6.5 #rest #malware #dashboard #packguard #cve #governance #job-runner #supply-chain-security #typosquat #policy-engine

  23. yara-x-proto

    Protocol buffer with options for YARA modules

    v1.19.0 48K #yara-x #protobuf #module #intend #malware

  24. yarlint

    A modern YARA linter written in Rust

    v0.2.0 #yara #malware #lint #security

  25. yara-x-parser

    A parsing library for YARA rules

    v1.19.0 56K #yara #yara-x #regex #yara-rules #expression #case-insensitive #ak #malware

  26. mwemu

    x86 32/64bits and system internals emulator, for securely emulating malware and other stuff

    v0.8.5 #emulation #malware #x86-64 #64bits #vv #metasploit #cargo-run

  27. bbpe

    Binary byte pair encoding (BPE) trainer and CLI compatible with Hugging Face tokenizers

    v0.6.3 #bpe #malware #hugging-face #binary #tokenizer

  28. apk-info-cli

    A command-line tool to inspect and extract APK files

    v1.0.11 #android #malware #apk #arsc #axml

  29. packguard-actions

    PackGuard Page Actions engine: generates prioritized remediation actions from the store + policy + intel, with dismiss/defer persistence

    v0.6.5 #action #malware #packguard #dashboard #store #policy-engine #governance #supply-chain-security #cve #remediation

  30. redis-objects

    Object oriented wrapper around redis client for the Assemblyline malware analysis platform

    v2.0.0 #object-oriented #redis #malware #malware-analysis #assemblyline

  31. floss-cli

    在 Rust 中以子进程方式调用 FLARE FLOSS CLI,并可选解析 -j JSON 输出

    v0.1.2 #malware #cli #reverse-engineering #wrapper

  32. libmwemu

    x86 32/64bits and system internals emulator, for securely emulating malware and other stuff

    v0.25.3 110 #malware #x86-64 #emulation #maps #winapi #64bits

  33. yara-x-fmt

    A code-formatting library for YARA rules

    v1.17.0 280 #yara #yara-x #pattern #yara-rules #boolean #code-formatting #malware

  34. yara-x-cli

    A command-line interface for YARA-X

    v1.19.0 #yara #regex #documentation #command-line-interface #create #malware

  35. tlsh-rs

    Pure Rust TLSH implementation with library and CLI support

    v0.1.0 #malware #similarity #fuzzy-hashing #security

  36. scanbridge

    A unified, pluggable API for malware scanning with circuit breakers, policy enforcement, and audit logging

    v0.3.0 #malware #clam-av #scanning #antivirus #security

  37. malwaredb-api

    Common API endpoints and data types for MalwareDB components

    v0.3.6 #malware #malware-research #security #forensics #api-bindings

  38. telfhash-rs

    Rust 2024 implementation of Trend Micro telfhash for ELF similarity hashing

    v0.1.0 #elf #malware #similarity #forensics #tlsh

  39. blocklist

    The project is based on blocklistproject. It provides perfect hash map/set structures for fast lookup of blocklisted items.

    v0.4.0 #hash-map #perfect-hash-map #malware #hash-map-set #structures #bittorrent #ads #fraud #gambling #phishing

  40. attack-data

    Request Mitre ATTACK data offline

    v1.0.0 #mitre #att-and-ck #stix #search #id #malware #embedded

  41. malware-modeler

    Train logisitic regression models for benign vs. malicious files based on byte n-grams and publish research, plus related tools.

    v0.0.5 #malware #security #machine-learning #research

  42. rune-entropy

    Shannon entropy calculator for files and byte streams — useful for detecting encrypted, packed, or compressed data

    v0.2.1 #malware-analysis #malware #forensics #analysis #entropy

  43. silly-png

    embed shellscripts and files into png files!

    v1.3.1 650 #png #shellscripts #embed #script #silly #malware

  44. npm_sentinel

    A CLI tool to detect supply chain attacks in npm packages by analyzing lifecycle scripts, dependencies, and registry metadata

    v0.3.0 #supply-chain #malware #malware-analysis #npm #analysis #security

  45. santh-sear

    Real-time URL detonation engine. Built for speed.

    v0.1.0 #malware #url #detonation #phishing #security

  46. dnsink

    A high-performance DNS proxy with threat intelligence, Shannon-entropy tunneling detection, and Prometheus metrics

    v0.3.0 #dns #dns-proxy #threat-intelligence #malware #security

  47. assemblyline-markings

    using access control strings with the Assemblyline malware analysis platform

    v0.2.0 #classification #assemblyline #malware #string #malware-analysis #markings

  48. malwaredb-types

    Data types and parsers for MalwareDB

    v0.3.6 #malware #malware-research #security #forensics

  49. malwaredb-client

    Client application and library for connecting to MalwareDB

    v0.3.6 #malware #malware-research #security #forensics

  50. mace

    Automated extration of malware configuration, focusing on C2 communication

    v0.1.4 #malware #malware-analysis #dga #malware-extraction

  51. npmls

    Fast cross-platform scanner for npm modules and malicious packages

    v0.4.0 #security-scanner #malware #npm

  52. assemblyline-client

    A client for the Assemblyline malware analysis platform

    v0.2.1 #assemblyline #malware #malware-analysis #api #platform

  53. cart_container

    The CaRT file format is used to store or transfer malware and it's associated metadata. It neuters the malware so it cannot be executed, and encrypts it so anti-virus software cannot flag the CaRT file as malware

    v1.0.0 4.1K #encryption #malware #security

  54. yara-x-capi

    A C API for the YARA-X library

    v1.19.0 #yara-x #documentation #matching #pattern #condition #regex #malware

  55. malwaredb-server

    Server data storage logic for MalwareDB

    v0.3.6 #malware #malware-research #security #forensics

  56. malwaredb-virustotal-bin

    VirusTotal command line client

    v0.5.4 #malware-analysis #virus-total #malware #security

  57. assemblyline-filestore

    A blob storage layer for the Assemblyline malware analysis platform

    v0.2.1 #data-storage #assemblyline #malware #malware-analysis #storage-layer

  58. malwaredb-client-py

    Python client for MalwareDB

    v0.3.6 #malware #python #malware-research #security #forensics

  59. yara-x-proto-yaml

    converts protocol buffers into YAML

    v1.17.0 #yara-x #protobuf #yaml #convert #intend #malware

  60. yara-x-proto-json

    converts protocol buffers into JSON

    v1.17.0 #yara-x #protobuf #json #convert #malware

  61. deoptimizer

    machine code de-optimizer. By transforming/mutating the machine code instructions to their functional equivalents it makes possible to bypass pattern-based detection mechanisms used by security products.

    v0.1.2 170 #malware #detect #evasion #optimization #obfuscation

  62. threatflux-string-analysis

    Advanced string analysis and categorization library for security applications

    v0.1.1 360 #malware #string-analysis #security-analysis #forensics #threat-detection

  63. maec-rs

    MAEC (Malware Attribute Enumeration and Characterization) data model library for Rust

    v0.1.0 #malware #malware-analysis #threat-intelligence #security #analysis

  64. stringzz

    strings and opcodes extraction from various file formats

    v0.3.4 #malware #string #yara #yara-generator #maturin

  65. proteus-engine

    Advanced zero-day static analysis engine built with Rust and Python

    v0.2.0 #static-analysis #malware-analysis #malware #engine #security

  66. pyrograph

    GPU-accelerated taint analysis for supply chain malware detection

    v0.1.0 #malware-analysis #malware #supply-chain-security #security #taint-analysis

  67. slickaf

    Cobalt Strike beacon config parser and C2 communication library. Memory-safe, SIMD-accelerated, zero-copy. The Python CobaltStrikeParser rewritten in Rust.

    v0.1.0 #beacon #dfir #malware #forensics #cobalt-strike

  68. polyswarm-api

    Client library for the PolySwarm consumer API

    v0.1.0 #malware #api-client #threat-intelligence #polyswarm

  69. apk-info-xml

    A small custom library for easy working with xml dom

    v1.0.11 #malware #apk #arsc #axml #android

  70. syara-x-capi

    C API for syara-x

    v0.3.1 #yara #malware #semantic #security

  71. apk-info-zip

    correctly unpacking APK files that use the BadPack technique

    v1.0.11 #malware #apk #android #arsc #axml

  72. open-detect

    Static malware detection engine with YARA rule support and automatic archive extraction for security researchers

    v0.1.1 #malware #archive #malware-detection #yara #detect #archive-extract #security #send-sync

  73. vtpipeline

    Collect files and anti-virus reports from VirusTotal to build your own collection of malicious and benign files

    v0.1.1 #virus-total #malware #malware-research

  74. apk-info-axml

    working with AXML and ARSC in APK files

    v1.0.11 #malware #arsc #apk #axml #android

  75. iocutil

    IoC utilities for malware researchers

    v0.1.3 #malware #ioc #researchers #utilities #hash #virus-total #scrape #otx

  76. packguard-core

    PackGuard core library: manifest parsing, registry clients, semver classification

    v0.6.5 #malware #react #graph #cve #policy-engine #classification #governance #dashboard #git #supply-chain-security

  77. assemblyline-server

    Server package for the Assemblyline malware analysis platform

    v0.1.0 #malware #assemblyline #platform #component #analysis #malware-analysis
  78. Try searching with DuckDuckGo.


  79. jopcall

    Dynamically executed Windows Syscalls via JOP/ROP

    v0.1.0 #syscalls #malware #cybersecurity

  80. Malware_Rhapsody

    Small researching of Linux's security for fun and education.. don't be silly to use it in wild. Have a great day, Dear Researcher/Scholar 💯❤️

    v0.0.2 #malware_rhapsody #malware #fun #education #research #simple

  81. yara-forge

    A powerful Rust library for crafting, validating, and managing YARA rules

    v0.1.0 #yara #yara-rules #malware #malware-detection #security

  82. tenshi

    Unbound local-zone generator for curated hosts files

    v0.2.2 #malware #host #unbound #adware

  83. amsi

    Wrapper for Windows Anti Malware Scan Interface

    v0.1.0 #malware #winapi #ffi #windows

  84. cart-rs

    A cart library that can cart/uncart data in a high performance streaming fashion

    v1.2.3 #data-streaming #footer #zlib #rc4 #high-performance #malware #streaming-download #amazon-s3

  85. xorstring

    Compile-time string XOR encryption

    v0.1.0 #encryption #compile-time #byte-string #xor #compile-time-string #decryption #malware

  86. cryptatools-core

    providing cryptographic tools and utilities

    v0.1.20 #cryptography #encryption #cryptanalysis #exploit #ctf #security #researcher #malware #hash #cryptocurrency

  87. armorlib

    Easily scan files for threats to security and privacy

    v0.2.3 #malware #steganography #os

  88. urlsafe

    defang and re-arm malicious URLs

    v0.1.1 #url #malicious #re-arm #decode #link #defang #malware #url-scheme

  89. cryptatools-cli

    providing cryptographic tools and utilities

    v0.1.0 #cryptography #ctf #researcher #player #cryptanalysis #security #malware #cryptocurrency #power-shell #reverse-engineering

  90. pcell

    malware sample cold storage tool

    v0.7.1 #malware #sample #cold-storage #database

  91. entropyscan-rs

    File entropy scanner to detect malware

    v0.1.0 #detect #malware #scanner #struct #entropy #hunting #threat

  92. rair-gui

    Reverse Engineering framework written in rust

    v0.1.0 #reverse-engineering #malware #disassembly

  93. plugin-system

    project plugin management system using Cargo

    v0.1.1 #plugin-management #management-system #using-cargo #version #install #malware

  94. plugin-runtime-codegen

    proc-macro generation for plugin-system runtime

    v0.1.1 #plugin-system #run-time #using-cargo #plugin-management #declare #management-system #proc-macro #proc-macro-generation #malware #child-process