yara-x
A pure Rust implementation of YARA
malwaredb
Service for storing malicious, benign, or unknown files and related metadata and relationships
aws-sdk-guardduty
AWS SDK for Amazon GuardDuty
reknife
A reverse engineer’s binary Swiss-army knife: parse, triage, and disassemble PE/ELF/Mach-O. Installs as
knife.
virustotal-rs
Rust SDK for VirusTotal API v3
libscemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
fast-flirt
Fast, thread-safe FLIRT (Fast Library Identification and Recognition Technology) signature parser and matcher
mwemu-mcp
Model Context Protocol (MCP) server for the mwemu x86/x64/arm64 emulator (libmwemu). Open a binary, configure, prepare memory and emulate step by step over MCP.
injectum
The modern, type-safe process injection framework for Red Teams and Offensive Security in Rust
packguard-policy
PackGuard policy engine: offset rules, pins, recommended-version computation
syara-x
Super YARA — extends YARA-compatible rules with semantic, classifier, and LLM-based matching
malwaredb-virustotal
Logic and datatypes for interacting with VirusTotal
nimrod
Parse and inspect Nim-compiled native binaries
unquarantine
Unquarantine/decrypt/extract quarantined files from ~40 AV products
apk-info
APK full-featured parser
sigil-cli
Automated security auditing for AI agent code - quarantine-first scanning for pip, npm, git repos, and MCP servers
vaas
Check files and hashes for malicious content
packguard-intel
PackGuard vulnerability intel: OSV + GHSA fetchers, parsers, dedup
packguard-store
PackGuard SQLite store: migrations, persistence, fingerprinting
scanii
Minimal-dependency Rust SDK for the Scanii content security API
assemblyline-models
Data models for the Assemblyline malware analysis platform
packguard-server
PackGuard HTTP server: REST API + job runner backing the dashboard
yara-x-proto
Protocol buffer with options for YARA modules
yarlint
A modern YARA linter written in Rust
yara-x-parser
A parsing library for YARA rules
mwemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
bbpe
Binary byte pair encoding (BPE) trainer and CLI compatible with Hugging Face tokenizers
apk-info-cli
A command-line tool to inspect and extract APK files
packguard-actions
PackGuard Page Actions engine: generates prioritized remediation actions from the store + policy + intel, with dismiss/defer persistence
redis-objects
Object oriented wrapper around redis client for the Assemblyline malware analysis platform
floss-cli
在 Rust 中以子进程方式调用 FLARE FLOSS CLI,并可选解析 -j JSON 输出
libmwemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
yara-x-fmt
A code-formatting library for YARA rules
yara-x-cli
A command-line interface for YARA-X
tlsh-rs
Pure Rust TLSH implementation with library and CLI support
scanbridge
A unified, pluggable API for malware scanning with circuit breakers, policy enforcement, and audit logging
malwaredb-api
Common API endpoints and data types for MalwareDB components
telfhash-rs
Rust 2024 implementation of Trend Micro telfhash for ELF similarity hashing
blocklist
The project is based on blocklistproject. It provides perfect hash map/set structures for fast lookup of blocklisted items.
attack-data
Request Mitre ATTACK data offline
malware-modeler
Train logisitic regression models for benign vs. malicious files based on byte n-grams and publish research, plus related tools.
rune-entropy
Shannon entropy calculator for files and byte streams — useful for detecting encrypted, packed, or compressed data
silly-png
embed shellscripts and files into png files!
npm_sentinel
A CLI tool to detect supply chain attacks in npm packages by analyzing lifecycle scripts, dependencies, and registry metadata
santh-sear
Real-time URL detonation engine. Built for speed.
dnsink
A high-performance DNS proxy with threat intelligence, Shannon-entropy tunneling detection, and Prometheus metrics
assemblyline-markings
using access control strings with the Assemblyline malware analysis platform
malwaredb-types
Data types and parsers for MalwareDB
malwaredb-client
Client application and library for connecting to MalwareDB
mace
Automated extration of malware configuration, focusing on C2 communication
npmls
Fast cross-platform scanner for npm modules and malicious packages
assemblyline-client
A client for the Assemblyline malware analysis platform
cart_container
The CaRT file format is used to store or transfer malware and it's associated metadata. It neuters the malware so it cannot be executed, and encrypts it so anti-virus software cannot flag the CaRT file as malware
yara-x-capi
A C API for the YARA-X library
malwaredb-server
Server data storage logic for MalwareDB
malwaredb-virustotal-bin
VirusTotal command line client
assemblyline-filestore
A blob storage layer for the Assemblyline malware analysis platform
malwaredb-client-py
Python client for MalwareDB
yara-x-proto-yaml
converts protocol buffers into YAML
yara-x-proto-json
converts protocol buffers into JSON
deoptimizer
machine code de-optimizer. By transforming/mutating the machine code instructions to their functional equivalents it makes possible to bypass pattern-based detection mechanisms used by security products.
threatflux-string-analysis
Advanced string analysis and categorization library for security applications
maec-rs
MAEC (Malware Attribute Enumeration and Characterization) data model library for Rust
stringzz
strings and opcodes extraction from various file formats
proteus-engine
Advanced zero-day static analysis engine built with Rust and Python
pyrograph
GPU-accelerated taint analysis for supply chain malware detection
slickaf
Cobalt Strike beacon config parser and C2 communication library. Memory-safe, SIMD-accelerated, zero-copy. The Python CobaltStrikeParser rewritten in Rust.
polyswarm-api
Client library for the PolySwarm consumer API
apk-info-xml
A small custom library for easy working with xml dom
syara-x-capi
C API for syara-x
apk-info-zip
correctly unpacking APK files that use the BadPack technique
open-detect
Static malware detection engine with YARA rule support and automatic archive extraction for security researchers
vtpipeline
Collect files and anti-virus reports from VirusTotal to build your own collection of malicious and benign files
apk-info-axml
working with AXML and ARSC in APK files
iocutil
IoC utilities for malware researchers
packguard-core
PackGuard core library: manifest parsing, registry clients, semver classification
assemblyline-server
Server package for the Assemblyline malware analysis platform
jopcall
Dynamically executed Windows Syscalls via JOP/ROP
Malware_Rhapsody
Small researching of Linux's security for fun and education.. don't be silly to use it in wild. Have a great day, Dear Researcher/Scholar 💯❤️
yara-forge
A powerful Rust library for crafting, validating, and managing YARA rules
tenshi
Unbound local-zone generator for curated hosts files
amsi
Wrapper for Windows Anti Malware Scan Interface
cart-rs
A cart library that can cart/uncart data in a high performance streaming fashion
xorstring
Compile-time string XOR encryption
cryptatools-core
providing cryptographic tools and utilities
armorlib
Easily scan files for threats to security and privacy
urlsafe
defang and re-arm malicious URLs
cryptatools-cli
providing cryptographic tools and utilities
pcell
malware sample cold storage tool
entropyscan-rs
File entropy scanner to detect malware
rair-gui
Reverse Engineering framework written in rust
plugin-system
project plugin management system using Cargo
plugin-runtime-codegen
proc-macro generation for plugin-system runtime
Try searching with DuckDuckGo.