Change the repository type filter
All
Repositories list
37 repositories
APOTHEOSIS
PublicA specialized implementation of the Hierarchical Navigable Small World (HNSW) data structure adapted for efficient nearest neighbor lookup of approximate matchi…synoptic
PublicSynoptic: Concolic execution for network protocol inferenceMANTILLA
Publicheaplist
PublicVolatility 3 plugin to extract the heap from Windows memory imagesMalGraphIQ
PublicTransform your malware sandbox reports and execution traces into behavior and category graphs and plot their Windows Behavior Catalog (WBC) behavior identificat…KeyReaper
Publicrme-Python-toolkit
PublicLLM-DGA-lab
PublicMALVADA
PublicMALVADA: Malware Execution Traces Dataset generation.RAMPAGE
PublicRAMPAGE is a framework aimed at training and comparing machine learning models for the detection of Algorithmically Generated Domains.winapi-categories
PublicWindows API (WinAPI) functions and system calls with categories in JSON format, including arguments (SAL notation) and more.windows-behavior-catalog
PublicWindows Behavior Catalog (WBC) is a collection of fundamental behaviors for Windows OS, represented as a sequence of Windows API and/or syscalls.capemon
Publiccape-hook-generator
PublicCAPEv2 (capemon) hook skeleton generator (hookdefs) for your malware analysis needs.winesap
PublicVolatility plugin to search for all Autostart Extensibility Points (AESPs)MOSTO-Modbus-simulator
PublicMOSTO is a SCADA network device simulator based on ModbusTCP communications. Based on Python3processfuzzyhash
PublicVolatility plugin to calculate and compare Windows processes fuzzy hashes- Volatility plugin to yield and compare similarity digest of modules on execution.
windows-memory-extractor
PublicTool to extract contents from the memory of Windows systems.EvalMe
PublicpinVMShield
PublicA pintool for protecting a sandbox application of common anti-virtualmachine and anti-sandbox detection techniquesSecure_Socket
PublicC++ Sockets implementing hybrid encryptionmalscan
PublicVolatility plugin to detect malicious code thanks to ClamAVsigcheck
PublicVolatility plugin to validate Authenticode-signed processes, either with embedded signature or catalog-signedmodex
PublicVolatility 3 plugins to extract a module as complete as possiblerop3
PublicA tool to search for gadgets, operations, and ROP chains using a backtracking algorithm in a tree-like structure
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.