-
-
qiling Public
Forked from qilingframework/qilingA True Instrumentable Binary Emulation Framework
Python GNU General Public License v2.0 UpdatedNov 23, 2022 -
unicorn Public
Forked from unicorn-engine/unicornUnicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
C GNU General Public License v2.0 UpdatedNov 22, 2022 -
capa-rules Public
Forked from mandiant/capa-rulesStandard collection of rules for capa: the tool for enumerating the capabilities of programs
Apache License 2.0 UpdatedOct 29, 2022 -
capa Public
Forked from mandiant/capaThe FLARE team's open-source tool to identify capabilities in executable files.
Python Apache License 2.0 UpdatedOct 29, 2022 -
ghidra Public
Forked from NationalSecurityAgency/ghidraGhidra is a software reverse engineering (SRE) framework
Java Apache License 2.0 UpdatedAug 2, 2022 -
retdec Public
Forked from avast/retdecRetDec is a retargetable machine-code decompiler based on LLVM.
C++ MIT License UpdatedJul 24, 2022 -
capstone Public
Forked from capstone-engine/capstoneCapstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings.
C Other UpdatedJul 23, 2022 -
zstd Public
Forked from facebook/zstdZstandard - Fast real-time compression algorithm
C Other UpdatedJul 8, 2022 -
NoVmpy Public
Forked from wallds/NoVmpyPython BSD 3-Clause "New" or "Revised" License UpdatedFeb 3, 2022 -
speakeasy Public
Forked from mandiant/speakeasyWindows kernel and user mode emulation.
Python MIT License UpdatedJan 27, 2022 -
VM-Packages Public
Forked from mandiant/VM-PackagesPowerShell Apache License 2.0 UpdatedJan 25, 2022 -
flare-floss Public
Forked from mandiant/flare-flossFLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
Python Apache License 2.0 UpdatedJan 24, 2022 -
-
flare-ida Public
Forked from mandiant/flare-idaIDA Pro utilities from FLARE team
Python Apache License 2.0 UpdatedDec 14, 2021 -
FIDL Public
Forked from mandiant/FIDLA sane API for IDA Pro's decompiler. Useful for malware RE and vulnerability research
Python MIT License UpdatedOct 1, 2021 -
python-idb Public
Forked from williballenthin/python-idbPure Python parser and analyzer for IDA Pro database files (.idb).
Python Apache License 2.0 UpdatedAug 6, 2021 -
-
squid-cache-extractor Public
Forked from wjwoodson/squid-cache-extractorForensic artifact extraction from squid proxy cache and secondary log sources
Python MIT License UpdatedApr 13, 2021 -
jitm Public
Forked from mandiant/jitmJITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.
C++ Apache License 2.0 UpdatedDec 11, 2020 -
malboxes Public
Forked from GoSecure/malboxesBuilds malware analysis Windows VMs so that you don't have to.
Python GNU General Public License v3.0 UpdatedApr 6, 2018 -
flare-fakenet-ng Public
Forked from mandiant/flare-fakenet-ngFakeNet-NG - Next Generation Dynamic Network Analysis Tool
Python Apache License 2.0 UpdatedMar 12, 2018 -
boxstarter Public
Forked from chocolatey/boxstarterRepeatable, reboot resilient windows environment installations made easy using Chocolatey packages
-
flare-dbg Public
Forked from mandiant/flare-dbgflare-dbg is a project meant to aid malware reverse engineers in rapidly developing debugger scripts.
Python UpdatedOct 5, 2017 -
rvmi Public
Forked from mandiant/rvmirVMI - A New Paradigm For Full System Analysis
C GNU General Public License v2.0 UpdatedOct 4, 2017 -
rvmi-qemu Public
Forked from mandiant/rvmi-qemuQEMU with rVMI extensions
C Other UpdatedJul 25, 2017