MANDIANT (mandiant)

MANDIANT

mandiant

Organization data from Github https://github.com/mandiant

Home Page:http://www.mandiant.com

GitHub:@mandiant

MANDIANT's repositories

flare-vm

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

Language:PowerShellLicense:Apache-2.0Stargazers:7967Issues:201Issues:550

commando-vm

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

Language:PowerShellLicense:Apache-2.0Stargazers:7398Issues:284Issues:234

capa

The FLARE team's open-source tool to identify capabilities in executable files.

Language:PythonLicense:Apache-2.0Stargazers:5641Issues:84Issues:1081

flare-floss

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Language:PythonLicense:Apache-2.0Stargazers:3766Issues:126Issues:495

flare-ida

IDA Pro utilities from FLARE team

Language:PythonLicense:Apache-2.0Stargazers:2403Issues:149Issues:57

flare-fakenet-ng

FakeNet-NG - Next Generation Dynamic Network Analysis Tool

Language:PythonLicense:Apache-2.0Stargazers:2025Issues:112Issues:111

speakeasy

Windows kernel and user mode emulation.

Language:PythonLicense:MITStargazers:1781Issues:57Issues:83

gocrack

GoCrack is a management frontend for password cracking tools written in Go

Language:GoLicense:MITStargazers:1252Issues:55Issues:44
Language:PythonLicense:Apache-2.0Stargazers:897Issues:37Issues:21

GoReSym

Go symbol recovery tool

Language:GoLicense:MITStargazers:842Issues:11Issues:40

stringsifter

A machine learning tool that ranks strings based on their relevance for malware analysis.

Language:PythonLicense:Apache-2.0Stargazers:743Issues:29Issues:22

capa-rules

Standard collection of rules for capa: the tool for enumerating the capabilities of programs

Language:PythonLicense:Apache-2.0Stargazers:408Issues:8Issues:7
Language:PythonLicense:Apache-2.0Stargazers:395Issues:18Issues:5

STrace

A DTrace on Windows Reimplementation

Language:C++License:MITStargazers:358Issues:13Issues:13

xrefer

FLARE Team's Binary Navigator

Language:PythonLicense:Apache-2.0Stargazers:292Issues:3Issues:17

macos-UnifiedLogs

A cross platform parser for Apple UnifiedLogs!

Language:RustLicense:Apache-2.0Stargazers:279Issues:14Issues:37

VM-Packages

Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.

Language:PowerShellLicense:Apache-2.0Stargazers:205Issues:12Issues:589

GeoLogonalyzer

GeoLogonalyzer is a utility to analyze remote access logs for anomalies such as travel feasibility and data center sources.

Language:PythonLicense:Apache-2.0Stargazers:196Issues:27Issues:8

dncil

The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.

Language:PythonLicense:Apache-2.0Stargazers:166Issues:9Issues:11

gostringungarbler

Python tool to resolve all strings in Go binaries obfuscated by garble

Language:PythonLicense:Apache-2.0Stargazers:133Issues:0Issues:2
Language:PythonLicense:Apache-2.0Stargazers:132Issues:2Issues:0

gocrack-ui

The User Interface for GoCrack

Language:VueLicense:MITStargazers:88Issues:7Issues:1

gootloader

Collection of scripts used to deobfuscate GOOTLOADER malware samples.

Language:PythonLicense:Apache-2.0Stargazers:64Issues:8Issues:3

poisonplug-scatterbrain

Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator

Language:PythonLicense:Apache-2.0Stargazers:64Issues:2Issues:0

capa-testfiles

Data to test capa's code and rules.

Language:MaxLicense:Apache-2.0Stargazers:46Issues:6Issues:0

flare-gsoc

Supporting resources and documentation for FLARE @ Google Summer of Code 2025

License:Apache-2.0Stargazers:26Issues:9Issues:0
Language:GoLicense:Apache-2.0Stargazers:11Issues:2Issues:0

flare-floss-testfiles

Resources for testing FLOSS by the FLARE team.

Language:CStargazers:7Issues:4Issues:0