Reedo's starred repositories

awesome-threat-intelligence

A curated list of Awesome Threat Intelligence resources

Malware

Course materials for Malware Analysis by RPISEC

flare-floss

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Language:PythonLicense:Apache-2.0Stargazers:3245Issues:132Issues:479
Language:PowerShellLicense:GPL-3.0Stargazers:2185Issues:129Issues:15

php-malware-finder

Detect potentially malicious PHP files

Language:PHPLicense:LGPL-3.0Stargazers:1469Issues:75Issues:88

intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Language:PythonLicense:AGPL-3.0Stargazers:975Issues:77Issues:1224

Kam1n0-Community

The Kam1n0 Assembly Analysis Platform

Language:CLicense:Apache-2.0Stargazers:615Issues:51Issues:48

DIE

Dynamic IDA Enrichment

Language:PythonLicense:MITStargazers:468Issues:44Issues:23

Shell-Detector

Shell Detector – is a application that helps you find and identify php/cgi(perl)/asp/aspx shells. Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%.

cuckoo-modified

Modified edition of cuckoo

CDQR

The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted drives and extracted artifacts from Windows, Linux, MacOS, and Android devices

Language:PythonLicense:GPL-3.0Stargazers:333Issues:30Issues:26

DC3-MWCP

DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, filenames, and mutex names.

Language:PythonLicense:NOASSERTIONStargazers:299Issues:43Issues:20

LoadDll

Better version of RunDll with GUI. This program allows you to load DLLs on Windows. You can select how to load the DLL. By direct Entry Point call (DllMain) or if you want to call directly an exported function of the DLL.

SysAnalyzer

Automated malcode analysis system - read more ->

Language:Visual Basic 6.0Stargazers:222Issues:28Issues:6

elsa

Enterprise Log Search and Archive

Language:PerlLicense:GPL-2.0Stargazers:207Issues:40Issues:37

Malfunction

Malware Analysis Tool using Function Level Fuzzy Hashing

Language:PythonLicense:LGPL-2.1Stargazers:191Issues:26Issues:4

osq-ext-bin

Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection

Language:PowerShellLicense:NOASSERTIONStargazers:180Issues:14Issues:11

plaso_filters

Scripts to facilitate filtering with Plaso

GithubDownloader

Find and download files from multiple Github repositories

Language:PythonLicense:MITStargazers:99Issues:26Issues:2

ip2geo

Script to perform bulk local GeoIP lookups (ASN and geo) for IP addresses

ntfs-linker

An NTFS journal parser

Language:C++License:LGPL-3.0Stargazers:82Issues:19Issues:1

r2-scripts

Multiple radare2 rpipe scripts

Language:JavaScriptLicense:LGPL-3.0Stargazers:61Issues:10Issues:2

CIS-ESP

The Center for Internet Security Enumeration and Scanning Program

Language:PythonLicense:Apache-2.0Stargazers:58Issues:18Issues:0

vim-log-syntax

Vim syntax for log highlighting

tools

Various tools and scripts

Language:PythonLicense:MITStargazers:43Issues:5Issues:0

evtx2json

evtx2json extracts events of interest from event logs, dedups them, and exports them to json.

Language:PythonLicense:Apache-2.0Stargazers:41Issues:6Issues:2

YaraRules

Multiple rules for yara-project for detect compiler/packer/protector

Language:YARAStargazers:33Issues:13Issues:0

nyx

Threat Intelligence distribution

Language:PythonLicense:MITStargazers:30Issues:9Issues:2

Google-Analytic-Parser

Parses for Google Analytic values in raw files like RAM, DD images etc.

Language:PythonStargazers:18Issues:2Issues:0