Change the repository type filter
All
Repositories list
38 repositories
APOTHEOSIS
PublicA specialized implementation of the Hierarchical Navigable Small World (HNSW) data structure adapted for efficient nearest neighbor lookup of approximate matchi…MARISSA
Public- Synoptic: Concolic execution for network protocol inference
MANTILLA
Publicheaplist
PublicVolatility 3 plugin to extract the heap from Windows memory imagesBinTopsy
Public- Transform your malware sandbox reports and execution traces into behavior and category graphs and plot their Windows Behavior Catalog (WBC) behavior identificat…
rme-Python-toolkit
PublicLLM-DGA-lab
PublicMALVADA
PublicMALVADA: Malware Execution Traces Dataset generation.RAMPAGE
PublicRAMPAGE is a framework aimed at training and comparing machine learning models for the detection of Algorithmically Generated Domains.winapi-categories
PublicWindows API (WinAPI) functions and system calls with categories in JSON format, including arguments (SAL notation) and more.windows-behavior-catalog
PublicWindows Behavior Catalog (WBC) is a collection of fundamental behaviors for Windows OS, represented as a sequence of Windows API and/or syscalls.capemon
Publiccape-hook-generator
PublicCAPEv2 (capemon) hook skeleton generator (hookdefs) for your malware analysis needs.winesap
PublicVolatility plugin to search for all Autostart Extensibility Points (AESPs)MOSTO-Modbus-simulator
PublicMOSTO is a SCADA network device simulator based on ModbusTCP communications. Based on Python3processfuzzyhash
PublicVolatility plugin to calculate and compare Windows processes fuzzy hashes- Volatility plugin to yield and compare similarity digest of modules on execution.
windows-memory-extractor
PublicTool to extract contents from the memory of Windows systems.EvalMe
PublicpinVMShield
PublicA pintool for protecting a sandbox application of common anti-virtualmachine and anti-sandbox detection techniquesSecure_Socket
PublicC++ Sockets implementing hybrid encryptionmalscan
PublicVolatility plugin to detect malicious code thanks to ClamAVsigcheck
PublicVolatility plugin to validate Authenticode-signed processes, either with embedded signature or catalog-signedmodex
PublicVolatility 3 plugins to extract a module as complete as possible
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.