Skip to main content
buildradar
Sign in
Topic · malware-analysis

malware-analysis

Tracked open-source repos tagged malware-analysis, sorted by stars.

86 repos
  • flare-fakenet-ng@mandiant

    FakeNet-NG - Next Generation Dynamic Network Analysis Tool

    2,187+3Star change over the last 7 days
  • malware_training_vol1@hasherezade

    Materials for Windows Malware Analysis training (volume 1)

    2,103+1Star change over the last 7 days
  • Qu1cksc0pe@CYB3RMX

    All-in-One malware analysis tool.

    2,049-2Star change over the last 7 days
  • speakeasy@mandiant

    Windows kernel and user mode emulation.

    2,039+2Star change over the last 7 days
  • hrtng@KasperskyLab

    IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformations

    1,919+2Star change over the last 7 days
  • x64dbg-MCP Server is a native MCP (Model Context Protocol) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Connect any MCP-compatible AI assistant and control x64dbg programmatically: set breakpoints, step through code, read memory, dump registers, and more. Built with Zig — zero dependencies, single-binary output, cros

    1,907+181Star change over the last 7 days
  • yarGen@Neo23x0

    yarGen is a generator for YARA rules

    1,812+1Star change over the last 7 days
  • quark-engine@ev-flow
    1,714+1Star change over the last 7 days
  • tiny_tracer@hasherezade

    A Pin Tool for tracing API calls etc

    1,695+2Star change over the last 7 days
  • A curated list of awesome resources related to executable packing

    1,615+1Star change over the last 7 days
  • LitterBox@BlackSnufkin

    A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

    1,533+1Star change over the last 7 days
  • flare-learning-hub@mandiant

    Free educational content on reverse engineering and malware analysis from the FLARE team

    1,442+5Star change over the last 7 days
  • Course Repository for University of Cincinnati Malware Analysis Class (CS[567]038)

    1,384+1Star change over the last 7 days
  • drakvuf-sandbox@CERT-Polska

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

    1,338+3Star change over the last 7 days
  • drakvuf@tklengyel

    DRAKVUF Black-box Binary Analysis

    1,272+2Star change over the last 7 days
  • a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM

    1,271+2Star change over the last 7 days
  • Malware-Exhibit@alvin-tosh

    🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.

    1,182+1Star change over the last 7 days
  • ViperMonkey@decalage2

    A VBA parser and emulation engine to analyze malicious macros.

    1,125+1Star change over the last 7 days
  • AsmResolver@Washi1337

    A library for creating, reading and editing PE files and .NET modules.

    1,119+1Star change over the last 7 days
  • open-reverselab@LING71671

    Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.

    1,093Star change over the last 7 days
  • thorium@cisagov

    A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.

    1,022+0Star change over the last 7 days
  • reverify@2akouwu

    Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.

    1,019Star change over the last 7 days
  • toolkit@indetectables-net

    The essential toolkit for reversing, malware analysis, and cracking

    1,007+0Star change over the last 7 days
  • honeypots@qeeqbox

    30 different honeypots in one package! (dhcp, dns, elastic, ftp, http proxy, https proxy, http, https, imap, ipp, irc, ldap, memcache, mssql, mysql, ntp, oracle, pjl, pop3, postgres, rdp, redis, sip, smb, smtp, snmp, socks5, ssh, telnet, vnc)

    987+2Star change over the last 7 days
  • A curated list of tools officially presented at Black Hat events

    980+8Star change over the last 7 days
  • flare-emu@mandiant
    955+0Star change over the last 7 days
  • fame@certsocietegenerale

    FAME Automates Malware Evaluation

    946+0Star change over the last 7 days
  • malware-samples@InQuest

    A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net

    938+0Star change over the last 7 days
  • Reverse Engineering and Malware Analysis Roadmap

    899+3Star change over the last 7 days
  • IPA@seekbytes

    GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat analysis.

    881+0Star change over the last 7 days
← Back to topics