<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Track Awesome Malware Analysis Updates Daily</title>
  <id>https://www.trackawesomelist.com/rshipp/awesome-malware-analysis/feed.xml</id>
  <updated>2024-07-07T08:56:26.133Z</updated>
  <link rel="self" type="application/atom+xml" href="https://www.trackawesomelist.com/rshipp/awesome-malware-analysis/feed.xml"/>
  <link rel="alternate" type="application/json" href="https://www.trackawesomelist.com/rshipp/awesome-malware-analysis/feed.json"/>
  <link rel="alternate" type="text/html" href="https://www.trackawesomelist.com/rshipp/awesome-malware-analysis/"/>
  <generator uri="https://github.com/bcomnes/jsonfeed-to-atom#readme" version="1.2.2">jsonfeed-to-atom</generator>
  <icon>https://www.trackawesomelist.com/favicon.ico</icon>
  <logo>https://www.trackawesomelist.com/icon.png</logo>
  <subtitle>Defund the Police.</subtitle>
  <entry>
    <id>https://www.trackawesomelist.com/2024/07/07/</id>
    <title>Awesome Malware Analysis Updates on Jul 07, 2024</title>
    <updated>2024-07-07T08:56:26.133Z</updated>
    <published>2024-07-07T08:56:25.806Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.filescan.io/" rel="noopener noreferrer">filescan.io</a> - Static malware analysis, VBA/Powershell/VBS/JS Emulation</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/dhondta/awesome-executable-packing" rel="noopener noreferrer">Executable Packing (⭐1.1k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2024/07/07/"/>
    <summary>2 awesome projects updated on Jul 07, 2024</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2024/05/09/</id>
    <title>Awesome Malware Analysis Updates on May 09, 2024</title>
    <updated>2024-05-09T12:40:21.880Z</updated>
    <published>2024-05-09T12:40:21.874Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://bruteforce.gr/honeydrive/" rel="noopener noreferrer">HoneyDrive</a> - Honeypot bundle Linux distro.</li>
</ul>
<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="http://support.clean-mx.com/clean-mx/viruses.php" rel="noopener noreferrer">Clean MX</a> - Realtime
database of malware and malicious domains.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2024/05/09/"/>
    <summary>2 awesome projects updated on May 09, 2024</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2024/04/20/</id>
    <title>Awesome Malware Analysis Updates on Apr 20, 2024</title>
    <updated>2024-04-20T01:22:48.582Z</updated>
    <published>2024-04-20T01:22:48.274Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/sooshie/packerid" rel="noopener noreferrer">packerid (⭐41)</a> - A cross-platform
Python alternative to PEiD.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.qiling.io/" rel="noopener noreferrer">Qiling Framework</a> - Cross platform emulation and sanboxing
framework with instruments for binary analysis.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2024/04/20/"/>
    <summary>2 awesome projects updated on Apr 20, 2024</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2024/04/16/</id>
    <title>Awesome Malware Analysis Updates on Apr 16, 2024</title>
    <updated>2024-04-16T01:23:21.396Z</updated>
    <published>2024-04-16T01:23:21.396Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://cybercentrecanada.github.io/assemblyline4_docs/" rel="noopener noreferrer">Assemblyline</a> - A scalable file triage and malware analysis system integrating the cyber security community's best tools..</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2024/04/16/"/>
    <summary>1 awesome projects updated on Apr 16, 2024</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/08/19/</id>
    <title>Awesome Malware Analysis Updates on Aug 19, 2020</title>
    <updated>2020-08-19T08:45:05.000Z</updated>
    <published>2020-08-19T08:45:05.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="http://vx-underground.org/" rel="noopener noreferrer">VX Underground</a> - Massive and growing collection of free malware samples.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/08/19/"/>
    <summary>1 awesome projects updated on Aug 19, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/08/15/</id>
    <title>Awesome Malware Analysis Updates on Aug 15, 2020</title>
    <updated>2020-08-15T03:10:20.000Z</updated>
    <published>2020-08-15T02:17:42.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/cmu-sei/pharos" rel="noopener noreferrer">fn2yara (⭐1.5k)</a> - FN2Yara is a tool to generate
Yara signatures for matching functions (code) in an executable program.</li>
</ul>
<h3><p>Browser Malware / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Konloch/bytecode-viewer" rel="noopener noreferrer">Bytecode Viewer (⭐14k)</a> - Combines
multiple Java bytecode viewers and decompilers into one tool, including
APK/DEX support.</li>
</ul>
<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/extremecoders-re/pyinstxtractor" rel="noopener noreferrer">PyInstaller Extractor (⭐2.6k)</a> -
A Python script to extract the contents of a PyInstaller generated Windows
executable file. The contents of the pyz file (usually pyc files) present
inside the executable are also extracted and automatically fixed so that a
Python bytecode decompiler will recognize it.</li>
</ul>

<ul>
<li><a href="https://github.com/rocky/python-uncompyle6/" rel="noopener noreferrer">uncompyle6 (⭐3.6k)</a> - A cross-version
Python bytecode decompiler.  Translates Python bytecode back into equivalent
Python source code.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://low-priority.appspot.com/ollydumpex/" rel="noopener noreferrer">OllyDumpEx</a> - Dump memory
from (unpacked) malware Windows process and store raw or rebuild PE file.
This is a plugin for OllyDbg, Immunity Debugger, IDA Pro, WinDbg, and x64dbg.</li>
</ul>

<ul>
<li><a href="https://github.com/NtQuery/Scylla" rel="noopener noreferrer">Scylla Imports Reconstructor (⭐1k)</a> - Find and fix
the IAT of an unpacked / dumped PE32 malware.</li>
</ul>

<ul>
<li><a href="https://github.com/x64dbg/ScyllaHide" rel="noopener noreferrer">ScyllaHide (⭐3.3k)</a> - An Anti-Anti-Debug library
and plugin for OllyDbg, x64dbg, IDA Pro, and TitanEngine.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/08/15/"/>
    <summary>7 awesome projects updated on Aug 15, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/08/13/</id>
    <title>Awesome Malware Analysis Updates on Aug 13, 2020</title>
    <updated>2020-08-13T14:39:20.000Z</updated>
    <published>2020-08-13T14:39:20.000Z</published>
    <content type="html"><![CDATA[<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://tsurugi-linux.org/" rel="noopener noreferrer">Tsurugi Linux</a> - Linux distribution designed to support your DFIR investigations, malware analysis and OSINT (Open Source INTelligence) activities.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/08/13/"/>
    <summary>1 awesome projects updated on Aug 13, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/07/17/</id>
    <title>Awesome Malware Analysis Updates on Jul 17, 2020</title>
    <updated>2020-07-17T22:05:52.000Z</updated>
    <published>2020-07-17T22:05:52.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/capa" rel="noopener noreferrer">capa (⭐4k)</a> - Detects capabilities in executable files.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/07/17/"/>
    <summary>1 awesome projects updated on Jul 17, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/06/21/</id>
    <title>Awesome Malware Analysis Updates on Jun 21, 2020</title>
    <updated>2020-06-21T17:13:55.000Z</updated>
    <published>2020-06-21T17:13:55.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://threatshare.io/" rel="noopener noreferrer">ThreatShare</a> - C2 panel tracker</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/06/21/"/>
    <summary>1 awesome projects updated on Jun 21, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/06/02/</id>
    <title>Awesome Malware Analysis Updates on Jun 02, 2020</title>
    <updated>2020-06-02T22:54:19.000Z</updated>
    <published>2020-06-02T22:54:19.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/season-lab/bluepill" rel="noopener noreferrer">BluePill (⭐118)</a> - Framework for executing and debugging evasive malware and protected executables.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/06/02/"/>
    <summary>1 awesome projects updated on Jun 02, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/04/01/</id>
    <title>Awesome Malware Analysis Updates on Apr 01, 2020</title>
    <updated>2020-04-01T12:43:13.000Z</updated>
    <published>2020-04-01T12:43:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Karneades/malware-persistence" rel="noopener noreferrer">Malware Persistence (⭐160)</a> - Collection
of various information focused on malware persistence: detection (techniques),
response, pitfalls and the log collection (tools).</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/04/01/"/>
    <summary>1 awesome projects updated on Apr 01, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2020/01/04/</id>
    <title>Awesome Malware Analysis Updates on Jan 04, 2020</title>
    <updated>2020-01-04T18:39:57.000Z</updated>
    <published>2020-01-04T18:39:57.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/guelfoweb/peframe" rel="noopener noreferrer">PEframe (⭐599)</a> - PEframe is an open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2020/01/04/"/>
    <summary>1 awesome projects updated on Jan 04, 2020</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/12/27/</id>
    <title>Awesome Malware Analysis Updates on Dec 27, 2019</title>
    <updated>2019-12-27T19:50:22.000Z</updated>
    <published>2019-12-27T19:50:22.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/pwnlandia/mhn" rel="noopener noreferrer">MHN (⭐2.4k)</a> - MHN is a centralized server for management and data collection of honeypots. MHN allows you to deploy sensors quickly and to collect data immediately, viewable from a neat web interface.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/12/27/"/>
    <summary>1 awesome projects updated on Dec 27, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/11/21/</id>
    <title>Awesome Malware Analysis Updates on Nov 21, 2019</title>
    <updated>2019-11-21T17:09:07.000Z</updated>
    <published>2019-11-21T17:09:07.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://spyse.com/" rel="noopener noreferrer">Spyse</a> - subdomains, whois, realted domains, DNS, hosts AS, SSL/TLS info,</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/11/21/"/>
    <summary>1 awesome projects updated on Nov 21, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/11/12/</id>
    <title>Awesome Malware Analysis Updates on Nov 12, 2019</title>
    <updated>2019-11-12T18:48:45.000Z</updated>
    <published>2019-11-12T18:48:45.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/stringsifter" rel="noopener noreferrer">StringSifter (⭐659)</a> - A machine learning tool
that automatically ranks strings based on their relevance for malware analysis.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/11/12/"/>
    <summary>1 awesome projects updated on Nov 12, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/11/11/</id>
    <title>Awesome Malware Analysis Updates on Nov 11, 2019</title>
    <updated>2019-11-11T01:08:47.000Z</updated>
    <published>2019-11-11T01:08:47.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://github.com/HynekPetrak/javascript-malware-collection" rel="noopener noreferrer">Javascript Mallware Collection (⭐653)</a> - Collection of almost 40.000 javascript malware samples</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/11/11/"/>
    <summary>1 awesome projects updated on Nov 11, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/11/02/</id>
    <title>Awesome Malware Analysis Updates on Nov 02, 2019</title>
    <updated>2019-11-02T01:39:33.000Z</updated>
    <published>2019-11-02T01:39:33.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/quark-engine/quark-engine" rel="noopener noreferrer">Quark-Engine (⭐1.3k)</a> - An Obfuscation-Neglect Android Malware Scoring System</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/11/02/"/>
    <summary>1 awesome projects updated on Nov 02, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/11/01/</id>
    <title>Awesome Malware Analysis Updates on Nov 01, 2019</title>
    <updated>2019-11-01T12:47:04.000Z</updated>
    <published>2019-11-01T12:47:04.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://labs.inquest.net" rel="noopener noreferrer">InQuest Labs</a> - Evergrowing searchable corpus of malicious Microsoft documents.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://labs.inquest.net/repdb" rel="noopener noreferrer">InQuest REPdb</a> - Continuous aggregation of IOCs from a variety of open reputation sources.</li>
</ul>

<ul>
<li><a href="https://labs.inquest.net/iocdb" rel="noopener noreferrer">InQuest IOCdb</a> - Continuous aggregation of IOCs from a variety of blogs, Github repos, and Twitter.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.abuseipdb.com/" rel="noopener noreferrer">AbuseIPDB</a> - AbuseIPDB is a project dedicated
to helping combat the spread of hackers, spammers, and abusive activity on the internet.</li>
</ul>
<h3><p>Documents and Shellcode / Other Resources</p>
</h3>
<ul>
<li><a href="https://labs.inquest.net/dfi" rel="noopener noreferrer">InQuest Deep File Inspection</a> - Upload common malware lures for Deep File Inspection and heuristical analysis.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/NationalSecurityAgency/ghidra" rel="noopener noreferrer">Ghidra (⭐49k)</a> - A software reverse engineering (SRE) framework created and       maintained by the National Security Agency Research Directorate.</li>
</ul>
<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.packtpub.com/networking-and-servers/mastering-malware-analysis" rel="noopener noreferrer">Mastering Malware Analysis</a> - Mastering Malware Analysis: The complete malware analyst's guide to combating malicious software, APT, cybercime, and IoT attacks</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/11/01/"/>
    <summary>7 awesome projects updated on Nov 01, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/10/31/</id>
    <title>Awesome Malware Analysis Updates on Oct 31, 2019</title>
    <updated>2019-10-31T11:55:25.000Z</updated>
    <published>2019-10-31T11:55:25.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/horsicq/Nauz-File-Detector" rel="noopener noreferrer">Nauz File Detector(NFD) (⭐497)</a> - Linker/Compiler/Tool detector  for Windows, Linux and MacOS.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/10/31/"/>
    <summary>1 awesome projects updated on Oct 31, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/10/15/</id>
    <title>Awesome Malware Analysis Updates on Oct 15, 2019</title>
    <updated>2019-10-15T20:04:51.000Z</updated>
    <published>2019-10-15T20:04:51.000Z</published>
    <content type="html"><![CDATA[<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.packtpub.com/networking-and-servers/learning-malware-analysis" rel="noopener noreferrer">Learning Malware Analysis</a> - Learning Malware Analysis: Explore the concepts, tools, and techniques to analuze and investigate Windows malware</li>
</ul>

<ul>
<li><a href="https://www.packtpub.com/networking-and-servers/mastering-reverse-engineering" rel="noopener noreferrer">Mastering Reverse Engineering</a> - Mastering Reverse Engineering: Re-engineer your ethical hacking skills</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/10/15/"/>
    <summary>2 awesome projects updated on Oct 15, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/10/12/</id>
    <title>Awesome Malware Analysis Updates on Oct 12, 2019</title>
    <updated>2019-10-12T10:47:39.000Z</updated>
    <published>2019-10-12T10:23:29.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://threatconnect.com/free/" rel="noopener noreferrer">ThreatConnect</a> - TC Open allows you to see and
share open source threat data, with support and validation from our free community.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://urlhaus.abuse.ch/" rel="noopener noreferrer">URLhaus</a> - A project from abuse.ch with the goal
of sharing malicious URLs that are being used for malware distribution.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/10/12/"/>
    <summary>2 awesome projects updated on Oct 12, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/09/19/</id>
    <title>Awesome Malware Analysis Updates on Sep 19, 2019</title>
    <updated>2019-09-19T04:11:22.000Z</updated>
    <published>2019-09-19T04:11:22.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/katjahahn/PortEx" rel="noopener noreferrer">PortEx (⭐494)</a> - Java library to analyse PE files with a special focus on malware analysis and PE malformation robustness.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/09/19/"/>
    <summary>1 awesome projects updated on Sep 19, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/09/04/</id>
    <title>Awesome Malware Analysis Updates on Sep 04, 2019</title>
    <updated>2019-09-04T05:46:46.000Z</updated>
    <published>2019-09-04T05:46:46.000Z</published>
    <content type="html"><![CDATA[<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/flare-fakenet-ng" rel="noopener noreferrer">FakeNet-NG (⭐1.7k)</a> - Next generation
dynamic network analysis tool.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/09/04/"/>
    <summary>1 awesome projects updated on Sep 04, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/08/19/</id>
    <title>Awesome Malware Analysis Updates on Aug 19, 2019</title>
    <updated>2019-08-19T19:39:37.000Z</updated>
    <published>2019-08-19T19:39:37.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/nbeede/BoomBox" rel="noopener noreferrer">BoomBox (⭐231)</a> - Automatic deployment of Cuckoo
Sandbox malware lab using Packer and Vagrant.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/08/19/"/>
    <summary>1 awesome projects updated on Aug 19, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/07/17/</id>
    <title>Awesome Malware Analysis Updates on Jul 17, 2019</title>
    <updated>2019-07-17T06:43:25.000Z</updated>
    <published>2019-07-17T06:43:25.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://malwareanalyser.io/" rel="noopener noreferrer">MalwareAnalyser.io</a> - Online malware anomaly-based static analyser with heuristic detection engine powered by data mining and machine learning.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/07/17/"/>
    <summary>1 awesome projects updated on Jul 17, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/06/12/</id>
    <title>Awesome Malware Analysis Updates on Jun 12, 2019</title>
    <updated>2019-06-12T10:13:31.000Z</updated>
    <published>2019-06-12T10:13:31.000Z</published>
    <content type="html"><![CDATA[<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/idaholab/Malcolm" rel="noopener noreferrer">Malcolm (⭐327)</a> - Malcolm is a powerful, easily
deployable network traffic analysis tool suite for full packet capture artifacts
(PCAP files) and Zeek logs.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/06/12/"/>
    <summary>1 awesome projects updated on Jun 12, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/05/04/</id>
    <title>Awesome Malware Analysis Updates on May 04, 2019</title>
    <updated>2019-05-04T18:31:13.000Z</updated>
    <published>2019-05-04T18:31:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.amazon.com/dp/1593277164" rel="noopener noreferrer">Rootkits and Bootkits</a> - Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/05/04/"/>
    <summary>1 awesome projects updated on May 04, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/03/13/</id>
    <title>Awesome Malware Analysis Updates on Mar 13, 2019</title>
    <updated>2019-03-13T17:13:47.000Z</updated>
    <published>2019-03-13T17:13:47.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/InQuest/ThreatIngestor/" rel="noopener noreferrer">ThreatIngestor (⭐801)</a> - Build
automated threat intel pipelines sourcing from Twitter, RSS, GitHub, and
more.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/03/13/"/>
    <summary>1 awesome projects updated on Mar 13, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/03/06/</id>
    <title>Awesome Malware Analysis Updates on Mar 06, 2019</title>
    <updated>2019-03-06T09:05:59.000Z</updated>
    <published>2019-03-06T09:05:59.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/micheloosterhof/cowrie" rel="noopener noreferrer">Cowrie (⭐5k)</a> - SSH honeypot, based
on Kippo.</li>
</ul>

<ul>
<li><a href="https://github.com/RevengeComing/DemonHunter" rel="noopener noreferrer">DemoHunter (⭐58)</a> - Low interaction Distributed Honeypots.</li>
</ul>

<ul>
<li><a href="https://github.com/DinoTools/dionaea" rel="noopener noreferrer">Dionaea (⭐688)</a> - Honeypot designed to trap malware.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.systemlookup.com/" rel="noopener noreferrer">SystemLookup</a> - SystemLookup hosts a collection of lists that provide information on
the components of legitimate and potentially unwanted programs.</li>
</ul>

<ul>
<li><a href="https://github.com/yeti-platform/yeti" rel="noopener noreferrer">YETI (⭐1.7k)</a> - Yeti is a platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://packettotal.com/" rel="noopener noreferrer">PacketTotal</a> - PacketTotal is an online engine for analyzing .pcap files, and visualizing the network traffic within.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/endgameinc/ember" rel="noopener noreferrer">Ember (⭐905)</a> - Endgame Malware BEnchmark for Research,
a repository that makes it easy to (re)create a machine learning model that can be used
to predict a score for a PE file based on static analysis.</li>
</ul>

<ul>
<li><a href="https://addons.mozilla.org/fr/firefox/addon/malware-search-plusplusplus/" rel="noopener noreferrer">Malware Search+++</a> Firefox extension allows
you to easily search some of the most popular malware databases</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/03/06/"/>
    <summary>8 awesome projects updated on Mar 06, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/02/16/</id>
    <title>Awesome Malware Analysis Updates on Feb 16, 2019</title>
    <updated>2019-02-16T01:41:41.000Z</updated>
    <published>2019-02-16T01:41:41.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.slideshare.net/bartblaze/malware-analysis-threat-intelligence-and-reverse-engineering" rel="noopener noreferrer">Malware Analysis, Threat Intelligence and Reverse Engineering</a> -
Presentation introducing the concepts of malware analysis, threat intelligence
and reverse engineering. Experience or prior knowledge is not required. Labs
link in description.</li>
</ul>

<ul>
<li><a href="https://github.com/msuhanov/regf/blob/master/Windows%20registry%20file%20format%20specification.md" rel="noopener noreferrer">Windows Registry specification (⭐312)</a> -
Windows registry file format specification.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/02/16/"/>
    <summary>2 awesome projects updated on Feb 16, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/02/14/</id>
    <title>Awesome Malware Analysis Updates on Feb 14, 2019</title>
    <updated>2019-02-14T13:52:48.000Z</updated>
    <published>2019-02-14T13:52:48.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://securitytrails.com/" rel="noopener noreferrer">SecurityTrails</a> - Historical and current WHOIS,
historical and current DNS records, similar domains, certificate information
and other domain and IP related API and tools.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/02/14/"/>
    <summary>1 awesome projects updated on Feb 14, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/02/12/</id>
    <title>Awesome Malware Analysis Updates on Feb 12, 2019</title>
    <updated>2019-02-12T15:14:43.000Z</updated>
    <published>2019-02-12T15:14:43.000Z</published>
    <content type="html"><![CDATA[<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/unipacker/unipacker" rel="noopener noreferrer">un{i}packer (⭐623)</a> - Automatic and
platform-independent unpacker for Windows binaries based on emulation.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/02/12/"/>
    <summary>1 awesome projects updated on Feb 12, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/02/08/</id>
    <title>Awesome Malware Analysis Updates on Feb 08, 2019</title>
    <updated>2019-02-08T12:52:55.000Z</updated>
    <published>2019-02-08T12:52:55.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://metadefender.opswat.com/" rel="noopener noreferrer">MetaDefender Cloud</a> - Scan a file, hash, IP, URL or
domain address for malware for free.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/02/08/"/>
    <summary>1 awesome projects updated on Feb 08, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2019/01/02/</id>
    <title>Awesome Malware Analysis Updates on Jan 02, 2019</title>
    <updated>2019-01-02T17:24:16.000Z</updated>
    <published>2019-01-02T17:24:16.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/crypto2011/IDR" rel="noopener noreferrer">IDR (⭐916)</a> - Interactive Delphi Reconstructor
is a decompiler of Delphi executable files and dynamic libraries.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2019/01/02/"/>
    <summary>1 awesome projects updated on Jan 02, 2019</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/12/27/</id>
    <title>Awesome Malware Analysis Updates on Dec 27, 2018</title>
    <updated>2018-12-27T15:53:59.000Z</updated>
    <published>2018-12-27T15:53:59.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.opswat.com/developers/threat-intelligence-feed" rel="noopener noreferrer">MetaDefender Threat Intelligence Feed</a> -
List of the most looked up file hashes from MetaDefender Cloud.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/12/27/"/>
    <summary>1 awesome projects updated on Dec 27, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/11/15/</id>
    <title>Awesome Malware Analysis Updates on Nov 15, 2018</title>
    <updated>2018-11-15T11:31:07.000Z</updated>
    <published>2018-11-15T11:31:07.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://riskdiscovery.com/honeydb" rel="noopener noreferrer">HoneyDB</a> - Community driven honeypot sensor data collection and aggregation.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/11/15/"/>
    <summary>1 awesome projects updated on Nov 15, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/10/06/</id>
    <title>Awesome Malware Analysis Updates on Oct 06, 2018</title>
    <updated>2018-10-06T18:02:02.000Z</updated>
    <published>2018-10-06T10:44:00.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/phdphuc/mac-a-mal" rel="noopener noreferrer">mac-a-mal (⭐82)</a> - An automated framework
for mac malware hunting.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/AbertayMachineLearningGroup/CryptoKnight" rel="noopener noreferrer">CryptoKnight (⭐38)</a> - Automated cryptographic algorithm reverse engineering and classification framework.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/10/06/"/>
    <summary>2 awesome projects updated on Oct 06, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/10/05/</id>
    <title>Awesome Malware Analysis Updates on Oct 05, 2018</title>
    <updated>2018-10-05T19:52:51.000Z</updated>
    <published>2018-10-05T19:52:51.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://phishstats.info/" rel="noopener noreferrer">PhishStats</a> - Phishing Statistics with search for
IP, domain and website title</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/10/05/"/>
    <summary>1 awesome projects updated on Oct 05, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/10/02/</id>
    <title>Awesome Malware Analysis Updates on Oct 02, 2018</title>
    <updated>2018-10-02T22:02:07.000Z</updated>
    <published>2018-10-02T22:02:07.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://malpedia.caad.fkie.fraunhofer.de/" rel="noopener noreferrer">Malpedia</a> - A resource providing
rapid identification and actionable context for malware investigations.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/10/02/"/>
    <summary>1 awesome projects updated on Oct 02, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/09/01/</id>
    <title>Awesome Malware Analysis Updates on Sep 01, 2018</title>
    <updated>2018-09-01T09:42:31.000Z</updated>
    <published>2018-09-01T09:42:31.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/radareorg/cutter" rel="noopener noreferrer">Cutter</a> - GUI for Radare2.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/09/01/"/>
    <summary>1 awesome projects updated on Sep 01, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/08/22/</id>
    <title>Awesome Malware Analysis Updates on Aug 22, 2018</title>
    <updated>2018-08-22T12:49:00.000Z</updated>
    <published>2018-08-22T12:49:00.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/uppusaikiran/yara-finder" rel="noopener noreferrer">Yara Finder (⭐0)</a> - A simple tool to yara match the file against various yara rules to find the indicators of suspicion.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/08/22/"/>
    <summary>1 awesome projects updated on Aug 22, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/08/13/</id>
    <title>Awesome Malware Analysis Updates on Aug 13, 2018</title>
    <updated>2018-08-13T21:26:28.000Z</updated>
    <published>2018-08-13T21:26:28.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/maliceio/malice" rel="noopener noreferrer">malice.io (⭐1.6k)</a> - Massively scalable malware analysis framework.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/08/13/"/>
    <summary>1 awesome projects updated on Aug 13, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/07/10/</id>
    <title>Awesome Malware Analysis Updates on Jul 10, 2018</title>
    <updated>2018-07-10T05:10:37.000Z</updated>
    <published>2018-07-10T05:10:37.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://beta.virusbay.io/" rel="noopener noreferrer">VirusBay</a> - Community-Based malware repository and social network.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/07/10/"/>
    <summary>1 awesome projects updated on Jul 10, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/07/09/</id>
    <title>Awesome Malware Analysis Updates on Jul 09, 2018</title>
    <updated>2018-07-09T15:10:26.000Z</updated>
    <published>2018-07-09T15:10:26.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/uppusaikiran/generic-parser" rel="noopener noreferrer">Generic File Parser (⭐0)</a> - A Single Library Parser to extract meta information,static analysis and detect macros within the files.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/07/09/"/>
    <summary>1 awesome projects updated on Jul 09, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/06/09/</id>
    <title>Awesome Malware Analysis Updates on Jun 09, 2018</title>
    <updated>2018-06-09T17:51:42.000Z</updated>
    <published>2018-06-09T17:51:10.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="http://exeinfo.pe.hu/" rel="noopener noreferrer">Exeinfo PE</a> - Packer, compressor detector, unpack
info, internal exe tools.</li>
</ul>

<ul>
<li><a href="https://hshrzd.wordpress.com/pe-bear/" rel="noopener noreferrer">PE-bear</a> - Reversing tool for PE
files.</li>
</ul>
<h3><p>Browser Malware / Other Resources</p>
</h3>
<ul>
<li><a href="https://labs.adobe.com/technologies/swfinvestigator/" rel="noopener noreferrer">SWF Investigator</a> -
Static and dynamic analysis of SWF applications.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.jetbrains.com/decompiler/" rel="noopener noreferrer">dotPeek</a> - Free .NET Decompiler and
Assembly Browser.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/06/09/"/>
    <summary>4 awesome projects updated on Jun 09, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/06/02/</id>
    <title>Awesome Malware Analysis Updates on Jun 02, 2018</title>
    <updated>2018-06-02T13:40:01.000Z</updated>
    <published>2018-06-02T13:40:01.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/gurnec/HashCheck" rel="noopener noreferrer">HashCheck (⭐1.7k)</a> - Windows shell extension
to compute hashes with a variety of algorithms.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/06/02/"/>
    <summary>1 awesome projects updated on Jun 02, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/05/09/</id>
    <title>Awesome Malware Analysis Updates on May 09, 2018</title>
    <updated>2018-05-09T01:42:21.000Z</updated>
    <published>2018-05-09T01:42:21.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/silascutler/MalPipe" rel="noopener noreferrer">MalPipe (⭐102)</a> - Malware/IOC ingestion and
processing engine, that enriches collected data.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/05/09/"/>
    <summary>1 awesome projects updated on May 09, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/04/25/</id>
    <title>Awesome Malware Analysis Updates on Apr 25, 2018</title>
    <updated>2018-04-25T23:10:36.000Z</updated>
    <published>2018-04-25T23:10:36.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://app.any.run/" rel="noopener noreferrer">any.run</a> - Online interactive sandbox.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/04/25/"/>
    <summary>1 awesome projects updated on Apr 25, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/04/20/</id>
    <title>Awesome Malware Analysis Updates on Apr 20, 2018</title>
    <updated>2018-04-20T17:46:04.000Z</updated>
    <published>2018-04-20T17:46:04.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/InQuest/python-iocextract" rel="noopener noreferrer">iocextract (⭐495)</a> - Advanced Indicator
of Compromise (IOC) extractor, Python library and command-line tool.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/04/20/"/>
    <summary>1 awesome projects updated on Apr 20, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/04/04/</id>
    <title>Awesome Malware Analysis Updates on Apr 04, 2018</title>
    <updated>2018-04-04T21:17:57.000Z</updated>
    <published>2018-04-04T21:17:57.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://urlscan.io/" rel="noopener noreferrer">urlscan.io</a> - Free URL Scanner &amp; domain information.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/04/04/"/>
    <summary>1 awesome projects updated on Apr 04, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/03/16/</id>
    <title>Awesome Malware Analysis Updates on Mar 16, 2018</title>
    <updated>2018-03-16T02:52:13.000Z</updated>
    <published>2018-03-16T02:52:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/honeytrap/honeytrap" rel="noopener noreferrer">Honeytrap (⭐1.2k)</a> - Opensource system for running, monitoring and managing honeypots.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/03/16/"/>
    <summary>1 awesome projects updated on Mar 16, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/03/14/</id>
    <title>Awesome Malware Analysis Updates on Mar 14, 2018</title>
    <updated>2018-03-14T01:19:33.000Z</updated>
    <published>2018-03-14T01:17:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://github.com/vduddu/Malware" rel="noopener noreferrer">vduddu malware repo</a> - Collection of
various malware files and source code.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/InQuest/python-sandboxapi" rel="noopener noreferrer">sandboxapi (⭐132)</a> - Python library for
building integrations with several open source and commercial malware sandboxes.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/03/14/"/>
    <summary>2 awesome projects updated on Mar 14, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/03/13/</id>
    <title>Awesome Malware Analysis Updates on Mar 13, 2018</title>
    <updated>2018-03-13T12:25:14.000Z</updated>
    <published>2018-03-13T12:25:14.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/JusticeRage/Manalyze" rel="noopener noreferrer">Manalyze (⭐997)</a> - Static analyzer for PE
executables.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/03/13/"/>
    <summary>1 awesome projects updated on Mar 13, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2018/03/12/</id>
    <title>Awesome Malware Analysis Updates on Mar 12, 2018</title>
    <updated>2018-03-12T10:51:26.000Z</updated>
    <published>2018-03-12T10:51:26.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://infosec.cert-pa.it/analyze/submission.html" rel="noopener noreferrer">Infosec - CERT-PA</a> - Malware samples collection and analysis.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://infosec.cert-pa.it/analyze/statistics.html" rel="noopener noreferrer">Infosec - CERT-PA lists</a> (<a href="https://infosec.cert-pa.it/analyze/listip.txt" rel="noopener noreferrer">IPs</a> - <a href="https://infosec.cert-pa.it/analyze/listdomains.txt" rel="noopener noreferrer">Domains</a> - <a href="https://infosec.cert-pa.it/analyze/listurls.txt" rel="noopener noreferrer">URLs</a>) - Blocklist service.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2018/03/12/"/>
    <summary>2 awesome projects updated on Mar 12, 2018</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/11/28/</id>
    <title>Awesome Malware Analysis Updates on Nov 28, 2017</title>
    <updated>2017-11-28T20:13:17.000Z</updated>
    <published>2017-11-28T19:34:34.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.fireeye.com/services/freeware.html" rel="noopener noreferrer">OpenIOC</a> - Framework for sharing threat intelligence.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://malware.sekoia.fr/" rel="noopener noreferrer">SEKOIA Dropper Analysis</a> - Online dropper analysis (Js, VBScript, Microsoft Office, PDF).</li>
</ul>
<h3><p>File Carving / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/vstinner/hachoir3" rel="noopener noreferrer">hachoir3 (⭐593)</a> - Hachoir is a Python library
to view and edit a binary stream field by field.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/uppusaikiran/malware-organiser" rel="noopener noreferrer">Malware Organiser (⭐0)</a> - A simple tool to organise large malicious/benign files into a organised Structure.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/11/28/"/>
    <summary>4 awesome projects updated on Nov 28, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/11/16/</id>
    <title>Awesome Malware Analysis Updates on Nov 16, 2017</title>
    <updated>2017-11-16T22:27:23.000Z</updated>
    <published>2017-11-16T22:27:23.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://analyze.intezer.com" rel="noopener noreferrer">Intezer</a> - Detect, analyze, and categorize malware by
identifying code reuse and code similarities.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/11/16/"/>
    <summary>1 awesome projects updated on Nov 16, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/11/02/</id>
    <title>Awesome Malware Analysis Updates on Nov 02, 2017</title>
    <updated>2017-11-02T22:26:53.000Z</updated>
    <published>2017-11-02T22:26:53.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/cmu-sei/pharos" rel="noopener noreferrer">Pharos (⭐1.5k)</a> - The Pharos binary analysis framework
can be used to perform automated static analysis of binaries.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/11/02/"/>
    <summary>1 awesome projects updated on Nov 02, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/10/22/</id>
    <title>Awesome Malware Analysis Updates on Oct 22, 2017</title>
    <updated>2017-10-22T20:42:37.000Z</updated>
    <published>2017-10-22T20:42:37.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://pulsedive.com" rel="noopener noreferrer">Pulsedive</a> - Free, community-driven threat intelligence platform collecting IOCs from open-source feeds.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/10/22/"/>
    <summary>1 awesome projects updated on Oct 22, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/10/18/</id>
    <title>Awesome Malware Analysis Updates on Oct 18, 2017</title>
    <updated>2017-10-18T03:16:18.000Z</updated>
    <published>2017-10-18T03:16:18.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.hopperapp.com/" rel="noopener noreferrer">Hopper</a> - The macOS and Linux Disassembler.</li>
</ul>

<ul>
<li><a href="http://ilspy.net/" rel="noopener noreferrer">ILSpy</a> - ILSpy is the open-source .NET assembly browser and decompiler.</li>
</ul>

<ul>
<li><a href="https://developer.microsoft.com/en-us/windows/hardware/download-windbg" rel="noopener noreferrer">WinDbg</a> - multipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/10/18/"/>
    <summary>3 awesome projects updated on Oct 18, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/10/17/</id>
    <title>Awesome Malware Analysis Updates on Oct 17, 2017</title>
    <updated>2017-10-17T19:57:19.000Z</updated>
    <published>2017-10-17T19:57:19.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/InQuest/awesome-yara" rel="noopener noreferrer">YARA (⭐3.4k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/10/17/"/>
    <summary>1 awesome projects updated on Oct 17, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/10/07/</id>
    <title>Awesome Malware Analysis Updates on Oct 07, 2017</title>
    <updated>2017-10-07T03:04:03.000Z</updated>
    <published>2017-10-07T03:04:03.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hugsy/codebro" rel="noopener noreferrer">codebro (⭐42)</a> - Web based code browser using
 clang to provide basic code analysis.</li>
</ul>

<ul>
<li><a href="https://github.com/sycurelab/DECAF" rel="noopener noreferrer">DECAF (Dynamic Executable Code Analysis Framework) (⭐794)</a>
- A binary analysis platform based   on QEMU. DroidScope is now an extension to DECAF.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/10/07/"/>
    <summary>2 awesome projects updated on Oct 07, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/09/25/</id>
    <title>Awesome Malware Analysis Updates on Sep 25, 2017</title>
    <updated>2017-09-25T07:18:26.000Z</updated>
    <published>2017-09-25T00:14:52.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/csirtgadgets/massive-octo-spice" rel="noopener noreferrer">Massive Octo Spice (⭐228)</a> -
Previously known as CIF (Collective Intelligence Framework). Aggregates IOCs
from various lists. Curated by the
<a href="http://csirtgadgets.org/collective-intelligence-framework" rel="noopener noreferrer">CSIRT Gadgets Foundation</a>.</li>
</ul>

<ul>
<li><a href="https://community.riskiq.com/" rel="noopener noreferrer">RiskIQ</a> - Research, connect, tag and
share IPs and domains. (Was PassiveTotal.)</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.threatminer.org/" rel="noopener noreferrer">ThreatMiner</a> - Data mining portal for threat
intelligence, with search.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/airbnb/binaryalert" rel="noopener noreferrer">BinaryAlert (⭐1.4k)</a> - An open source, serverless
AWS pipeline that scans and alerts on uploaded files based on a set of
YARA rules.</li>
</ul>

<ul>
<li><a href="https://ssdeep-project.github.io/ssdeep/" rel="noopener noreferrer">ssdeep</a> - Compute fuzzy hashes.</li>
</ul>

<ul>
<li><a href="https://gist.github.com/gleblanc1783/3c8e6b379fa9d646d401b96ab5c7877f" rel="noopener noreferrer">totalhash.py</a> -
Python script for easy searching of the <a href="https://totalhash.cymru.com/" rel="noopener noreferrer">TotalHash.cymru.com</a>
database.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://sandbox.anlyz.io/" rel="noopener noreferrer">anlyz.io</a> - Online sandbox.</li>
</ul>

<ul>
<li><a href="https://github.com/keithjjones/cuckoo-modified-api" rel="noopener noreferrer">cuckoo-modified-api (⭐19)</a> - A
Python API used to control a cuckoo-modified sandbox.</li>
</ul>

<ul>
<li><a href="https://github.com/detuxsandbox/detux/" rel="noopener noreferrer">detux (⭐257)</a> - A sandbox developed to do
traffic analysis of Linux malwares and capturing IOCs.</li>
</ul>

<ul>
<li><a href="http://firmware.re/" rel="noopener noreferrer">firmware.re</a> - Unpacks, scans and analyzes almost any
firmware package.</li>
</ul>

<ul>
<li><a href="https://github.com/Tencent/HaboMalHunter" rel="noopener noreferrer">HaboMalHunter (⭐725)</a> - An Automated Malware
Analysis Tool for Linux ELF Files.</li>
</ul>

<ul>
<li><a href="https://github.com/monnappa22/Limon" rel="noopener noreferrer">Limon (⭐384)</a> - Sandbox for Analyzing Linux Malware.</li>
</ul>

<ul>
<li><a href="https://github.com/diogo-fernan/malsub" rel="noopener noreferrer">malsub (⭐363)</a> - A Python RESTful API framework for
online malware and URL analysis services.</li>
</ul>

<ul>
<li><a href="https://github.com/keithjjones/visualize_logs" rel="noopener noreferrer">Visualize_Logs (⭐136)</a> - Open source
visualization library and command line tools for logs.  (Cuckoo, Procmon, more
to come...)</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.badips.com/" rel="noopener noreferrer">badips.com</a> - Community based IP blacklist service.</li>
</ul>

<ul>
<li><a href="https://github.com/EmersonElectricCo/boomerang" rel="noopener noreferrer">boomerang (⭐34)</a> - A tool designed
for consistent and safe capture of off network web resources.</li>
</ul>

<ul>
<li><a href="https://cymon.io/" rel="noopener noreferrer">Cymon</a> - Threat intelligence tracker, with IP/domain/hash
search.</li>
</ul>

<ul>
<li><a href="https://talosintelligence.com/" rel="noopener noreferrer">Talos Intelligence</a> - Search for IP, domain
or network owner. (Previously SenderBase.)</li>
</ul>

<ul>
<li><a href="https://zulu.zscaler.com/#" rel="noopener noreferrer">ZScalar Zulu</a> - Zulu URL Risk Analyzer.</li>
</ul>
<h3><p>Browser Malware / Other Resources</p>
</h3>
<ul>
<li><a href="https://getfirebug.com/" rel="noopener noreferrer">Firebug</a> - Firefox extension for web development.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://binary.ninja/" rel="noopener noreferrer">Binary ninja</a> - A reversing engineering platform
that is an alternative to IDA.</li>
</ul>

<ul>
<li><a href="https://github.com/moyix/panda" rel="noopener noreferrer">PANDA (⭐102)</a> - Platform for Architecture-Neutral
Dynamic Analysis.</li>
</ul>

<ul>
<li><a href="https://github.com/plasma-disassembler/plasma" rel="noopener noreferrer">plasma (⭐3k)</a> - Interactive
disassembler for x86/ARM/MIPS.</li>
</ul>

<ul>
<li><a href="http://processhacker.sourceforge.net/" rel="noopener noreferrer">Process Hacker</a> - Tool that monitors
system resources.</li>
</ul>

<ul>
<li><a href="https://github.com/Cisco-Talos/pyrebox" rel="noopener noreferrer">PyREBox (⭐1.6k)</a> - Python scriptable reverse
engineering sandbox by the Talos team at Cisco.</li>
</ul>

<ul>
<li><a href="https://github.com/ispras/qemu/releases/" rel="noopener noreferrer">QKD (⭐50)</a> - QEMU with embedded WinDbg
server for stealth debugging.</li>
</ul>

<ul>
<li><a href="https://sourceforge.net/projects/regshot/" rel="noopener noreferrer">RegShot</a> - Registry compare utility
that compares snapshots.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/mateuszk87/PcapViz" rel="noopener noreferrer">PcapViz (⭐328)</a> - Network topology and
traffic visualizer.</li>
</ul>

<ul>
<li><a href="https://github.com/RamadhanAmizudin/python-icap-yara" rel="noopener noreferrer">Python ICAP Yara (⭐56)</a> - An
ICAP Server with yara scanner for URL or content.</li>
</ul>

<ul>
<li><a href="https://github.com/ch3k1/squidmagic" rel="noopener noreferrer">Squidmagic (⭐75)</a> - squidmagic is a tool
designed to analyze a web-based network traffic to detect central command
and control (C&amp;C) servers and malicious sites, using Squid proxy server and
Spamhaus.</li>
</ul>
<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.blackbagtech.com/blacklight.html" rel="noopener noreferrer">BlackLight</a> - Windows/MacOS
forensics client supporting hiberfil, pagefile, raw memory analysis.</li>
</ul>

<ul>
<li><a href="https://github.com/504ensicsLabs/DAMM" rel="noopener noreferrer">DAMM (⭐209)</a> - Differential Analysis of
Malware in Memory, built on Volatility.</li>
</ul>

<ul>
<li><a href="https://github.com/ShaneK2/inVtero.net" rel="noopener noreferrer">inVtero.net (⭐276)</a> - High speed memory
analysis framework developed in .NET supports all Windows x64, includes
code integrity and write support.</li>
</ul>
<h3><p>Storage and Workflow / Other Resources</p>
</h3>
<ul>
<li><a href="https://certsocietegenerale.github.io/fame/" rel="noopener noreferrer">FAME</a> - A malware analysis
framework featuring a pipeline that can be extended with custom modules,
which can be chained and interact with each other to perform end-to-end
analysis.</li>
</ul>
<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://amzn.com/dp/1593272901" rel="noopener noreferrer">Practical Malware Analysis</a> - The Hands-On
Guide to Dissecting Malicious Software.</li>
</ul>

<ul>
<li><a href="https://www.amzn.com/dp/1118787315/" rel="noopener noreferrer">Practical Reverse Engineering</a> -
Intermediate Reverse Engineering.</li>
</ul>

<ul>
<li><a href="https://www.amzn.com/dp/0321240693" rel="noopener noreferrer">Real Digital Forensics</a> - Computer
Security and Incident Response.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.kernelmode.info/forum/" rel="noopener noreferrer">Kernel Mode</a> - An active community
devoted to malware analysis and kernel development.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/09/25/"/>
    <summary>38 awesome projects updated on Sep 25, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/08/10/</id>
    <title>Awesome Malware Analysis Updates on Aug 10, 2017</title>
    <updated>2017-08-10T00:12:16.000Z</updated>
    <published>2017-08-10T00:12:16.000Z</published>
    <content type="html"><![CDATA[<h3><p>File Carving / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/jbremer/sflock" rel="noopener noreferrer">SFlock (⭐81)</a> - Nested archive
extraction/unpacking (used in Cuckoo Sandbox).</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/jbremer/httpreplay" rel="noopener noreferrer">HTTPReplay (⭐94)</a> - Library for parsing
and reading out PCAP files, including TLS streams using TLS Master Secrets
(used in Cuckoo Sandbox).</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/08/10/"/>
    <summary>2 awesome projects updated on Aug 10, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/07/28/</id>
    <title>Awesome Malware Analysis Updates on Jul 28, 2017</title>
    <updated>2017-07-28T09:49:22.000Z</updated>
    <published>2017-07-28T09:49:22.000Z</published>
    <content type="html"><![CDATA[<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/flare-vm" rel="noopener noreferrer">FLARE VM (⭐6.1k)</a> - A fully customizable,
Windows-based, security distribution for malware analysis.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/07/28/"/>
    <summary>1 awesome projects updated on Jul 28, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/07/26/</id>
    <title>Awesome Malware Analysis Updates on Jul 26, 2017</title>
    <updated>2017-07-26T06:08:59.000Z</updated>
    <published>2017-07-26T06:08:59.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://services.normshield.com/" rel="noopener noreferrer">NormShield Services</a> - Free API Services
for detecting possible phishing domains, blacklisted ip addresses and breached
accounts.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/07/26/"/>
    <summary>1 awesome projects updated on Jul 26, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/04/08/</id>
    <title>Awesome Malware Analysis Updates on Apr 08, 2017</title>
    <updated>2017-04-08T13:09:37.000Z</updated>
    <published>2017-04-08T12:53:52.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/devttys0/binwalk" rel="noopener noreferrer">Binwalk (⭐10k)</a> - Firmware analysis tool.</li>
</ul>

<ul>
<li><a href="https://lief.quarkslab.com/" rel="noopener noreferrer">LIEF</a> - LIEF provides a cross-platform library
to parse, modify and abstract ELF, PE and MachO formats.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/04/08/"/>
    <summary>2 awesome projects updated on Apr 08, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/03/26/</id>
    <title>Awesome Malware Analysis Updates on Mar 26, 2017</title>
    <updated>2017-03-26T20:57:01.000Z</updated>
    <published>2017-03-26T20:57:01.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://triton.quarkslab.com/" rel="noopener noreferrer">Triton</a> - A dynamic binary analysis (DBA) framework.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/03/26/"/>
    <summary>1 awesome projects updated on Mar 26, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/03/23/</id>
    <title>Awesome Malware Analysis Updates on Mar 23, 2017</title>
    <updated>2017-03-23T10:51:50.000Z</updated>
    <published>2017-03-23T10:51:50.000Z</published>
    <content type="html"><![CDATA[<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/swwwolf/wdbgark" rel="noopener noreferrer">WDBGARK (⭐610)</a> -
WinDBG Anti-RootKit Extension.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/03/23/"/>
    <summary>1 awesome projects updated on Mar 23, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/03/03/</id>
    <title>Awesome Malware Analysis Updates on Mar 03, 2017</title>
    <updated>2017-03-03T19:28:49.000Z</updated>
    <published>2017-03-03T19:28:49.000Z</published>
    <content type="html"><![CDATA[<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.cloudshark.org" rel="noopener noreferrer">CloudShark</a> - Web-based tool for packet analysis
and malware traffic detection.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/03/03/"/>
    <summary>1 awesome projects updated on Mar 03, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2017/02/16/</id>
    <title>Awesome Malware Analysis Updates on Feb 16, 2017</title>
    <updated>2017-02-16T08:06:17.000Z</updated>
    <published>2017-02-16T08:06:17.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="http://kaitai.io/" rel="noopener noreferrer">Kaitai Struct</a> - DSL for file formats / network protocols /
data structures reverse engineering and dissection, with code generation
for C++, C#, Java, JavaScript, Perl, PHP, Python, Ruby.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2017/02/16/"/>
    <summary>1 awesome projects updated on Feb 16, 2017</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/12/16/</id>
    <title>Awesome Malware Analysis Updates on Dec 16, 2016</title>
    <updated>2016-12-16T00:23:58.000Z</updated>
    <published>2016-12-16T00:04:24.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="http://tracker.h3x.eu/" rel="noopener noreferrer">Tracker h3x</a> - Agregator for malware corpus tracker
and malicious download sites.</li>
</ul>

<ul>
<li><a href="http://vxvault.net" rel="noopener noreferrer">VX Vault</a> - Active collection of malware samples.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="http://cybercrime-tracker.net/" rel="noopener noreferrer">Cybercrime tracker</a> - Multiple botnet active tracker.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://malwareconfig.com/" rel="noopener noreferrer">Malware config</a> - Extract, decode and display online
the configuration settings from common malwares.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="http://multirbl.valli.org/" rel="noopener noreferrer">Multi rbl</a> - Multiple DNS blacklist and forward
confirmed reverse DNS lookup over more than 300 RBLs.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/12/16/"/>
    <summary>5 awesome projects updated on Dec 16, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/12/15/</id>
    <title>Awesome Malware Analysis Updates on Dec 15, 2016</title>
    <updated>2016-12-15T23:58:20.000Z</updated>
    <published>2016-12-15T23:42:51.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml" rel="noopener noreferrer">Ransomware overview</a> -
A list of ransomware overview with details, detection and prevention.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://archive.org/details/malwaremuseum" rel="noopener noreferrer">Malware Museum</a> - Collection of
malware programs that were distributed in the 1980s and 1990s.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/12/15/"/>
    <summary>2 awesome projects updated on Dec 15, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/12/07/</id>
    <title>Awesome Malware Analysis Updates on Dec 07, 2016</title>
    <updated>2016-12-07T12:33:20.000Z</updated>
    <published>2016-12-07T12:33:20.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Cugu/awesome-forensics" rel="noopener noreferrer">Forensics (⭐3.7k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/12/07/"/>
    <summary>1 awesome projects updated on Dec 07, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/11/25/</id>
    <title>Awesome Malware Analysis Updates on Nov 25, 2016</title>
    <updated>2016-11-25T04:55:28.000Z</updated>
    <published>2016-11-25T04:55:28.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/EmersonElectricCo/fsf" rel="noopener noreferrer">File Scanning Framework (⭐283)</a> -
Modular, recursive file scanning solution.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/11/25/"/>
    <summary>1 awesome projects updated on Nov 25, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/11/20/</id>
    <title>Awesome Malware Analysis Updates on Nov 20, 2016</title>
    <updated>2016-11-20T15:38:27.000Z</updated>
    <published>2016-11-20T15:38:27.000Z</published>
    <content type="html"><![CDATA[<h3><p>Storage and Workflow / Other Resources</p>
</h3>
<ul>
<li><a href="http://stoq.punchcyber.com" rel="noopener noreferrer">stoQ</a> - Distributed content analysis
framework with extensive plugin support, from input to output, and everything
in between.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/11/20/"/>
    <summary>1 awesome projects updated on Nov 20, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/11/14/</id>
    <title>Awesome Malware Analysis Updates on Nov 14, 2016</title>
    <updated>2016-11-14T11:25:41.000Z</updated>
    <published>2016-11-14T11:25:41.000Z</published>
    <content type="html"><![CDATA[<h3><p>Documents and Shellcode / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/CapacitorSet/box-js" rel="noopener noreferrer">box-js (⭐606)</a> - A tool for studying JavaScript
malware, featuring JScript/WScript support and ActiveX emulation.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/11/14/"/>
    <summary>1 awesome projects updated on Nov 14, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/11/13/</id>
    <title>Awesome Malware Analysis Updates on Nov 13, 2016</title>
    <updated>2016-11-13T20:21:25.000Z</updated>
    <published>2016-11-13T19:47:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/BinaryAnalysisPlatform/bap" rel="noopener noreferrer">BAP (⭐2k)</a> - Multiplatform and
open source (MIT) binary analysis framework developed at CMU's Cylab.</li>
</ul>

<ul>
<li><a href="https://www.mcafee.com/us/downloads/free-tools/fport.aspx" rel="noopener noreferrer">FPort</a> - Reports
open TCP/IP and UDP ports in a live system and maps them to the owning application.</li>
</ul>

<ul>
<li><a href="https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer" rel="noopener noreferrer">Process Explorer</a> -
Advanced task manager for Windows.</li>
</ul>

<ul>
<li><a href="https://docs.microsoft.com/en-us/sysinternals/downloads/pstools" rel="noopener noreferrer">PSTools</a> - Windows
command-line tools that help manage and investigate live systems.</li>
</ul>
<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://amzn.com/dp/144962636X" rel="noopener noreferrer">The Rootkit Arsenal</a> - The Rootkit Arsenal:
Escape and Evasion in the Dark Corners of the System</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/11/13/"/>
    <summary>5 awesome projects updated on Nov 13, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/10/10/</id>
    <title>Awesome Malware Analysis Updates on Oct 10, 2016</title>
    <updated>2016-10-10T15:46:08.000Z</updated>
    <published>2016-10-10T15:37:08.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.proofpoint.com/us/products/et-intelligence" rel="noopener noreferrer">Proofpoint Threat Intelligence</a> -
Rulesets and more. (Formerly Emerging Threats.)</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.procdot.com" rel="noopener noreferrer">ProcDot</a> - A graphical malware analysis tool kit.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/10/10/"/>
    <summary>2 awesome projects updated on Oct 10, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/09/29/</id>
    <title>Awesome Malware Analysis Updates on Sep 29, 2016</title>
    <updated>2016-09-29T03:47:04.000Z</updated>
    <published>2016-09-29T03:47:04.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://github.com/robbyFux/Ragpicker" rel="noopener noreferrer">Ragpicker (⭐91)</a> - Plugin based malware
crawler with pre-analysis and reporting functionalities</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/09/29/"/>
    <summary>1 awesome projects updated on Sep 29, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/09/11/</id>
    <title>Awesome Malware Analysis Updates on Sep 11, 2016</title>
    <updated>2016-09-11T14:37:31.000Z</updated>
    <published>2016-09-11T14:37:31.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/keithjjones/fileintel" rel="noopener noreferrer">Fileintel (⭐115)</a> - Pull intelligence per file hash.</li>
</ul>

<ul>
<li><a href="https://github.com/keithjjones/hostintel" rel="noopener noreferrer">Hostintel (⭐258)</a> - Pull intelligence per host.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/09/11/"/>
    <summary>2 awesome projects updated on Sep 11, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/08/28/</id>
    <title>Awesome Malware Analysis Updates on Aug 28, 2016</title>
    <updated>2016-08-28T00:40:57.000Z</updated>
    <published>2016-08-28T00:40:57.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="http://urlquery.net/" rel="noopener noreferrer">URLQuery</a> - Free URL Scanner.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/08/28/"/>
    <summary>1 awesome projects updated on Aug 28, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/08/09/</id>
    <title>Awesome Malware Analysis Updates on Aug 09, 2016</title>
    <updated>2016-08-09T13:25:38.000Z</updated>
    <published>2016-08-09T13:25:38.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://retdec.com/" rel="noopener noreferrer">RetDec</a> - Retargetable machine-code decompiler with an
<a href="https://retdec.com/decompilation/" rel="noopener noreferrer">online decompilation service</a> and
<a href="https://retdec.com/api/" rel="noopener noreferrer">API</a> that you can use in your tools.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/08/09/"/>
    <summary>1 awesome projects updated on Aug 09, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/07/30/</id>
    <title>Awesome Malware Analysis Updates on Jul 30, 2016</title>
    <updated>2016-07-30T04:54:24.000Z</updated>
    <published>2016-07-30T04:54:24.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="http://osint.bambenekconsulting.com/feeds/" rel="noopener noreferrer">Bambenek Consulting Feeds</a> -
OSINT feeds based on malicious DGA algorithms.</li>
</ul>

<ul>
<li><a href="https://www.fidelissecurity.com/resources/fidelis-barncat" rel="noopener noreferrer">Fidelis Barncat</a> -
Extensive malware config database (must request access).</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/07/30/"/>
    <summary>2 awesome projects updated on Jul 30, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/07/01/</id>
    <title>Awesome Malware Analysis Updates on Jul 01, 2016</title>
    <updated>2016-07-01T02:05:30.000Z</updated>
    <published>2016-07-01T02:05:30.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.joesecurity.org" rel="noopener noreferrer">Joe Sandbox</a> - Deep malware analysis with Joe Sandbox.</li>
</ul>
<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://developer.microsoft.com/en-us/windows/hardware/windows-driver-kit" rel="noopener noreferrer">WinDbg</a> -
Live memory inspection and kernel debugging for Windows systems.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/07/01/"/>
    <summary>2 awesome projects updated on Jul 01, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/06/28/</id>
    <title>Awesome Malware Analysis Updates on Jun 28, 2016</title>
    <updated>2016-06-28T10:32:45.000Z</updated>
    <published>2016-06-28T09:44:29.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.networktotal.com/index.html" rel="noopener noreferrer">NetworkTotal</a> - A service that analyzes
pcap files and facilitates the quick detection of viruses, worms, trojans, and all
kinds of malware using Suricata configured with EmergingThreats Pro.</li>
</ul>
<h3><p>Documents and Shellcode / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.quicksand.io/" rel="noopener noreferrer">QuickSand</a> - QuickSand is a compact C framework
to analyze suspected malware documents to identify exploits in streams of different
encodings and to locate and extract embedded executables.</li>
</ul>
<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/flare-floss" rel="noopener noreferrer">FLOSS (⭐3.1k)</a> - The FireEye Labs Obfuscated
String Solver uses advanced static analysis techniques to automatically
deobfuscate strings from malware binaries.</li>
</ul>

<ul>
<li><a href="https://github.com/malwaremusings/unpacker/" rel="noopener noreferrer">unpacker (⭐117)</a> - Automated malware
unpacker for Windows malware based on WinAppDbg.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/bwall/bamfdetect" rel="noopener noreferrer">bamfdetect</a> - Identifies and extracts
information from bots and other malware.</li>
</ul>
<h3><p>Storage and Workflow / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/ANSSI-FR/polichombr" rel="noopener noreferrer">Polichombr (⭐373)</a> - A malware analysis
platform designed to help analysts to reverse malwares collaboratively.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/LordNoteworthy/al-khaser" rel="noopener noreferrer">al-khaser (⭐5.6k)</a> - A PoC malware
with good intentions that aimes to stress anti-malware systems.</li>
</ul>

<ul>
<li><a href="https://github.com/misterch0c/malSploitBase" rel="noopener noreferrer">MalSploitBase (⭐531)</a> - A database
containing exploits used by malware.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/06/28/"/>
    <summary>8 awesome projects updated on Jun 28, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/06/05/</id>
    <title>Awesome Malware Analysis Updates on Jun 05, 2016</title>
    <updated>2016-06-05T05:25:14.000Z</updated>
    <published>2016-06-05T05:25:14.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hslatman/awesome-industrial-control-system-security" rel="noopener noreferrer">Industrial Control System Security (⭐1.6k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/hslatman/awesome-threat-intelligence" rel="noopener noreferrer">Threat Intelligence (⭐7.6k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/06/05/"/>
    <summary>2 awesome projects updated on Jun 05, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/06/04/</id>
    <title>Awesome Malware Analysis Updates on Jun 04, 2016</title>
    <updated>2016-06-04T21:47:58.000Z</updated>
    <published>2016-06-04T21:47:58.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Cisco-Talos/ROPMEMU" rel="noopener noreferrer">ROPMEMU (⭐281)</a> - A framework to analyze, dissect
and decompile complex code-reuse attacks.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/06/04/"/>
    <summary>1 awesome projects updated on Jun 04, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/05/26/</id>
    <title>Awesome Malware Analysis Updates on May 26, 2016</title>
    <updated>2016-05-26T19:46:13.000Z</updated>
    <published>2016-05-26T14:33:56.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/mushorg/glastopf" rel="noopener noreferrer">Glastopf (⭐541)</a> - Web application honeypot.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/abusesa/abusehelper" rel="noopener noreferrer">AbuseHelper (⭐113)</a> - An open-source
framework for receiving and redistributing abuse feeds and threat intel.</li>
</ul>

<ul>
<li><a href="https://otx.alienvault.com/" rel="noopener noreferrer">AlienVault Open Threat Exchange</a> - Share and
collaborate in developing Threat Intelligence.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/horsicq/Detect-It-Easy" rel="noopener noreferrer">Detect It Easy(DiE) (⭐6.9k)</a> - A program for
determining types of files.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/michael-yip/MaltegoVT" rel="noopener noreferrer">MaltegoVT (⭐77)</a> - Maltego transform
for the VirusTotal API. Allows domain/IP research, and searching for file
hashes and scan reports.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/rabbitstack/fibratus" rel="noopener noreferrer">Fibratus (⭐2.1k)</a> - Tool for exploration
and tracing of the Windows kernel.</li>
</ul>

<ul>
<li><a href="https://www.mzrst.com/" rel="noopener noreferrer">PPEE (puppy)</a> - A Professional PE file Explorer for
reversers, malware researchers and those who want to statically inspect PE
files in more detail.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/05/26/"/>
    <summary>7 awesome projects updated on May 26, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/05/18/</id>
    <title>Awesome Malware Analysis Updates on May 18, 2016</title>
    <updated>2016-05-18T19:56:33.000Z</updated>
    <published>2016-05-18T19:56:33.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/elceef/dnstwist" rel="noopener noreferrer">dnstwist (⭐4.7k)</a> - Domain name permutation
engine for detecting typo squatting, phishing and corporate espionage.</li>
</ul>

<ul>
<li><a href="https://github.com/FGRibreau/mailchecker" rel="noopener noreferrer">mailchecker (⭐1.6k)</a> - Cross-language
temporary email detection library.</li>
</ul>
<h3><p>Browser Malware / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Storyyeller/Krakatau" rel="noopener noreferrer">Krakatau (⭐2k)</a> - Java decompiler,
assembler, and disassembler.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.haka-security.org/" rel="noopener noreferrer">Haka</a> - An open source security oriented
language for describing protocols and applying security policies on (live)
captured traffic.</li>
</ul>
<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/JamesHabben/evolve" rel="noopener noreferrer">evolve (⭐259)</a> - Web interface for the
Volatility Memory Forensics Framework.</li>
</ul>

<ul>
<li><a href="https://github.com/kevthehermit/VolUtility" rel="noopener noreferrer">VolUtility (⭐375)</a> - Web Interface for
Volatility Memory Analysis framework.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/corkami/pics" rel="noopener noreferrer">File Formats posters (⭐10k)</a> - Nice visualization
of commonly used file format (including PE &amp; ELF).</li>
</ul>

<ul>
<li><a href="http://fumalwareanalysis.blogspot.nl/p/malware-analysis-tutorials-reverse.html" rel="noopener noreferrer">Malware Analysis Tutorials</a> -
The Malware Analysis Tutorials by Dr. Xiang Fu, a great resource for learning
practical malware analysis.</li>
</ul>

<ul>
<li><a href="https://bluesoul.me/practical-malware-analysis-starter-kit/" rel="noopener noreferrer">Practical Malware Analysis Starter Kit</a> -
This package contains most of the software referenced in the Practical Malware
Analysis book.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/05/18/"/>
    <summary>9 awesome projects updated on May 18, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/04/27/</id>
    <title>Awesome Malware Analysis Updates on Apr 27, 2016</title>
    <updated>2016-04-27T16:12:28.000Z</updated>
    <published>2016-04-27T16:12:28.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://virusshare.com/" rel="noopener noreferrer">VirusShare</a> - Malware repository, registration
required.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/04/27/"/>
    <summary>1 awesome projects updated on Apr 27, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/04/02/</id>
    <title>Awesome Malware Analysis Updates on Apr 02, 2016</title>
    <updated>2016-04-02T14:15:33.000Z</updated>
    <published>2016-04-02T14:15:33.000Z</published>
    <content type="html"><![CDATA[<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/lmco/laikaboss" rel="noopener noreferrer">Laika BOSS (⭐723)</a> - Laika BOSS is a file-centric
malware analysis and intrusion detection system.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/04/02/"/>
    <summary>1 awesome projects updated on Apr 02, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/03/31/</id>
    <title>Awesome Malware Analysis Updates on Mar 31, 2016</title>
    <updated>2016-03-31T21:27:13.000Z</updated>
    <published>2016-03-31T21:27:13.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://iplists.firehol.org/" rel="noopener noreferrer">FireHOL IP Lists</a> - Analytics for 350+ IP lists
with a focus on attacks, malware and abuse. Evolution, Changes History,
Country Maps, Age of IPs listed, Retention Policy, Overlaps.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/03/31/"/>
    <summary>1 awesome projects updated on Mar 31, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/03/16/</id>
    <title>Awesome Malware Analysis Updates on Mar 16, 2016</title>
    <updated>2016-03-16T04:45:20.000Z</updated>
    <published>2016-03-16T04:45:20.000Z</published>
    <content type="html"><![CDATA[<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hurricanelabs/machinae" rel="noopener noreferrer">Machinae (⭐499)</a> - OSINT tool for
gathering information about URLs, IPs, or hashes. Similar to Automator.</li>
</ul>

<ul>
<li><a href="http://www.tekdefense.com/automater/" rel="noopener noreferrer">TekDefense Automater</a> - OSINT tool
for gathering information about URLs, IPs, or hashes.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/03/16/"/>
    <summary>2 awesome projects updated on Mar 16, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/02/27/</id>
    <title>Awesome Malware Analysis Updates on Feb 27, 2016</title>
    <updated>2016-02-27T19:35:50.000Z</updated>
    <published>2016-02-27T19:35:50.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/meirwah/awesome-incident-response" rel="noopener noreferrer">Incident-Response (⭐7.3k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/02/27/"/>
    <summary>1 awesome projects updated on Feb 27, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/01/22/</id>
    <title>Awesome Malware Analysis Updates on Jan 22, 2016</title>
    <updated>2016-01-22T14:26:02.000Z</updated>
    <published>2016-01-22T14:26:02.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="http://malware-traffic-analysis.net/" rel="noopener noreferrer">Malware Samples and Traffic</a> - This
blog focuses on network traffic related to malware infections.</li>
</ul>

<ul>
<li><a href="https://github.com/RPISEC/Malware" rel="noopener noreferrer">RPISEC Malware Analysis (⭐3.7k)</a> - These are the
course materials used in the Malware Analysis course at at Rensselaer Polytechnic
Institute during Fall 2015.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/01/22/"/>
    <summary>2 awesome projects updated on Jan 22, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2016/01/09/</id>
    <title>Awesome Malware Analysis Updates on Jan 09, 2016</title>
    <updated>2016-01-09T11:43:10.000Z</updated>
    <published>2016-01-09T11:43:10.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/F-Secure/see" rel="noopener noreferrer">SEE (⭐809)</a> - Sandboxed Execution Environment (SEE)
is a framework for building test automation in secured Environments.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2016/01/09/"/>
    <summary>1 awesome projects updated on Jan 09, 2016</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/12/29/</id>
    <title>Awesome Malware Analysis Updates on Dec 29, 2015</title>
    <updated>2015-12-29T10:17:15.000Z</updated>
    <published>2015-12-29T09:58:43.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="http://www.honeyd.org/" rel="noopener noreferrer">Honeyd</a> - Create a virtual honeynet.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://www.fireeye.com/services/freeware/ioc-editor.html" rel="noopener noreferrer">IOC Editor</a> -
A free editor for XML IOC files.</li>
</ul>

<ul>
<li><a href="https://github.com/pidydx/PyIOCe" rel="noopener noreferrer">PyIOCe (⭐16)</a> - A Python OpenIOC editor.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/12/29/"/>
    <summary>3 awesome projects updated on Dec 29, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/12/28/</id>
    <title>Awesome Malware Analysis Updates on Dec 28, 2015</title>
    <updated>2015-12-28T23:09:27.000Z</updated>
    <published>2015-12-28T11:50:37.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/michael-yip/ThreatTracker" rel="noopener noreferrer">ThreatTracker (⭐64)</a> - A Python
script to monitor and generate alerts based on IOCs indexed by a set of
Google Custom Search Engines.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.autoshun.org/" rel="noopener noreferrer">Autoshun</a> (<a href="https://www.autoshun.org/files/shunlist.csv" rel="noopener noreferrer">list</a>) -
Snort plugin and blocklist.</li>
</ul>

<ul>
<li><a href="http://stixproject.github.io" rel="noopener noreferrer">STIX - Structured Threat Information eXpression</a> -
Standardized language to represent and share cyber threat information.
Related efforts from <a href="https://www.mitre.org/" rel="noopener noreferrer">MITRE</a>:<ul>
<li><a href="http://capec.mitre.org/" rel="noopener noreferrer">CAPEC - Common Attack Pattern Enumeration and Classification</a></li>
<li><a href="http://cyboxproject.github.io" rel="noopener noreferrer">CybOX - Cyber Observables eXpression</a></li>
<li><a href="http://maec.mitre.org/" rel="noopener noreferrer">MAEC - Malware Attribute Enumeration and Characterization</a></li>
<li><a href="http://taxiiproject.github.io" rel="noopener noreferrer">TAXII - Trusted Automated eXchange of Indicator Information</a></li>
</ul>
</li>
</ul>
<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/BromiumLabs/PackerAttacker" rel="noopener noreferrer">PackerAttacker (⭐263)</a> - A generic
hidden code extractor for Windows malware.</li>
</ul>

<ul>
<li><a href="https://github.com/jnraber/VirtualDeobfuscator" rel="noopener noreferrer">VirtualDeobfuscator (⭐128)</a> -
Reverse engineering tool for virtualization wrappers.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/angr/angr" rel="noopener noreferrer">angr (⭐7.3k)</a> - Platform-agnostic binary analysis
framework developed at UCSB's Seclab.</li>
</ul>

<ul>
<li><a href="https://github.com/programa-stic/barf-project" rel="noopener noreferrer">BARF (⭐1.4k)</a> - Multiplatform, open
source Binary Analysis and Reverse engineering Framework.</li>
</ul>

<ul>
<li><a href="https://github.com/google/binnavi" rel="noopener noreferrer">binnavi (⭐2.9k)</a> - Binary analysis IDE for
reverse engineering based on graph visualization.</li>
</ul>

<ul>
<li><a href="https://github.com/aquynh/capstone" rel="noopener noreferrer">Capstone (⭐7.2k)</a> - Disassembly framework for
binary analysis and reversing, with support for many architectures and
bindings in several languages.</li>
</ul>

<ul>
<li><a href="https://github.com/hugsy/gef" rel="noopener noreferrer">GEF (⭐6.7k)</a> - GDB Enhanced Features, for exploiters
and reverse engineers.</li>
</ul>

<ul>
<li><a href="https://github.com/longld/peda" rel="noopener noreferrer">PEDA (⭐5.8k)</a> - Python Exploit Development
Assistance for GDB, an enhanced display with added commands.</li>
</ul>

<ul>
<li><a href="https://github.com/pidydx/SMRT" rel="noopener noreferrer">SMRT (⭐64)</a> - Sublime Malware Research Tool, a
plugin for Sublime 3 to aid with malware analyis.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hempnall/broyara" rel="noopener noreferrer">BroYara (⭐31)</a> - Use Yara rules from Bro.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/12/28/"/>
    <summary>13 awesome projects updated on Dec 28, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/12/10/</id>
    <title>Awesome Malware Analysis Updates on Dec 10, 2015</title>
    <updated>2015-12-10T15:26:23.000Z</updated>
    <published>2015-12-10T15:26:23.000Z</published>
    <content type="html"><![CDATA[<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/stamparm/maltrail" rel="noopener noreferrer">Maltrail (⭐5.9k)</a> - A malicious traffic
detection system, utilizing publicly available (black)lists containing
malicious and/or generally suspicious trails and featuring an reporting
and analysis interface.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/12/10/"/>
    <summary>1 awesome projects updated on Dec 10, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/11/14/</id>
    <title>Awesome Malware Analysis Updates on Nov 14, 2015</title>
    <updated>2015-11-14T05:13:24.000Z</updated>
    <published>2015-11-14T03:37:29.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/mushorg/conpot" rel="noopener noreferrer">Conpot (⭐1.2k)</a> - ICS/SCADA honeypot.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.clamav.net/" rel="noopener noreferrer">ClamAV</a> - Open source antivirus engine.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.deepviz.com/" rel="noopener noreferrer">DeepViz</a> - Multi-format file analyzer with
machine-learning classification.</li>
</ul>

<ul>
<li><a href="https://virusscan.jotti.org/en" rel="noopener noreferrer">Jotti</a> - Free online multi-AV scanner.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/11/14/"/>
    <summary>4 awesome projects updated on Nov 14, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/10/13/</id>
    <title>Awesome Malware Analysis Updates on Oct 13, 2015</title>
    <updated>2015-10-13T05:23:16.000Z</updated>
    <published>2015-10-13T05:23:16.000Z</published>
    <content type="html"><![CDATA[<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://andrototal.org/" rel="noopener noreferrer">AndroTotal</a> - Free online analysis of APKs
against multiple mobile antivirus apps.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/10/13/"/>
    <summary>1 awesome projects updated on Oct 13, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/10/08/</id>
    <title>Awesome Malware Analysis Updates on Oct 08, 2015</title>
    <updated>2015-10-08T23:20:31.000Z</updated>
    <published>2015-10-08T23:20:31.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/x64dbg/" rel="noopener noreferrer">X64dbg</a> - An open-source x64/x32 debugger for windows.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/10/08/"/>
    <summary>1 awesome projects updated on Oct 08, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/10/02/</id>
    <title>Awesome Malware Analysis Updates on Oct 02, 2015</title>
    <updated>2015-10-02T16:28:37.000Z</updated>
    <published>2015-10-02T16:25:51.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Dynetics/Malfunction" rel="noopener noreferrer">Malfunction (⭐191)</a> - Catalog and
compare malware at a function level.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/aptnotes/data" rel="noopener noreferrer">APT Notes (⭐1.6k)</a> - A collection of papers
and notes related to Advanced Persistent Threats.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/10/02/"/>
    <summary>2 awesome projects updated on Oct 02, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/10/01/</id>
    <title>Awesome Malware Analysis Updates on Oct 01, 2015</title>
    <updated>2015-10-01T14:14:43.000Z</updated>
    <published>2015-10-01T14:14:43.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/paragonie/awesome-appsec" rel="noopener noreferrer">AppSec (⭐6.2k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/10/01/"/>
    <summary>1 awesome projects updated on Oct 01, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/09/25/</id>
    <title>Awesome Malware Analysis Updates on Sep 25, 2015</title>
    <updated>2015-09-25T18:44:44.000Z</updated>
    <published>2015-09-25T18:44:44.000Z</published>
    <content type="html"><![CDATA[<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/onlurking/awesome-infosec" rel="noopener noreferrer">Infosec (⭐5.1k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/09/25/"/>
    <summary>1 awesome projects updated on Sep 25, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/09/22/</id>
    <title>Awesome Malware Analysis Updates on Sep 22, 2015</title>
    <updated>2015-09-22T16:35:43.000Z</updated>
    <published>2015-09-22T14:51:15.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://malshare.com" rel="noopener noreferrer">Malshare</a> - Large repository of malware actively
scrapped from malicious sites.</li>
</ul>

<ul>
<li><a href="https://github.com/ytisf/theZoo" rel="noopener noreferrer">theZoo (⭐11k)</a> - Live malware samples for
analysts.</li>
</ul>

<ul>
<li><a href="http://www.virussign.com/" rel="noopener noreferrer">ViruSign</a> - Malware database that detected by
many anti malware programs except ClamAV.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://www.enisa.europa.eu/topics/csirt-cert-services/community-projects/incident-handling-automation" rel="noopener noreferrer">IntelMQ</a> -
A tool for CERTs for processing incident data using a message queue.</li>
</ul>

<ul>
<li><a href="https://github.com/MISP/MISP" rel="noopener noreferrer">MISP (⭐5.1k)</a> - Malware Information Sharing
Platform curated by <a href="http://www.misp-project.org/" rel="noopener noreferrer">The MISP Project</a>.</li>
</ul>

<ul>
<li><a href="https://www.threatcrowd.org/" rel="noopener noreferrer">ThreatCrowd</a> - A search engine for threats,
with graphical visualization.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://intel.criticalstack.com" rel="noopener noreferrer">Critical Stack- Free Intel Market</a> - Free
intel aggregator with deduplication featuring 90+ feeds and over 1.2M indicators.</li>
</ul>

<ul>
<li><a href="https://threatrecon.co/" rel="noopener noreferrer">threatRECON</a> - Search for indicators, up to 1000
free per month.</li>
</ul>

<ul>
<li><a href="https://github.com/Yara-Rules/rules" rel="noopener noreferrer">Yara rules (⭐4k)</a> - Yara rules repository.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Neo23x0/Loki" rel="noopener noreferrer">Loki (⭐3.3k)</a> - Host based scanner for IOCs.</li>
</ul>

<ul>
<li><a href="https://github.com/mitre/multiscanner" rel="noopener noreferrer">MultiScanner (⭐615)</a> - Modular file
scanning/analysis framework</li>
</ul>

<ul>
<li><a href="https://github.com/Neo23x0/yarGen" rel="noopener noreferrer">Yara rules generator (⭐1.5k)</a> - Generate
yara rules based on a set of malware samples. Also contains a good
strings DB to avoid false positives.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.cryptam.com/" rel="noopener noreferrer">Cryptam</a> - Analyze suspicious office documents.</li>
</ul>

<ul>
<li><a href="https://github.com/brad-accuvant/cuckoo-modified" rel="noopener noreferrer">cuckoo-modified (⭐268)</a> - Modified
version of Cuckoo Sandbox released under the GPL. Not merged upstream due to
legal concerns by the author.</li>
</ul>

<ul>
<li><a href="http://irma.quarkslab.com/" rel="noopener noreferrer">IRMA</a> - An asynchronous and customizable
analysis platform for suspicious files.</li>
</ul>

<ul>
<li><a href="http://www.pdfexaminer.com/" rel="noopener noreferrer">PDF Examiner</a> - Analyse suspicious PDF files.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="http://desenmascara.me" rel="noopener noreferrer">Desenmascara.me</a> - One click tool to retrieve as
much metadata as possible for a website and to assess its good standing.</li>
</ul>

<ul>
<li><a href="https://www.spamcop.net/bl.shtml" rel="noopener noreferrer">SpamCop</a> - IP based spam block list.</li>
</ul>

<ul>
<li><a href="https://www.spamhaus.org/lookup/" rel="noopener noreferrer">SpamHaus</a> - Block list based on
domains and IPs.</li>
</ul>

<ul>
<li><a href="https://sitecheck.sucuri.net/" rel="noopener noreferrer">Sucuri SiteCheck</a> - Free Website Malware
and Security Scanner.</li>
</ul>
<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/0xd4d/de4dot" rel="noopener noreferrer">de4dot (⭐6.8k)</a> - .NET deobfuscator and
unpacker.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/0xd4d/dnSpy" rel="noopener noreferrer">dnSpy (⭐26k)</a> - .NET assembly editor, decompiler
and debugger.</li>
</ul>

<ul>
<li><a href="https://github.com/codypierce/hackers-grep" rel="noopener noreferrer">hackers-grep (⭐167)</a> - A utility to
search for strings in PE executables including imports, exports, and debug
symbols.</li>
</ul>

<ul>
<li><a href="https://sourceforge.net/projects/strace/" rel="noopener noreferrer">strace</a> - Dynamic analysis for
Linux executables.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/omriher/CapTipper" rel="noopener noreferrer">CapTipper (⭐707)</a> -  Malicious HTTP traffic
explorer.</li>
</ul>
<h3><p>Windows Artifacts / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/OMENScan/AChoir" rel="noopener noreferrer">AChoir (⭐177)</a> - A live incident response
script for gathering Windows artifacts.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/a0rtega/pafish" rel="noopener noreferrer">Pafish (⭐3.2k)</a> - Paranoid Fish, a demonstration
tool that employs several techniques to detect sandboxes and analysis
environments in the same way as malware families do.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.reddit.com/r/csirt_tools/" rel="noopener noreferrer">/r/csirt_tools</a> - Subreddit for CSIRT
tools and resources, with a
<a href="https://www.reddit.com/r/csirt_tools/search?q=flair%3A%22Malware%20analysis%22&amp;sort=new&amp;restrict_sr=on" rel="noopener noreferrer">malware analysis</a> flair.</li>
</ul>

<ul>
<li><a href="https://github.com/apsdehal/awesome-ctf" rel="noopener noreferrer">CTFs (⭐9.4k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/carpedm20/awesome-hacking" rel="noopener noreferrer">"Hacking" (⭐12k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/paralax/awesome-honeypots" rel="noopener noreferrer">Honeypots (⭐8.3k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/caesar0301/awesome-pcaptools" rel="noopener noreferrer">PCAP Tools (⭐3k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/09/22/"/>
    <summary>32 awesome projects updated on Sep 22, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/05/18/</id>
    <title>Awesome Malware Analysis Updates on May 18, 2015</title>
    <updated>2015-05-18T16:20:28.000Z</updated>
    <published>2015-05-18T16:19:02.000Z</published>
    <content type="html"><![CDATA[<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="https://winitor.com/" rel="noopener noreferrer">pestudio</a> - Perform static analysis of Windows
executables.</li>
</ul>
<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/aim4r/VolDiff" rel="noopener noreferrer">VolDiff (⭐192)</a> - Run Volatility on memory
images before and after malware execution, and report changes.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/05/18/"/>
    <summary>2 awesome projects updated on May 18, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/05/17/</id>
    <title>Awesome Malware Analysis Updates on May 17, 2015</title>
    <updated>2015-05-17T20:08:50.000Z</updated>
    <published>2015-05-17T15:05:09.000Z</published>
    <content type="html"><![CDATA[<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="http://pev.sourceforge.net/" rel="noopener noreferrer">PEV</a> - A multiplatform toolkit to work with PE
files, providing feature-rich tools for proper analysis of suspicious binaries.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.hybrid-analysis.com/" rel="noopener noreferrer">Hybrid Analysis</a> - Online malware
analysis tool, powered by VxSandbox.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/MITRECND/chopshop" rel="noopener noreferrer">chopshop (⭐487)</a> - Protocol analysis and
decoding framework.</li>
</ul>

<ul>
<li><a href="https://github.com/aol/moloch" rel="noopener noreferrer">Moloch (⭐6.2k)</a> - IPv4 traffic capturing, indexing
and database system.</li>
</ul>
<h3><p>Storage and Workflow / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/merces/aleph" rel="noopener noreferrer">Aleph (⭐154)</a> - Open Source Malware Analysis
Pipeline System.</li>
</ul>

<ul>
<li><a href="https://crits.github.io/" rel="noopener noreferrer">CRITs</a> - Collaborative Research Into Threats, a
malware and threat repository.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/Defense-Cyber-Crime-Center/DC3-MWCP" rel="noopener noreferrer">DC3-MWCP (⭐290)</a> -
The Defense Cyber Crime Center's Malware Configuration Parser framework.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/05/17/"/>
    <summary>7 awesome projects updated on May 17, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/05/15/</id>
    <title>Awesome Malware Analysis Updates on May 15, 2015</title>
    <updated>2015-05-15T20:20:11.000Z</updated>
    <published>2015-05-15T01:33:30.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="https://github.com/Visgean/Zeus" rel="noopener noreferrer">Zeus Source Code (⭐1.4k)</a> - Source for the Zeus
trojan leaked in 2011.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/mandiant/ioc_writer" rel="noopener noreferrer">ioc_writer (⭐199)</a> - Python library for
working with OpenIOC objects, from Mandiant.</li>
</ul>

<ul>
<li><a href="https://github.com/jpsenior/threataggregator" rel="noopener noreferrer">threataggregator (⭐78)</a> -
Aggregates security threats from a number of sources, including some of
those listed below in <a href="#other-resources">other resources</a>.</li>
</ul>

<ul>
<li><a href="https://github.com/mlsecproject/tiq-test" rel="noopener noreferrer">TIQ-test (⭐166)</a> - Data visualization
and statistical analysis of Threat Intelligence feeds.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/fireeye/iocs" rel="noopener noreferrer">FireEye IOCs (⭐461)</a> - Indicators of Compromise
shared publicly by FireEye.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/KoreLogicSecurity/mastiff" rel="noopener noreferrer">MASTIFF (⭐173)</a> - Static analysis
framework.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/tklengyel/drakvuf" rel="noopener noreferrer">DRAKVUF (⭐1k)</a> - Dynamic malware analysis
system.</li>
</ul>

<ul>
<li><a href="https://github.com/rieck/malheur" rel="noopener noreferrer">Malheur (⭐365)</a> - Automatic sandboxed analysis
of malware behavior.</li>
</ul>

<ul>
<li><a href="https://malwr.com/" rel="noopener noreferrer">Malwr</a> - Free analysis with an online Cuckoo Sandbox
instance.</li>
</ul>

<ul>
<li><a href="https://github.com/Rurik/Noriben" rel="noopener noreferrer">Noriben (⭐1.1k)</a> - Uses Sysinternals Procmon to
collect information about malware in a sandboxed environment.</li>
</ul>
<h3><p>Deobfuscation / Other Resources</p>
</h3>
<ul>
<li><a href="https://bitbucket.org/decalage/balbuzard/wiki/Home" rel="noopener noreferrer">Balbuzard</a> - A malware
analysis tool for reversing obfuscation (XOR, ROL, etc) and more.</li>
</ul>

<ul>
<li><a href="http://hooked-on-mnemonics.blogspot.com/2014/04/expexorpy.html" rel="noopener noreferrer">ex_pe_xor</a>
&amp; <a href="http://hooked-on-mnemonics.blogspot.com/p/iheartxor.html" rel="noopener noreferrer">iheartxor</a> -
Two tools from Alexander Hanel for working with single-byte XOR encoded
files.</li>
</ul>

<ul>
<li><a href="https://github.com/hiddenillusion/NoMoreXOR" rel="noopener noreferrer">NoMoreXOR (⭐84)</a> - Guess a 256 byte
XOR key using frequency analysis.</li>
</ul>

<ul>
<li><a href="https://github.com/tomchop/unxor/" rel="noopener noreferrer">unxor (⭐138)</a> - Guess XOR keys using
known-plaintext attacks.</li>
</ul>

<ul>
<li><a href="http://eternal-todo.com/var/scripts/xorbruteforcer" rel="noopener noreferrer">XORBruteForcer</a> -
A Python script for brute forcing single-byte XOR keys.</li>
</ul>

<ul>
<li><a href="https://blog.didierstevens.com/programs/xorsearch/" rel="noopener noreferrer">XORSearch &amp; XORStrings</a> -
A couple programs from Didier Stevens for finding XORed data.</li>
</ul>

<ul>
<li><a href="https://github.com/hellman/xortool" rel="noopener noreferrer">xortool (⭐1.4k)</a> - Guess XOR key length, as
well as the key itself.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="https://www.bro.org" rel="noopener noreferrer">Bro</a> - Protocol analyzer that operates at incredible
scale; both file and network protocols.</li>
</ul>

<ul>
<li><a href="https://www.telerik.com/fiddler" rel="noopener noreferrer">Fiddler</a> - Intercepting web proxy designed
for "web debugging."</li>
</ul>

<ul>
<li><a href="https://github.com/pjlantz/Hale" rel="noopener noreferrer">Hale (⭐184)</a> - Botnet C&amp;C monitor.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://santoku-linux.com/" rel="noopener noreferrer">Santoku Linux</a> - Linux distribution for mobile
forensics, malware analysis, and security.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li>Lenny Zeltser and other contributors for developing REMnux, where I
found many of the tools in this list;</li>
</ul>

<ul>
<li>Michail Hale Ligh, Steven Adair, Blake Hartstein, and Mather Richard for
writing the <em>Malware Analyst's Cookbook</em>, which was a big inspiration for
creating the list;</li>
</ul>

<ul>
<li>And everyone else who has sent pull requests or suggested links to add here!</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/05/15/"/>
    <summary>24 awesome projects updated on May 15, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/05/12/</id>
    <title>Awesome Malware Analysis Updates on May 12, 2015</title>
    <updated>2015-05-12T03:01:53.000Z</updated>
    <published>2015-05-12T03:01:53.000Z</published>
    <content type="html"><![CDATA[<h3><p>Open Source Threat Intelligence / Tools</p>
</h3>
<ul>
<li><a href="https://github.com/mlsecproject/combine" rel="noopener noreferrer">Combine (⭐650)</a> - Tool to gather Threat
Intelligence indicators from publicly available sources.</li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/05/12/"/>
    <summary>1 awesome projects updated on May 12, 2015</summary>
  </entry>
  <entry>
    <id>https://www.trackawesomelist.com/2015/05/09/</id>
    <title>Awesome Malware Analysis Updates on May 09, 2015</title>
    <updated>2015-05-09T22:46:02.000Z</updated>
    <published>2015-05-09T03:40:28.000Z</published>
    <content type="html"><![CDATA[<h3><p>Malware Collection / Anonymizers</p>
</h3>
<ul>
<li><a href="http://anonymouse.org/" rel="noopener noreferrer">Anonymouse.org</a> - A free, web based anonymizer.</li>
</ul>

<ul>
<li><a href="https://openvpn.net/" rel="noopener noreferrer">OpenVPN</a> - VPN software and hosting solutions.</li>
</ul>

<ul>
<li><a href="http://www.privoxy.org/" rel="noopener noreferrer">Privoxy</a> - An open source proxy server with some
privacy features.</li>
</ul>

<ul>
<li><a href="https://www.torproject.org/" rel="noopener noreferrer">Tor</a> - The Onion Router, for browsing the web
without leaving traces of the client IP.</li>
</ul>
<h3><p>Malware Collection / Honeypots</p>
</h3>
<ul>
<li><a href="https://github.com/johnnykv/mnemosyne" rel="noopener noreferrer">Mnemosyne (⭐44)</a> - A normalizer for
honeypot data; supports Dionaea.</li>
</ul>

<ul>
<li><a href="https://github.com/buffer/thug" rel="noopener noreferrer">Thug (⭐967)</a> - Low interaction honeyclient, for
investigating malicious websites.</li>
</ul>
<h3><p>Malware Collection / Malware Corpora</p>
</h3>
<ul>
<li><a href="http://contagiodump.blogspot.com/" rel="noopener noreferrer">Contagio</a> - A collection of recent
malware samples and analyses.</li>
</ul>

<ul>
<li><a href="https://www.exploit-db.com/" rel="noopener noreferrer">Exploit Database</a> - Exploit and shellcode
samples.</li>
</ul>

<ul>
<li><a href="https://zeltser.com/malware-sample-sources/" rel="noopener noreferrer">Zeltser's Sources</a> - A list
of malware sample sources put together by Lenny Zeltser.</li>
</ul>
<h3><p>Open Source Threat Intelligence / Other Resources</p>
</h3>
<ul>
<li><a href="http://cinsscore.com/" rel="noopener noreferrer">CI Army</a> (<a href="http://cinsscore.com/list/ci-badguys.txt" rel="noopener noreferrer">list</a>) -
Network security blocklists.</li>
</ul>

<ul>
<li><a href="https://github.com/rep/hpfeeds" rel="noopener noreferrer">hpfeeds (⭐208)</a> - Honeypot feed protocol.</li>
</ul>

<ul>
<li><a href="https://isc.sans.edu/" rel="noopener noreferrer">Internet Storm Center (DShield)</a> - Diary and
searchable incident database, with a web <a href="https://dshield.org/api/" rel="noopener noreferrer">API</a>.
(<a href="https://github.com/rshipp/python-dshield" rel="noopener noreferrer">unofficial Python library (⭐24)</a>).</li>
</ul>

<ul>
<li><a href="http://malc0de.com/database/" rel="noopener noreferrer">malc0de</a> - Searchable incident database.</li>
</ul>

<ul>
<li><a href="http://www.malwaredomainlist.com/" rel="noopener noreferrer">Malware Domain List</a> - Search and share
malicious URLs.</li>
</ul>

<ul>
<li><a href="https://zeustracker.abuse.ch/blocklist.php" rel="noopener noreferrer">ZeuS Tracker</a> - ZeuS
blocklists.</li>
</ul>
<h3><p>Detection and Classification / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hiddenillusion/AnalyzePE" rel="noopener noreferrer">AnalyzePE (⭐201)</a> - Wrapper for a
variety of tools for reporting on Windows PE files.</li>
</ul>

<ul>
<li><a href="http://www.chkrootkit.org/" rel="noopener noreferrer">chkrootkit</a> - Local Linux rootkit detection.</li>
</ul>

<ul>
<li><a href="https://sno.phy.queensu.ca/~phil/exiftool/" rel="noopener noreferrer">ExifTool</a> - Read, write and
edit file metadata.</li>
</ul>

<ul>
<li><a href="https://github.com/jessek/hashdeep" rel="noopener noreferrer">hashdeep (⭐694)</a> - Compute digest hashes with
a variety of algorithms.</li>
</ul>

<ul>
<li><a href="https://github.com/rjhansen/nsrllookup" rel="noopener noreferrer">nsrllookup (⭐110)</a> - A tool for looking
up hashes in NIST's National Software Reference Library database.</li>
</ul>

<ul>
<li><a href="http://rkhunter.sourceforge.net/" rel="noopener noreferrer">Rootkit Hunter</a> - Detect Linux rootkits.</li>
</ul>

<ul>
<li><a href="http://mark0.net/soft-trid-e.html" rel="noopener noreferrer">TrID</a> - File identifier.</li>
</ul>

<ul>
<li><a href="https://plusvic.github.io/yara/" rel="noopener noreferrer">YARA</a> - Pattern matching tool for
analysts.</li>
</ul>
<h3><p>Online Scanners and Sandboxes / Other Resources</p>
</h3>
<ul>
<li><a href="https://cuckoosandbox.org/" rel="noopener noreferrer">Cuckoo Sandbox</a> - Open source, self hosted
sandbox and automated analysis system.</li>
</ul>

<ul>
<li><a href="https://github.com/secretsquirrel/recomposer" rel="noopener noreferrer">Recomposer (⭐130)</a> - A helper
script for safely uploading binaries to sandbox sites.</li>
</ul>

<ul>
<li><a href="https://www.virustotal.com/" rel="noopener noreferrer">VirusTotal</a> - Free online analysis of malware
samples and URLs</li>
</ul>

<ul>
<li><a href="https://zeltser.com/automated-malware-analysis/" rel="noopener noreferrer">Zeltser's List</a> - Free
automated sandboxes and services, compiled by Lenny Zeltser.</li>
</ul>
<h3><p>Domain Analysis / Other Resources</p>
</h3>
<ul>
<li><a href="https://networking.ringofsaturn.com/" rel="noopener noreferrer">Dig</a> - Free online dig and other
network tools.</li>
</ul>

<ul>
<li><a href="https://github.com/hiddenillusion/IPinfo" rel="noopener noreferrer">IPinfo (⭐95)</a> - Gather information
about an IP or domain by searching online resources.</li>
</ul>

<ul>
<li><a href="https://whois.domaintools.com/" rel="noopener noreferrer">Whois</a> - DomainTools free online whois
search.</li>
</ul>

<ul>
<li><a href="https://zeltser.com/lookup-malicious-websites/" rel="noopener noreferrer">Zeltser's List</a> - Free
online tools for researching malicious websites, compiled by Lenny Zeltser.</li>
</ul>
<h3><p>Browser Malware / Other Resources</p>
</h3>
<ul>
<li><a href="http://jd.benow.ca/" rel="noopener noreferrer">Java Decompiler</a> - Decompile and inspect Java apps.</li>
</ul>

<ul>
<li><a href="https://github.com/Rurik/Java_IDX_Parser/" rel="noopener noreferrer">Java IDX Parser (⭐39)</a> - Parses Java
IDX cache files.</li>
</ul>

<ul>
<li><a href="http://www.relentless-coding.com/projects/jsdetox/" rel="noopener noreferrer">JSDetox</a> - JavaScript
malware analysis tool.</li>
</ul>

<ul>
<li><a href="https://github.com/urule99/jsunpack-n" rel="noopener noreferrer">jsunpack-n (⭐158)</a> - A javascript
unpacker that emulates browser functionality.</li>
</ul>

<ul>
<li><a href="http://malzilla.sourceforge.net/" rel="noopener noreferrer">Malzilla</a> - Analyze malicious web pages.</li>
</ul>

<ul>
<li><a href="https://github.com/CyberShadow/RABCDAsm" rel="noopener noreferrer">RABCDAsm (⭐427)</a> - A "Robust
ActionScript Bytecode Disassembler."</li>
</ul>

<ul>
<li><a href="http://www.swftools.org/" rel="noopener noreferrer">swftools</a> - Tools for working with Adobe Flash
files.</li>
</ul>

<ul>
<li><a href="http://hooked-on-mnemonics.blogspot.com/2011/12/xxxswfpy.html" rel="noopener noreferrer">xxxswf</a> - A
Python script for analyzing Flash files.</li>
</ul>
<h3><p>Documents and Shellcode / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/hiddenillusion/AnalyzePDF" rel="noopener noreferrer">AnalyzePDF (⭐171)</a> - A tool for
analyzing PDFs and attempting to determine whether they are malicious.</li>
</ul>

<ul>
<li><a href="http://www.ragestorm.net/distorm/" rel="noopener noreferrer">diStorm</a> - Disassembler for analyzing
malicious shellcode.</li>
</ul>

<ul>
<li><a href="http://jsbeautifier.org/" rel="noopener noreferrer">JS Beautifier</a> - JavaScript unpacking and deobfuscation.</li>
</ul>

<ul>
<li><a href="http://libemu.carnivore.it/" rel="noopener noreferrer">libemu</a> - Library and tools for x86 shellcode
emulation.</li>
</ul>

<ul>
<li><a href="https://github.com/9b/malpdfobj" rel="noopener noreferrer">malpdfobj (⭐51)</a> - Deconstruct malicious PDFs
into a JSON representation.</li>
</ul>

<ul>
<li><a href="http://www.reconstructer.org/code.html" rel="noopener noreferrer">OfficeMalScanner</a> - Scan for
malicious traces in MS Office documents.</li>
</ul>

<ul>
<li><a href="http://www.decalage.info/python/olevba" rel="noopener noreferrer">olevba</a> - A script for parsing OLE
and OpenXML documents and extracting useful information.</li>
</ul>

<ul>
<li><a href="https://code.google.com/archive/p/origami-pdf" rel="noopener noreferrer">Origami PDF</a> - A tool for
analyzing malicious PDFs, and more.</li>
</ul>

<ul>
<li><a href="https://blog.didierstevens.com/programs/pdf-tools/" rel="noopener noreferrer">PDF Tools</a> - pdfid,
pdf-parser, and more from Didier Stevens.</li>
</ul>

<ul>
<li><a href="https://github.com/9b/pdfxray_lite" rel="noopener noreferrer">PDF X-Ray Lite (⭐34)</a> - A PDF analysis tool,
the backend-free version of PDF X-RAY.</li>
</ul>

<ul>
<li><a href="http://eternal-todo.com/tools/peepdf-pdf-analysis-tool" rel="noopener noreferrer">peepdf</a> - Python
tool for exploring possibly malicious PDFs.</li>
</ul>

<ul>
<li><a href="https://developer.mozilla.org/en-US/docs/Mozilla/Projects/SpiderMonkey" rel="noopener noreferrer">Spidermonkey</a> -
Mozilla's JavaScript engine, for debugging malicious JS.</li>
</ul>
<h3><p>File Carving / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/simsong/bulk_extractor" rel="noopener noreferrer">bulk_extractor (⭐1k)</a> - Fast file
carving tool.</li>
</ul>

<ul>
<li><a href="https://github.com/williballenthin/EVTXtract" rel="noopener noreferrer">EVTXtract (⭐176)</a> - Carve Windows
Event Log files from raw binary data.</li>
</ul>

<ul>
<li><a href="http://foremost.sourceforge.net/" rel="noopener noreferrer">Foremost</a> - File carving tool designed
by the US Air Force.</li>
</ul>

<ul>
<li><a href="https://github.com/sleuthkit/scalpel" rel="noopener noreferrer">Scalpel (⭐612)</a> - Another data carving
tool.</li>
</ul>
<h3><p>Debugging and Reverse Engineering / Other Resources</p>
</h3>
<ul>
<li><a href="http://codef00.com/projects#debugger" rel="noopener noreferrer">Evan's Debugger (EDB)</a> - A
modular debugger with a Qt GUI.</li>
</ul>

<ul>
<li><a href="http://www.sourceware.org/gdb/" rel="noopener noreferrer">GDB</a> - The GNU debugger.</li>
</ul>

<ul>
<li><a href="https://www.hex-rays.com/products/ida/index.shtml" rel="noopener noreferrer">IDA Pro</a> - Windows
disassembler and debugger, with a free evaluation version.</li>
</ul>

<ul>
<li><a href="http://debugger.immunityinc.com/" rel="noopener noreferrer">Immunity Debugger</a> - Debugger for
malware analysis and more, with a Python API.</li>
</ul>

<ul>
<li><a href="http://ltrace.org/" rel="noopener noreferrer">ltrace</a> - Dynamic analysis for Linux executables.</li>
</ul>

<ul>
<li><a href="https://en.wikipedia.org/wiki/Objdump" rel="noopener noreferrer">objdump</a> - Part of GNU binutils,
for static analysis of Linux binaries.</li>
</ul>

<ul>
<li><a href="http://www.ollydbg.de/" rel="noopener noreferrer">OllyDbg</a> - An assembly-level debugger for Windows
executables.</li>
</ul>

<ul>
<li><a href="https://docs.microsoft.com/en-us/sysinternals/downloads/procmon" rel="noopener noreferrer">Process Monitor</a> -
Advanced monitoring tool for Windows programs.</li>
</ul>

<ul>
<li><a href="https://github.com/joxeankoret/pyew" rel="noopener noreferrer">Pyew (⭐380)</a> - Python tool for malware
analysis.</li>
</ul>

<ul>
<li><a href="http://www.radare.org/r/" rel="noopener noreferrer">Radare2</a> - Reverse engineering framework, with
debugger support.</li>
</ul>

<ul>
<li><a href="https://github.com/vmt/udis86" rel="noopener noreferrer">Udis86 (⭐999)</a> - Disassembler library and tool
for x86 and x86_64.</li>
</ul>

<ul>
<li><a href="https://github.com/vivisect/vivisect" rel="noopener noreferrer">Vivisect (⭐908)</a> - Python tool for
malware analysis.</li>
</ul>
<h3><p>Network / Other Resources</p>
</h3>
<ul>
<li><a href="http://www.inetsim.org/" rel="noopener noreferrer">INetSim</a> - Network service emulation, useful when
building a malware lab.</li>
</ul>

<ul>
<li><a href="https://github.com/tomchop/malcom" rel="noopener noreferrer">Malcom (⭐1.1k)</a> - Malware Communications
Analyzer.</li>
</ul>

<ul>
<li><a href="https://mitmproxy.org/" rel="noopener noreferrer">mitmproxy</a> - Intercept network traffic on the fly.</li>
</ul>

<ul>
<li><a href="http://www.netresec.com/?page=NetworkMiner" rel="noopener noreferrer">NetworkMiner</a> - Network
forensic analysis tool, with a free version.</li>
</ul>

<ul>
<li><a href="https://github.com/jpr5/ngrep" rel="noopener noreferrer">ngrep (⭐864)</a> - Search through network traffic
like grep.</li>
</ul>

<ul>
<li><a href="http://www.tcpdump.org/" rel="noopener noreferrer">Tcpdump</a> - Collect network traffic.</li>
</ul>

<ul>
<li><a href="http://tcpick.sourceforge.net/" rel="noopener noreferrer">tcpick</a> - Trach and reassemble TCP streams
from network traffic.</li>
</ul>

<ul>
<li><a href="http://tcpxtract.sourceforge.net/" rel="noopener noreferrer">tcpxtract</a> - Extract files from network
traffic.</li>
</ul>

<ul>
<li><a href="https://www.wireshark.org/" rel="noopener noreferrer">Wireshark</a> - The network traffic analysis
tool.</li>
</ul>
<h3><p>Memory Forensics / Other Resources</p>
</h3>
<ul>
<li><a href="https://sourceforge.net/projects/findaes/" rel="noopener noreferrer">FindAES</a> - Find AES
encryption keys in memory.</li>
</ul>

<ul>
<li><a href="https://github.com/ytisf/muninn" rel="noopener noreferrer">Muninn (⭐51)</a> - A script to automate portions
of analysis using Volatility, and create a readable report.
<a href="https://github.com/LDO-CERT/orochi" rel="noopener noreferrer">Orochi (⭐208)</a> - Orochi is an open source framework for
collaborative forensic memory dump analysis.</li>
</ul>

<ul>
<li><a href="http://www.rekall-forensic.com/" rel="noopener noreferrer">Rekall</a> - Memory analysis framework,
forked from Volatility in 2013.</li>
</ul>

<ul>
<li><a href="https://github.com/sketchymoose/TotalRecall" rel="noopener noreferrer">TotalRecall (⭐49)</a> - Script based
on Volatility for automating various malware analysis tasks.</li>
</ul>

<ul>
<li><a href="https://github.com/volatilityfoundation/volatility" rel="noopener noreferrer">Volatility (⭐7k)</a> - Advanced
memory forensics framework.</li>
</ul>
<h3><p>Windows Artifacts / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/williballenthin/python-evt" rel="noopener noreferrer">python-evt (⭐46)</a> - Python
library for parsing Windows Event Logs.</li>
</ul>

<ul>
<li><a href="http://www.williballenthin.com/registry/" rel="noopener noreferrer">python-registry</a> - Python
library for parsing registry files.</li>
</ul>

<ul>
<li><a href="http://brettshavers.cc/index.php/brettsblog/tags/tag/regripper/" rel="noopener noreferrer">RegRipper</a>
(<a href="https://github.com/keydet89/RegRipper2.8" rel="noopener noreferrer">GitHub</a>) -
Plugin-based registry analysis tool.</li>
</ul>
<h3><p>Storage and Workflow / Other Resources</p>
</h3>
<ul>
<li><a href="https://github.com/sroberts/malwarehouse" rel="noopener noreferrer">Malwarehouse (⭐131)</a> - Store, tag, and
search malware.</li>
</ul>

<ul>
<li><a href="http://viper.li/" rel="noopener noreferrer">Viper</a> - A binary management and analysis framework for
analysts and researchers.</li>
</ul>
<h3><p>Miscellaneous / Other Resources</p>
</h3>
<ul>
<li><a href="https://remnux.org/" rel="noopener noreferrer">REMnux</a> - Linux distribution and docker images for
malware reverse engineering and analysis.</li>
</ul>
<h3><p>Books / Other Resources</p>
</h3>
<ul>
<li><a href="https://amzn.com/dp/0470613033" rel="noopener noreferrer">Malware Analyst's Cookbook and DVD</a> -
Tools and Techniques for Fighting Malicious Code.</li>
</ul>

<ul>
<li><a href="https://amzn.com/dp/1118825098" rel="noopener noreferrer">The Art of Memory Forensics</a> - Detecting
Malware and Threats in Windows, Linux, and Mac Memory.</li>
</ul>

<ul>
<li><a href="https://amzn.com/dp/1593272898" rel="noopener noreferrer">The IDA Pro Book</a> - The Unofficial Guide
to the World's Most Popular Disassembler.</li>
</ul>
<h3><p>Other / Other Resources</p>
</h3>
<ul>
<li><a href="http://honeynet.org/" rel="noopener noreferrer">Honeynet Project</a> - Honeypot tools, papers, and
other resources.</li>
</ul>

<ul>
<li><a href="https://zeltser.com/malicious-software/" rel="noopener noreferrer">Malicious Software</a> - Malware
blog and resources by Lenny Zeltser.</li>
</ul>

<ul>
<li><a href="https://cse.google.com/cse/home?cx=011750002002865445766%3Apc60zx1rliu" rel="noopener noreferrer">Malware Analysis Search</a> -
Custom Google search engine from <a href="https://github.com/rshipp/awesome-malware-analysis/blob/main/README.md/journeyintoir.blogspot.com/" rel="noopener noreferrer">Corey Harrell</a>.</li>
</ul>

<ul>
<li><a href="http://windowsir.blogspot.com/p/malware.html" rel="noopener noreferrer">WindowsIR: Malware</a> - Harlan
Carvey's page on Malware.</li>
</ul>

<ul>
<li><a href="https://www.reddit.com/r/Malware" rel="noopener noreferrer">/r/Malware</a> - The malware subreddit.</li>
</ul>

<ul>
<li><a href="https://www.reddit.com/r/ReverseEngineering" rel="noopener noreferrer">/r/ReverseEngineering</a> -
Reverse engineering subreddit, not limited to just malware.</li>
</ul>

<ul>
<li><a href="https://github.com/ashishb/android-security-awesome" rel="noopener noreferrer">Android Security (⭐7.9k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/enaqx/awesome-pentest" rel="noopener noreferrer">Pentesting (⭐21k)</a></li>
</ul>

<ul>
<li><a href="https://github.com/sbilly/awesome-security" rel="noopener noreferrer">Security (⭐12k)</a></li>
</ul>
]]></content>
    <link rel="alternate" href="https://www.trackawesomelist.com/2015/05/09/"/>
    <summary>99 awesome projects updated on May 09, 2015</summary>
  </entry>
</feed>