Showing 55 open source projects for "malware analysis"

View related business solutions
  • $300 Free Credits to Build on Google Cloud Icon
    $300 Free Credits to Build on Google Cloud

    New customers can spin up VMs, build with AI, and query data at no cost.

    Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
    Start Free
  • Fully Managed MySQL, PostgreSQL, and SQL Server Icon
    Fully Managed MySQL, PostgreSQL, and SQL Server

    Automatic backups, patching, replication, and failover. Focus on your app, not your database.

    Cloud SQL handles your database ops end to end, so you can focus on your app.
    Try Free
  • 1
    FLARE VM

    FLARE VM

    A collection of software installations scripts for Windows systems

    ...Because security toolchains often clash (DLL versions, signing, privileges), FLARE VM’s packaging handles compatibility issues ahead of time. For investigations involving malware unpacking, sandboxing, static analysis, or code reversing on Windows, the platform dramatically accelerates readiness and consistency across analysts.
    Downloads: 106 This Week
    Last Update:
    See Project
  • 2
    MalwareSourceCode

    MalwareSourceCode

    Collection of malware source code for a variety of platforms

    MalwareSourceCode is a large archival collection of malware-related source code gathered for research and historical reference. The repository organizes material by platform, programming language, malware family, and technical category. Its directories cover Android, Linux, macOS, legacy Windows, Win32, Java, JavaScript, PHP, Perl, Python, Ruby, and other environments. Collections include proof-of-concept samples, older malware families, analysis-related libraries, phishing pages, and web panels. ...
    Downloads: 2 This Week
    Last Update:
    See Project
  • 3
    Hypatia

    Hypatia

    A realtime malware scanner

    Hypatia is a free and open-source malware scanner for Android that aims to provide on-device, real-time scanning with minimal battery and resource impact using signature-based detection inspired by ClamAV style databases. Designed as an Android app, it scans user filesystems and installed applications either on demand or in real time when files are written or renamed, operating completely offline aside from occasional signature database downloads. The project is offered under an AGPL-3.0...
    Downloads: 22 This Week
    Last Update:
    See Project
  • 4
    Al-Khaser

    Al-Khaser

    Public malware techniques used in the wild: Virtual Machine, Emulation

    al-khaser is an open-source proof-of-concept security tool that deliberately implements techniques commonly used by real-world malware to test and evaluate the effectiveness of antivirus and endpoint detection and response (EDR) systems. It’s written in C/C++ and designed to execute a wide range of anti-analysis, anti-debugging, anti-virtualization, timing-based evasion, and sandbox detection routines so security researchers and defenders can see how well their tools detect or ignore these behaviors. ...
    Downloads: 5 This Week
    Last Update:
    See Project
  • Ship Agents Faster Icon
    Ship Agents Faster

    Transform your applications and workflows into powerful agentic systems at global scale.

    Gemini Enterprise Agent Platform lets you rapidly build, scale, govern and optimize production-ready agents grounded in your organization's data. The platform enables developers to build custom or pre-built agents for virtually any use case. New customers get $300 in free credits.
    Get Started Free
  • 5
    Ghidra

    Ghidra

    Ghidra is a software reverse engineering (SRE) framework

    ...It supports a wide array of instruction sets and executable formats, offering features such as decompilation, disassembly, scripting, and interactive graphing. Designed for security researchers and analysts, Ghidra provides a robust environment for understanding malware, auditing code, and performing software forensics. It includes both GUI-based and headless analysis modes.
    Downloads: 1,397 This Week
    Last Update:
    See Project
  • 6
    malware_training_vol1

    malware_training_vol1

    Materials for Windows Malware Analysis training (volume 1)

    malware_training_vol1 is an educational repository for Windows malware analysis training. It is designed to help learners understand common malware techniques through programming, reverse engineering, and Windows internals concepts. The material focuses on analysis rather than active misuse, making it useful for students, security researchers, and defenders building foundational skills. It includes exercises that explain how malware-like behaviors can be recognized and studied in a controlled lab context. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 7
    IntelOwl

    IntelOwl

    Centralized platform for automated threat intelligence analysis

    ...These plugins can collect data from external intelligence platforms or generate insights using internal analysis tools such as YARA or static malware analyzers.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 8
    SSH-MITM

    SSH-MITM

    Server for security audits supporting public key authentication

    ssh man-in-the-middle (ssh-mitm) server for security audits supporting publickey authentication, session hijacking and file manipulation. SSH-MITM is a man in the middle SSH Server for security audits and malware analysis. Password and publickey authentication are supported and SSH-MITM is able to detect, if a user is able to login with publickey authentication on the remote server. This allows SSH-MITM to accept the same key as the destination server. If publickey authentication is not possible, the authentication will fall back to password-authentication. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 9
    Detect It Easy

    Detect It Easy

    Program for determining types of files for Windows, Linux and MacOS

    Detect It Easy (DiE) is a tool for determining the type and internal features of binary and other file formats. It is widely used by malware analysts, digital forensics investigators, reverse engineers, and security researchers to quickly inspect unknown files and infer their type, architecture, compiler/packer used, and internal structure. DiE supports a large variety of file formats — from common executables (Windows PE, Linux ELF, macOS Mach-O) to archives, mobile packages (APK, IPA), legacy binaries, compressed or packed files, and more — making it a versatile first step in analysis or triage workflows. ...
    Downloads: 131 This Week
    Last Update:
    See Project
  • Go from Code to Production URL in Seconds Icon
    Go from Code to Production URL in Seconds

    Cloud Run deploys apps in any language instantly. Scales to zero. Pay only when code runs.

    Skip the Kubernetes configs. Cloud Run handles HTTPS, scaling, and infrastructure automatically. Two million requests free per month.
    Try it free
  • 10
    MalbianLinux

    MalbianLinux

    GNU/Linux Distribution for Malware Analysis and Reverse Engineering.

    Malbian is a Light-weight Debian Based GNU/Linux Distribution for Malware Analysis and Reverse Engineering designed to aid the user in both Static and Dynamic analysis of malware samples. 100% Free to use and distribute. About: https://github.com/MalbianLinux Installation Guide in: https://github.com/MalbianLinux/Malbian-ISOs/
    Downloads: 1 This Week
    Last Update:
    See Project
  • 11
    A modular, lightweight security research VM for OSINT, OPSEC, malware analysis, and forensics.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 12
    LSG - Linux SecureGuard

    LSG - Linux SecureGuard

    Professional antivirus solution developed for Linux systems.

    Professional antivirus solution developed for Linux systems. Protects your Linux servers and desktop systems with real-time protection, network security and advanced threat detection features.
    Downloads: 11 This Week
    Last Update:
    See Project
  • 13
    Thunderbird Anti Virus v3.5

    Thunderbird Anti Virus v3.5

    Thunderbird Anti Virus Free Scanner v3.5

    Thunderbird Anti-Virus v3.4 | Professional Security & Network Shield Thunderbird Anti-Virus v3.4 is a high-performance security suite engineered for users who demand elite protection without system degradation. Built on a sophisticated Heuristic Analysis Engine, it delivers surgical precision in identifying malware, ransomware, and volatile memory threats. This version introduces the Integrated Network Shield, a professional-grade firewall providing real-time perimeter control. Complemented by the new Live I/O Telemetry, users can monitor data throughput (KB/s) in real-time, identifying anomalous activity instantly. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 14
    malware-samples

    malware-samples

    A collection of malware samples and relevant dissection information

    This repo is a public collection of malware samples and related dissection/analysis information, maintained by InQuest. It gathers various kinds of malicious artifacts, executables, scripts, macros, obfuscated documents, etc., with metadata (e.g., VirusTotal reports), file carriers, and sample hashes. It’s intended for malware analysts/researchers to help study how malware works, how they are delivered, and how it evolves.
    Downloads: 222 This Week
    Last Update:
    See Project
  • 15
    Anya

    Anya

    A malware analysis platform built in Rust

    Anya is a privacy-first static malware analysis tool for Windows, Linux, and macOS. It combines PE, ELF, and Mach-O binary analysis with MITRE ATT&CK mapping, confidence-based risk scoring, and plain-English explanations. All offline, with zero network calls. Built for analysts and students alike, it ships as both a CLI and a desktop GUI.
    Downloads: 4 This Week
    Last Update:
    See Project
  • 16
    HydraDragonAntivirus

    HydraDragonAntivirus

    Open Source Antivirus/XDR for Windows operating system

    Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X, machine learning AI, behavioral analysis, Unpacker, Deobfuscator, Decompiler, website signatures, Ghidra, Suricata, Sigma, Kernel, Hypervisior based protection and much more than you can imagine.
    Downloads: 21 This Week
    Last Update:
    See Project
  • 17
    X-Ray of Death
    A professional PE (Portable Executable) analysis and modification tool for Windows executables and DLLs.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 18

    url-checker-php-sdk

    Official PHP SDK for the EmailVeritas URL Checker API

    The EmailVeritas URL Checker PHP SDK provides real-time phishing and malicious link detection through the official EmailVeritas API. It enables developers to classify and analyze URLs directly from PHP applications using simple methods for URL Lookup and URL Scan. Lightweight and dependency-free, the SDK performs redirect-chain, WHOIS, and HTML metadata analysis. Composer support makes integration seamless with PSR-4 autoloading. Ideal for CRMs, contact forms, and security...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 19
    Thunderbird Anti Virus 3.4

    Thunderbird Anti Virus 3.4

    Thunderbird Anti Virus Free Scanner v3.4

    ...Designed with a focus on resource efficiency and transparent operations, Thunderbird AV provides a robust alternative to bloated security suites, offering a surgical approach to malware detection and system auditing. The v3.4 architecture integrates an advanced Heuristic Analysis Engine capable of deep-memory inspection and multi-tier file system scanning. This version debuts the Integrated Network Shield, a native firewall module that allows for instantaneous perimeter control. Complementing this is the Live I/O Analytics layer, which provides real-time telemetry of network throughput, allowing administrators and power users to identify anomalous data patterns as they occur.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 20

    Thunderbird Anti Virus 3.2

    Thunderbird Anti Virus Free Scanner v3.2

    Thunderbird Anti-Virus v3.2 – Proactive Digital Guard Thunderbird Anti-Virus v3.2 represents the next evolution in desktop security, offering a streamlined yet uncompromising shield against modern cyber threats. Designed for users who demand high-level protection without the system bloat, version 3.2 introduces enhanced heuristic analysis and a refined scanning engine optimized for Windows 10 and 11. Core Defense Features: Real-Time Threat Detection: Monitors system activity to block malware, ransomware, and spyware before they can execute. Deep System Scanning: A versatile engine that targets hidden trojans and persistent threats in the deepest layers of your storage. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 21

    Thunderbird Free Scanner

    Thunderbird Anti Virus Online Free Scanner

    ...Included Scan Options Thunder Anti-Virus Free Scanner includes a comprehensive system scan. This option allows you to thoroughly scan your entire system, checking memory, hard drives, and connected devices for a wide range of threats, including malware, viruses, and trojans. You can also opt for a targeted folder scan, ideal when you need a faster analysis. You can select a specific folder or directory for a focused scan. This feature is ideal for users who want to check specific locations without scanning the entire system.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 22
    readpe

    readpe

    The PE file analysis toolkit

    readpe (formerly known as pev) is a multiplatform toolkit to work with PE (Portable Executable) binaries. Its main goal is to provide feature-rich tools for properly analyze binaries with a strong focus on suspicious ones.
    Downloads: 23 This Week
    Last Update:
    See Project
  • 23
    VX-API

    VX-API

    Collection of various malicious functionality

    VX-API is a research-oriented collection of Windows-focused code that demonstrates low-level techniques commonly studied in malware analysis and red-team development. It is organized as a Visual Studio solution so related functions and dependencies can be explored together. The repository covers areas such as anti-debugging, cryptographic helpers, fingerprinting, process creation, process injection, networking, library loading, and string handling. It also includes examples involving shellcode execution, privilege-related behavior, and Windows internals. ...
    Downloads: 9 This Week
    Last Update:
    See Project
  • 24
    DracOS GNU/Linux Remastered
    What is DracOS GNU/Linux Remastered ? DracOS GNU/Linux Remastered ( https://github.com/dracos-linux ) is the Linux operating system from Indonesia , open source is built based on Debian live project under the protection of the GNU General Public License v3.0. This operating system is one variant of Linux distributions, which is used to perform security testing (penetration testing). Dracos linux in Arm by hundreds hydraulic pentest, forensics and reverse engineering. Use a GUI-based...
    Downloads: 18 This Week
    Last Update:
    See Project
  • 25
     Abdal Header Analyzer

    Abdal Header Analyzer

    analyzing site and web server headers

    Abdal Header Analyzer is a software for analyzing site and web server headers. As you know, headers contain information that security experts and hackers use to analyze targets.
    Downloads: 0 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • 3
  • Next