Showing 71 open source projects for "malware analysis"

View related business solutions
  • $300 Free Credits to Build on Google Cloud Icon
    $300 Free Credits to Build on Google Cloud

    New customers can spin up VMs, build with AI, and query data at no cost.

    Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
    Start Free
  • Build Agents and Models on One Platform Icon
    Build Agents and Models on One Platform

    Everything you need to build production-ready agents and models. Access 200+ Google and third-party AI models and tools.

    Gemini Enterprise Agent Platform is Google Cloud's comprehensive platform for developers to build, scale, govern, and optimize agents and models. Choose from Google's most advanced models and third-party models like Anthropic's Claude Model Family.
    Try It Free
  • 1
    PySilon Malware

    PySilon Malware

    Advanced RAT written in Python language

    ...The repository’s own disclaimer frames the material as educational while placing responsibility on the user. It is best categorized as malware for defensive analysis, threat research, and understanding abuse patterns, not as a normal administration tool.
    Downloads: 5 This Week
    Last Update:
    See Project
  • 2
    FLARE VM

    FLARE VM

    A collection of software installations scripts for Windows systems

    ...Because security toolchains often clash (DLL versions, signing, privileges), FLARE VM’s packaging handles compatibility issues ahead of time. For investigations involving malware unpacking, sandboxing, static analysis, or code reversing on Windows, the platform dramatically accelerates readiness and consistency across analysts.
    Downloads: 106 This Week
    Last Update:
    See Project
  • 3
    PE-bear

    PE-bear

    Portable Executable reversing tool with a friendly GUI

    PE-bear is a multiplatform reversing tool for inspecting Windows Portable Executable files. It is designed to give malware analysts and reverse engineers a fast first view of a PE file’s structure. The tool can handle malformed PE files, which is important when analyzing packed, damaged, or intentionally manipulated binaries. It provides a graphical interface for exploring headers, sections, imports, resources, strings, and other PE internals. PE-bear also includes analysis conveniences such as hashes, signatures, and searchable string views. ...
    Downloads: 134 This Week
    Last Update:
    See Project
  • 4
    MalwareSourceCode

    MalwareSourceCode

    Collection of malware source code for a variety of platforms

    MalwareSourceCode is a large archival collection of malware-related source code gathered for research and historical reference. The repository organizes material by platform, programming language, malware family, and technical category. Its directories cover Android, Linux, macOS, legacy Windows, Win32, Java, JavaScript, PHP, Perl, Python, Ruby, and other environments. Collections include proof-of-concept samples, older malware families, analysis-related libraries, phishing pages, and web panels. ...
    Downloads: 2 This Week
    Last Update:
    See Project
  • Build Securely on Azure with Proven Frameworks Icon
    Build Securely on Azure with Proven Frameworks

    Lay a foundation for success with Tested Reference Architectures developed by Fortinet’s experts. Learn more in this white paper.

    Moving to the cloud brings new challenges. How can you manage a larger attack surface while ensuring great network performance? Turn to Fortinet’s Tested Reference Architectures, blueprints for designing and securing cloud environments built by cybersecurity experts. Learn more and explore use cases in this white paper.
    Download Now
  • 5
    Kudu

    Kudu

    Free Windows, Mac and Linux cleaner, scanner, and more

    Kudu is a free, open source system maintenance and security application for Windows, macOS, and Linux. It removes temporary files, logs, browser caches, abandoned application data, and other unnecessary content to recover disk space. Its security tools include malware scanning, heuristic analysis, secure file deletion, and controls for Windows privacy settings. Users can analyze disk usage, manage startup programs, uninstall software, remove bloatware, clean stale drivers, and update multiple applications in bulk. Real-time monitoring displays processor, memory, storage, network, and drive health information. ...
    Downloads: 54 This Week
    Last Update:
    See Project
  • 6
    Portable Executable Parser

    Portable Executable Parser

    lightweight Go package to parse, analyze and extract metadata

    Saferwall PE is a lightweight Go package for parsing, analyzing, and extracting metadata from Portable Executable (PE) binaries. Designed with malware analysis in mind, it is robust against malformed PE files and provides detailed insights into executable structures.​
    Downloads: 2 This Week
    Last Update:
    See Project
  • 7
    Al-Khaser

    Al-Khaser

    Public malware techniques used in the wild: Virtual Machine, Emulation

    al-khaser is an open-source proof-of-concept security tool that deliberately implements techniques commonly used by real-world malware to test and evaluate the effectiveness of antivirus and endpoint detection and response (EDR) systems. It’s written in C/C++ and designed to execute a wide range of anti-analysis, anti-debugging, anti-virtualization, timing-based evasion, and sandbox detection routines so security researchers and defenders can see how well their tools detect or ignore these behaviors. ...
    Downloads: 5 This Week
    Last Update:
    See Project
  • 8
    Sogen

    Sogen

    Windows User Space Emulator

    ...Unlike traditional emulators that reimplement full operating system APIs, Sogen works closer to the kernel boundary by intercepting and emulating system calls, allowing it to leverage native system libraries while maintaining granular control. This approach makes it particularly valuable for advanced use cases such as malware analysis, reverse engineering, and DRM research, where precise observation and manipulation of execution flow are critical. The emulator supports multiple backends, including Unicorn Engine and Hyper-V, enabling flexible deployment depending on performance or accuracy requirements. It also includes robust support for loading Portable Executable (PE) files, including proper handling of relocations, thread-local storage, and memory mapping.
    Downloads: 13 This Week
    Last Update:
    See Project
  • 9
    Ghidra

    Ghidra

    Ghidra is a software reverse engineering (SRE) framework

    ...It supports a wide array of instruction sets and executable formats, offering features such as decompilation, disassembly, scripting, and interactive graphing. Designed for security researchers and analysts, Ghidra provides a robust environment for understanding malware, auditing code, and performing software forensics. It includes both GUI-based and headless analysis modes.
    Downloads: 1,397 This Week
    Last Update:
    See Project
  • Fully Managed MySQL, PostgreSQL, and SQL Server Icon
    Fully Managed MySQL, PostgreSQL, and SQL Server

    Automatic backups, patching, replication, and failover. Focus on your app, not your database.

    Cloud SQL handles your database ops end to end, so you can focus on your app.
    Try Free
  • 10
    hollows_hunter

    hollows_hunter

    Recognizes and dumps a variety of potentially malicious implants

    Hollows Hunter is a command-line malware analysis tool based on the PE-sieve passive memory scanner. It scans running processes, or even the full system, to identify potentially malicious implants. The tool can recognize and dump suspicious artifacts such as replaced PEs, injected PEs, shellcode, hooks, and in-memory patches. Unlike PE-sieve’s more process-specific workflow, Hollows Hunter can select targets using broader criteria such as process IDs, process names, or creation time. ...
    Downloads: 3 This Week
    Last Update:
    See Project
  • 11
    malware_training_vol1

    malware_training_vol1

    Materials for Windows Malware Analysis training (volume 1)

    malware_training_vol1 is an educational repository for Windows malware analysis training. It is designed to help learners understand common malware techniques through programming, reverse engineering, and Windows internals concepts. The material focuses on analysis rather than active misuse, making it useful for students, security researchers, and defenders building foundational skills. It includes exercises that explain how malware-like behaviors can be recognized and studied in a controlled lab context. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 12
    IntelOwl

    IntelOwl

    Centralized platform for automated threat intelligence analysis

    ...These plugins can collect data from external intelligence platforms or generate insights using internal analysis tools such as YARA or static malware analyzers.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 13
    LIEF

    LIEF

    LIEF - Library to Instrument Executable Formats (C++, Python, Rust)

    LIEF (Library to Instrument Executable Formats) is a cross-platform library that enables parsing, modifying, and abstracting executable formats such as ELF, PE, and Mach-O. It's widely used in reverse engineering and binary analysis.​
    Downloads: 1 This Week
    Last Update:
    See Project
  • 14
    LitterBox

    LitterBox

    A secure sandbox environment for malware developers and red teamers

    LitterBox is a controlled malware-analysis and payload-testing sandbox aimed at red teams who need to validate evasions and behaviors before deployment. It provides an isolated environment to exercise payloads against modern detection stacks, verify signatures and heuristics, and observe runtime characteristics without leaking binaries to third-party vendors. The README frames typical use cases: testing evasion, validating detections, analyzing behavior, and keeping sensitive tooling in-house. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 15
    Capstone

    Capstone

    Capstone disassembly/disassembler framework

    Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community. Created by Nguyen Anh Quynh, then developed and maintained by a small community, Capstone offers some unparalleled features. Support multiple hardware architectures: ARM, ARM64 (ARMv8), Ethereum VM, M68K, Mips, MOS65XX, PPC, Sparc, SystemZ, TMS320C64X, M680X, XCore and X86 (including X86_64). Having clean/simple/lightweight/intuitive...
    Downloads: 8 This Week
    Last Update:
    See Project
  • 16
    SSH-MITM

    SSH-MITM

    Server for security audits supporting public key authentication

    ssh man-in-the-middle (ssh-mitm) server for security audits supporting publickey authentication, session hijacking and file manipulation. SSH-MITM is a man in the middle SSH Server for security audits and malware analysis. Password and publickey authentication are supported and SSH-MITM is able to detect, if a user is able to login with publickey authentication on the remote server. This allows SSH-MITM to accept the same key as the destination server. If publickey authentication is not possible, the authentication will fall back to password-authentication. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 17
    Detect It Easy

    Detect It Easy

    Program for determining types of files for Windows, Linux and MacOS

    Detect It Easy (DiE) is a tool for determining the type and internal features of binary and other file formats. It is widely used by malware analysts, digital forensics investigators, reverse engineers, and security researchers to quickly inspect unknown files and infer their type, architecture, compiler/packer used, and internal structure. DiE supports a large variety of file formats — from common executables (Windows PE, Linux ELF, macOS Mach-O) to archives, mobile packages (APK, IPA), legacy binaries, compressed or packed files, and more — making it a versatile first step in analysis or triage workflows. ...
    Downloads: 131 This Week
    Last Update:
    See Project
  • 18
    x64dbg

    x64dbg

    An open-source x64/x32 debugger for windows

    An open-source binary debugger for Windows, aimed at malware analysis and reverse engineering of executables you do not have the source code for. There are many features available and a comprehensive plugin system to add your own. Fully customizable color scheme. Dynamically recognize modules and strings. Import reconstructor integrated (Scylla). Fast disassembler (Zydis). User database (JSON) for comments, labels, bookmarks, etc.
    Downloads: 81 This Week
    Last Update:
    See Project
  • 19
    MemProcFS Analyzer

    MemProcFS Analyzer

    Automated Forensic Analysis of Windows Memory Dumps for DFIR

    ...It emphasizes automation and reproducibility: parsers can be chained, results exported, and reports templated to fit incident workflows. Because memory contains transient but critical traces of running malware or misuse, the project focuses on robust parsing in the face of corruption and mismatched OS versions.
    Downloads: 8 This Week
    Last Update:
    See Project
  • 20
    UTMStack

    UTMStack

    Customizable SIEM and XDR powered by Real-Time correlation

    Welcome to the UTMStack open-source project! UTMStack is a unified threat management platform that merges SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) technologies. Our unique approach allows real-time correlation of log data, threat intelligence, and malware activity patterns from multiple sources, enabling the identification and halting of complex threats that use stealthy techniques. UTMStack stands out in threat prevention by surpassing the...
    Downloads: 3 This Week
    Last Update:
    See Project
  • 21
    DEVIL FISH

    DEVIL FISH

    Windows application for analyzing Portable Executable (PE) files.

    ...It provides information about the file structure, security features, indicators of compromise, and other characteristics that may be useful during reverse engineering, malware analysis, or general security research.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 22
    XPEViewer

    XPEViewer

    PE file viewer/editor for Windows, Linux and MacOS

    XPEViewer is a cross-platform viewer and editor for Microsoft Portable Executable files used by Windows applications. It is designed for developers, malware analysts, and reverse engineers who need to inspect executable structures in detail. The application combines PE parsing with tools for examining binary data, disassembly, symbols, regions, entropy, and memory layout. Integrated hexadecimal viewing and editing provide direct access to raw file contents. The project also incorporates signature scanning, extraction, unpacking, and related analysis components from the developer's wider tool ecosystem. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 23
    APKdevastate

    APKdevastate

    Advanced analysis software for APK payloads created by RATs.

    APKdevastate is a powerful Windows application designed to analyze Android APK files for security risks, malware signatures, and suspicious behaviors. The tool helps identify potentially malicious applications by examining permissions, certificate information, and known Remote Access Trojan (RAT) signatures.
    Downloads: 1 This Week
    Last Update:
    See Project
  • 24
    Thunderbird Anti Virus v3.5

    Thunderbird Anti Virus v3.5

    Thunderbird Anti Virus Free Scanner v3.5

    Thunderbird Anti-Virus v3.4 | Professional Security & Network Shield Thunderbird Anti-Virus v3.4 is a high-performance security suite engineered for users who demand elite protection without system degradation. Built on a sophisticated Heuristic Analysis Engine, it delivers surgical precision in identifying malware, ransomware, and volatile memory threats. This version introduces the Integrated Network Shield, a professional-grade firewall providing real-time perimeter control. Complemented by the new Live I/O Telemetry, users can monitor data throughput (KB/s) in real-time, identifying anomalous activity instantly. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 25
    malware-samples

    malware-samples

    A collection of malware samples and relevant dissection information

    This repo is a public collection of malware samples and related dissection/analysis information, maintained by InQuest. It gathers various kinds of malicious artifacts, executables, scripts, macros, obfuscated documents, etc., with metadata (e.g., VirusTotal reports), file carriers, and sample hashes. It’s intended for malware analysts/researchers to help study how malware works, how they are delivered, and how it evolves.
    Downloads: 222 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • 3
  • Next