awesome-malware-analysis/README.md

111 lines
3.4 KiB
Markdown
Raw Normal View History

# Awesome Malware Analysis
A curated list of awesome malware analysis tools and resources. Inspired by
[awesome-python](https://github.com/vinta/awesome-python) and
[awesome-php](https://github.com/ziadoz/awesome-php).
- [Awesome Malware Analysis](#awesome-malware-analysis)
- [Malware Collection](#malware-collection)
- [Anonymizers](#anonymizers)
- [Honeypots](#honeypots)
- [Malware Corpora](#malware-corpora)
- [Detection and Classification](#detection-and-classification)
2015-05-08 22:35:17 -06:00
- [Online Scanners and Sandboxes](#online-scanners-and-sandboxes)
- [Domain Analysis](#domain-analysis)
2015-05-08 22:41:41 -06:00
- [Memory Forensics](#memory-forensics)
2015-05-08 22:31:31 -06:00
- [Miscellaneous](#miscellaneous)
- [Resources](#resources)
- [Books](#books)
- [Twitter](#twitter)
2015-05-08 21:51:11 -06:00
- [Other](#other)
- [Related Awesome Lists](#related-awesome-lists)
- [Contributing](#contributing)
---
## Malware Collection
### Anonymizers
*Web traffic anonymizers for analysts.*
2015-05-08 22:23:12 -06:00
* [Anonymouse.org](http://anonymouse.org/) - A free, web based anonymizer.
* [OpenVPN](https://openvpn.net/) - VPN software and hosting solutions.
* [Privoxy](http://www.privoxy.org/) - An open source proxy server with some
privacy features.
* [Tor](https://www.torproject.org/) - The Onion Router, for browsing the web
without leaving traces of the client IP.
2015-05-08 21:51:11 -06:00
### Honeypots
2015-05-08 22:24:53 -06:00
*Trap and collect your own samples.*
2015-05-08 21:51:11 -06:00
### Malware Corpora
2015-05-08 22:24:53 -06:00
*Malware samples collected for analysis.*
2015-05-08 21:51:11 -06:00
* [Contagio](http://contagiodump.blogspot.com/) - A collection of recent
malware samples and analyses.
## Detection and Classification
*Antivirus and other malware identification tools*
* [ClamAV](http://www.clamav.net/index.html) - Open source antivirus engine.
* [YARA](https://plusvic.github.io/yara/) - Pattern matching tool for
analysts.
2015-05-08 22:35:17 -06:00
## Online Scanners and Sandboxes
* [Jotti]() - Free online multi-AV scanner.
* [Malwr]() - Free analysis with an online Cuckoo Sandbox instance.
2015-05-08 22:35:53 -06:00
* [VirusTotal](https://www.virustotal.com/) - Free online analysis of malware
samples and URLs
2015-05-08 22:35:17 -06:00
2015-05-08 22:41:41 -06:00
## Memory Forensics
*Tools for dissecting malware in memory images or running systems.*
2015-05-08 22:41:41 -06:00
* [FindAES](https://jessekornblum.livejournal.com/269749.html) - Find AES
encryption keys in memory.
* [Rekall](http://www.rekall-forensic.com/) - Memory analysis framework,
forked from Volatility in 2013.
* [TotalRecall](https://github.com/sketchymoose/TotalRecall) - Script based
on Volatility for automating various malware analysis tasks.
* [Volatility](https://github.com/volatilityfoundation/volatility) - Advanced
memory forensics framework.
2015-05-08 22:42:55 -06:00
* [WinDbg](https://msdn.microsoft.com/en-us/windows/hardware/hh852365) - Live
memory inspection and kernel debugging for Windows systems.
2015-05-08 22:41:41 -06:00
## Domain Analysis
*Inspect domains and IP addresses.*
* [Dig](http://networking.ringofsaturn.com/) - Free online dig and other
network tools.
* [Whois](http://whois.domaintools.com/) - DomainTools free online whois
search.
2015-05-08 22:31:31 -06:00
## Miscellaneous
* [REMnux](https://remnux.org/) - Linux distribution and docker images for
malware reverse engineering and analysis.
2015-05-08 21:51:11 -06:00
# Resources
## Books
## Twitter
## Other
# Related Awesome Lists
* [Android Security](https://github.com/ashishb/android-security-awesome)
* [Pentesting](https://github.com/enaqx/awesome-pentest)
* [Security](https://github.com/sbilly/awesome-security)
# [Contributing](CONTRIBUTING.md)
Pull requests and issues with suggestions are welcome!