Updated 11 months ago

docker-packing-box • Science 54%

Docker image gathering packers and tools for making datasets of packed executables and training machine learning models for packing detection

Updated 11 months ago

https://github.com/csvl/sema • Science 26%

SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create representative signatures based on System Call Dependency graph (SCDG). Those SCDGs can be exploited in machine learning modules to do classification/detection.

Updated 11 months ago

malgraphiq • Science 39%

Transform your malware sandbox reports and execution traces into behavior and category graphs and plot their Windows Behavior Catalog (WBC) behavior identification.

Updated 11 months ago

gview • Science 44%

GView is a cross-platform framework for reverse-engineering. Users can leverage the diverse range of available visualization options to effectively analyze and interpret the information.

Updated 11 months ago

cape-hook-generator • Science 44%

CAPEv2 (capemon) hook skeleton generator (hookdefs) for your malware analysis needs.