awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

23 مستودعات

Awesome GitHub RepositoriesDetection and Classification

Tools for identifying, scanning, and analyzing suspicious files.

Explore 23 awesome GitHub repositories matching part of an awesome list · Detection and Classification. Refine with filters or upvote what's useful.

Awesome Detection and Classification GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • horsicq/detect-it-easyالصورة الرمزية لـ horsicq

    horsicq/Detect-It-Easy

    10,266عرض على GitHub↗

    Detect-It-Easy is a binary file identifier and analysis toolkit designed to determine file formats, compilers, and packers. It functions as a binary file identifier that utilizes signature matching and heuristic analysis to identify executable and archive formats. The project includes a custom file signature engine and a scriptable rule system for defining and applying detection logic to identify specific binary patterns. It features specialized detectors for Android packages, such as APK and DEX files, and a malware packer detector to identify protections, obfuscators, and virus families. T

    Identifies file types, compilers, and linkers.

    JavaScriptbinary-analysisdebuggerdetect
    عرض على GitHub↗10,266
  • fireeye/capaالصورة الرمزية لـ fireeye

    fireeye/capa

    6,062عرض على GitHub↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Detects capabilities and behaviors in executable files.

    Python
    عرض على GitHub↗6,062
  • neo23x0/lokiالصورة الرمزية لـ Neo23x0

    Neo23x0/Loki

    3,763عرض على GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Host-based scanner for detecting known IOCs.

    Python
    عرض على GitHub↗3,763
  • gurnec/hashcheckالصورة الرمزية لـ gurnec

    gurnec/HashCheck

    2,046عرض على GitHub↗

    HashCheck Shell Extension for Windows with added SHA2, SHA3, and multithreading; originally from code.kliu.org

    Windows shell extension for computing file hashes.

    C
    عرض على GitHub↗2,046
  • neo23x0/yargenالصورة الرمزية لـ Neo23x0

    Neo23x0/yarGen

    1,796عرض على GitHub↗

    yarGen is a generator for YARA rules

    Generates YARA rules from malware samples.

    Python
    عرض على GitHub↗1,796
  • cmu-sei/pharosالصورة الرمزية لـ cmu-sei

    cmu-sei/pharos

    1,708عرض على GitHub↗

    Automated static analysis tools for binary programs

    Generates YARA signatures for functions within executables.

    C++
    عرض على GitHub↗1,708
  • quark-engine/quark-engineالصورة الرمزية لـ quark-engine

    quark-engine/quark-engine

    1,687عرض على GitHub↗

    Scoring system for Android malware based on obfuscation analysis.

    Python
    عرض على GitHub↗1,687
  • airbnb/binaryalertالصورة الرمزية لـ airbnb

    airbnb/binaryalert

    1,450عرض على GitHub↗

    BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

    Serverless pipeline for scanning files using YARA rules.

    Python
    عرض على GitHub↗1,450
  • justicerage/manalyzeالصورة الرمزية لـ JusticeRage

    JusticeRage/Manalyze

    1,124عرض على GitHub↗

    A static analyzer for PE executables.

    Static analysis tool for PE executables.

    YARA
    عرض على GitHub↗1,124
  • jessek/hashdeepالصورة الرمزية لـ jessek

    jessek/hashdeep

    781عرض على GitHub↗

    This is md5deep, a set of cross-platform tools to compute hashes, or message digests, for any number of files while optionally recursively digging through the directory structure. It can also take a list of known hashes and display the filenames of input files whose hashes either do or do not…

    Computes multiple hash digests for file verification.

    C++
    عرض على GitHub↗781
  • guelfoweb/peframeالصورة الرمزية لـ guelfoweb

    guelfoweb/peframe

    628عرض على GitHub↗

    PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

    Performs static analysis on PE files and Office documents.

    YARA
    عرض على GitHub↗628
  • mitre/multiscannerالصورة الرمزية لـ mitre

    mitre/multiscanner

    622عرض على GitHub↗

    Modular file scanning/analysis framework

    Modular framework for file scanning and analysis.

    Python
    عرض على GitHub↗622
  • horsicq/nauz-file-detectorالصورة الرمزية لـ horsicq

    horsicq/Nauz-File-Detector

    574عرض على GitHub↗

    Linker/Compiler/Tool detector for Windows, Linux and MacOS.

    Detects compilers and linkers for various operating systems.

    C++
    عرض على GitHub↗574
  • katjahahn/portexالصورة الرمزية لـ katjahahn

    katjahahn/PortEx

    532عرض على GitHub↗

    Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

    Java library for analyzing PE files and malformations.

    Scala
    عرض على GitHub↗532
  • emersonelectricco/fsfالصورة الرمزية لـ EmersonElectricCo

    EmersonElectricCo/fsf

    294عرض على GitHub↗

    File Scanning Framework

    Modular solution for recursive file scanning.

    Python
    عرض على GitHub↗294
  • hiddenillusion/analyzepeالصورة الرمزية لـ hiddenillusion

    hiddenillusion/AnalyzePE

    210عرض على GitHub↗

    Wraps around various tools and provides some additional checks/information to produce a centralized report of a PE file.

    Wrapper for reporting on Windows PE file characteristics.

    Python
    عرض على GitHub↗210
  • dynetics/malfunctionالصورة الرمزية لـ Dynetics

    Dynetics/Malfunction

    192عرض على GitHub↗

    Malware Analysis Tool using Function Level Fuzzy Hashing

    Compares malware samples at the function level.

    Python
    عرض على GitHub↗192
  • korelogicsecurity/mastiffالصورة الرمزية لـ KoreLogicSecurity

    KoreLogicSecurity/mastiff

    185عرض على GitHub↗

    Malware static analysis framework

    Framework for automated static analysis.

    Python
    عرض على GitHub↗185
  • rjhansen/nsrllookupالصورة الرمزية لـ rjhansen

    rjhansen/nsrllookup

    115عرض على GitHub↗

    Checks with NSRL RDS servers looking for for hash matches

    Queries NIST's software reference library for file hashes.

    C++
    عرض على GitHub↗115
  • sooshie/packeridالصورة الرمزية لـ sooshie

    sooshie/packerid

    50عرض على GitHub↗

    Fork of packerid.py

    Cross-platform tool for identifying file packers.

    Python
    عرض على GitHub↗50
السابق12التالي
  1. Home
  2. Part of an Awesome List
  3. Developer Tools
  4. Detection and Classification