Automated static analysis tools for binary programs
capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
Malware Analysis Tool using Function Level Fuzzy Hashing
الميزات الرئيسية لـ dynetics/malfunction هي: Detection and Classification.
تشمل البدائل مفتوحة المصدر لـ dynetics/malfunction: cmu-sei/pharos — Automated static analysis tools for binary programs. emersonelectricco/fsf — File Scanning Framework. fireeye/capa — capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities… gleblanc1783/3c8e6b379fa9d646d401b96ab5c7877f. guelfoweb/peframe — PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office… airbnb/binaryalert — BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.