awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to danielbohannon/revoke-obfuscation

Projects sharing features with Revoke Obfuscation

30 open-source projects similar to danielbohannon/revoke-obfuscation, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • security-onion-solutions/security-onionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/security-onion

    3,123View on GitHub↗

    Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

    View on GitHub↗3,123
  • 3lp4tr0n/beaconhunter3lp4tr0n avatar

    3lp4tr0n/BeaconHunter

    516View on GitHub↗

    Behavior based monitoring and hunting tool built in C# leveraging ETW tracing. Blue teamers can use this tool to detect and respond to potential Cobalt Strike beacons. Red teamers can use this tool to research ETW bypasses and discover new processes that behave like beacons.

    C#
    View on GitHub↗516
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0View on GitHub↗
    View on GitHub↗0
  • austin-taylor/flareA

    austin-taylor/flare

    0View on GitHub↗
    View on GitHub↗0
  • ben0xa/powershelldefenseB

    Ben0xA/PowerShellDefense

    0View on GitHub↗
    View on GitHub↗0
  • blueteamlabs/sentinel-attackB

    BlueTeamLabs/sentinel-attack

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • brimsec/brimB

    brimsec/brim

    0View on GitHub↗
    View on GitHub↗0
  • ccob/beaconeyeCCob avatar

    CCob/BeaconEye

    961View on GitHub↗

    BeaconEye scans running processes for active CobaltStrike beacons. When processes are found to be running beacon, BeaconEye will monitor each process for C2 activity.

    C#
    View on GitHub↗961
  • cisagov/sparrowcisagov avatar

    cisagov/Sparrow

    1,430View on GitHub↗

    Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

    PowerShell
    View on GitHub↗1,430
  • clong/detectionlabclong avatar

    clong/DetectionLab

    4,904View on GitHub↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    View on GitHub↗4,904
  • corelight/zeek2escorelight avatar

    corelight/zeek2es

    40View on GitHub↗

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python
    View on GitHub↗40
  • countercept/python-exe-unpackerC

    countercept/python-exe-unpacker

    0View on GitHub↗
    View on GitHub↗0
  • creddefense/creddefenseC

    CredDefense/CredDefense

    0View on GitHub↗
    View on GitHub↗0
  • cyb3rward0g/helkCyb3rWard0g avatar

    Cyb3rWard0g/HELK

    3,926View on GitHub↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    View on GitHub↗3,926
  • airbnb/binaryalertairbnb avatar

    airbnb/binaryalert

    1,450View on GitHub↗

    BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

    Python
    View on GitHub↗1,450
  • damonmohammadbagher/etwprocessmon2D

    DamonMohammadbagher/ETWProcessMon2

    0View on GitHub↗
    View on GitHub↗0
  • denisugarte/powerdriveD

    denisugarte/PowerDrive

    0View on GitHub↗
    View on GitHub↗0
  • emposha/php-shell-detectoremposha avatar

    emposha/PHP-Shell-Detector

    823View on GitHub↗

    Web Shell Detector Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%. By using the latest javascript and css technologies, web shell detector…

    PHP
    View on GitHub↗823
  • endgameinc/eqlE

    endgameinc/eql

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/varnaendgameinc avatar

    endgameinc/varna

    52View on GitHub↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    View on GitHub↗52
  • ernw/hardeningE

    ernw/hardening

    0View on GitHub↗
    View on GitHub↗0
  • fireeye/capafireeye avatar

    fireeye/capa

    6,062View on GitHub↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    View on GitHub↗6,062
  • foxio-llc/logslashF

    FoxIO-LLC/LogSlash

    0View on GitHub↗
    View on GitHub↗0
  • hasherezade/pe-sievehasherezade avatar

    hasherezade/pe-sieve

    3,559View on GitHub↗

    pe-sieve is a set of diagnostic tools for scanning Windows process memory to identify malicious implants, shellcode, and hooks. It functions as an in-memory implant detector, malware unpacker, and process callstack analyzer designed to locate and dump memory patches and injected code from running processes. The project identifies advanced evasion techniques, such as process hollowing and reflective injection, by verifying portable executable structures in memory. It distinguishes itself by analyzing process callstacks to detect anomalies and redirections and by reconstructing executable heade

    C++anti-malwarehookinglibpeconv
    View on GitHub↗3,559
  • hegusung/avsignseekH

    hegusung/AVSignSeek

    0View on GitHub↗
    View on GitHub↗0
  • intelowlproject/intelowlintelowlproject avatar

    intelowlproject/IntelOwl

    4,605View on GitHub↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    View on GitHub↗4,605
  • invoke-ir/uprootI

    Invoke-IR/Uproot

    0View on GitHub↗
    View on GitHub↗0
  • ion28/bluespawnION28 avatar

    ION28/BLUESPAWN

    1,332View on GitHub↗

    An Active Defense and EDR software to empower Blue Teams

    C++active-defenseanti-virusblue-team
    View on GitHub↗1,332
  • 0xd4d/de4dot0xd4d avatar

    0xd4d/de4dot

    7,426View on GitHub↗

    de4dot is a .NET deobfuscator, unpacker, and assembly analysis tool. It is designed to remove obfuscation layers, restore metadata, and simplify bytecode control flow to transform protected binaries back into human-readable code. The project features specialized systems for decrypting strings and constants using both static and dynamic analysis. It identifies specific protection tools through pattern-based detection and strips anti-analysis protections, such as tamper detection and anti-debugging code. The tool provides a suite of reverse engineering capabilities, including binary wrapper un

    C#
    View on GitHub↗7,426