30 open-source projects similar to jpcertcc/malconfscan, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best MalConfScan alternative.
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisitio
Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
A multi-platform .Net wrapper library for the native Yara library.
A Yara rule generator for finding related samples and hunting
AI-assisted malware reverse-engineering debugger with ATT&CK, YARA, IOC, JSON, and analyst report output
Yara rule generator using VirusTotal code similarity feature code-similar-to:
Clojure YARA-style pattern matching - malware signatures, hex/ascii/regex patterns
Performs OCR on image files and scans them for matches to YARA rules
Repository that contains a set of purposefully erroneous Yara rules.
Yara integrated software to handle archive file data.
Python 3 tool to parse Yara rules (extension of yarabuilder)
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.
Validates yara rules and tries to repair the broken ones.
Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.
CrowdStrike Feed Management System. CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the Private API system. This framework automatically downloads recent samples, which triggered an alert on the users YARA notification feed.
YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA
Create base64 or XOR encoded variations of a string (or list of strings for base64)
Scan files with Yara and send rule matches to VirusTotal reports as comments