awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to maliceio/malice

Projects sharing features with Malice

30 open-source projects similar to maliceio/malice, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    View on GitHub↗6,360
  • secretsquirrel/recomposersecretsquirrel avatar

    secretsquirrel/recomposer

    132View on GitHub↗

    Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

    Python
    View on GitHub↗132
  • nbeede/boomboxnbeede avatar

    nbeede/BoomBox

    239View on GitHub↗

    Automatic deployment of Cuckoo Sandbox malware lab using Packer and Vagrant

    PowerShell
    View on GitHub↗239

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • kevoreilly/capev2kevoreilly avatar

    kevoreilly/CAPEv2

    3,284View on GitHub↗

    Malware Configuration And Payload Extraction

    Python
    View on GitHub↗3,284
  • f-secure/seeF-Secure avatar

    F-Secure/see

    822View on GitHub↗

    Sandboxed Execution Environment

    Python
    View on GitHub↗822
  • rurik/noribenRurik avatar

    Rurik/Noriben

    1,273View on GitHub↗

    Noriben - Portable, Simple, Malware Analysis Sandbox

    Python
    View on GitHub↗1,273
  • rieck/malheurrieck avatar

    rieck/malheur

    374View on GitHub↗

    A Tool for Automatic Analysis of Malware Behavior

    C
    View on GitHub↗374
  • tklengyel/drakvuftklengyel avatar

    tklengyel/drakvuf

    1,208View on GitHub↗
    C++introspectionmalware-analysisvirtualization
    View on GitHub↗1,208
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu avatar

    zhuifengshaonianhanlu/pikachu

    4,421View on GitHub↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    View on GitHub↗4,421
  • lionsec/katoolinLionSec avatar

    LionSec/katoolin

    5,302View on GitHub↗

    Katoolin is a Debian software repository manager and security toolset automator. It functions as a script to automate the addition of repositories and the installation of security tools from Kali Linux onto other Debian-based systems. The project focuses on automating the deployment of penetration testing and forensics software. It provides a method for managing third-party software sources and provisioning security labs with tools for network and system testing without requiring a full operating system installation. The tool includes an interactive command line interface for navigating tool

    Python
    View on GitHub↗5,302
  • attackiq/detectiqAttackIQ avatar

    AttackIQ/DetectIQ

    121View on GitHub↗

    DetectIQ is an AI-powered security rule management platform that helps create, analyze, and optimize detection rules across multiple security platforms. It can be used with the provided UI, or just with Python scripts using the self contained detectiq/core module. See examples in the examples…

    Python
    View on GitHub↗121
  • advanced-threat-research/iocsadvanced-threat-research avatar

    advanced-threat-research/IOCs

    83View on GitHub↗

    Repository containing IOCs, CSV and MISP JSON from our blogs

    HTML
    View on GitHub↗83
  • azr43lkn1ght/dfir-labsAzr43lKn1ght avatar

    Azr43lKn1ght/DFIR-LABS

    484View on GitHub↗

    DFIR LABS is a compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.

    Python
    View on GitHub↗484
  • ashishb/android-malwareashishb avatar

    ashishb/android-malware

    1,209View on GitHub↗

    Collection of android malware samples

    Shell
    View on GitHub↗1,209
  • aquasecurity/traceeaquasecurity avatar

    aquasecurity/tracee

    4,377View on GitHub↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Gobpfdockerebpf
    View on GitHub↗4,377
  • advanced-threat-research/darkside-config-extractA

    advanced-threat-research/DarkSide-Config-Extract

    0View on GitHub↗
    View on GitHub↗0
  • accidentalrebel/mbcscanA

    accidentalrebel/mbcscan

    0View on GitHub↗
    View on GitHub↗0
  • cea-sec/openwecC

    cea-sec/openwec

    0View on GitHub↗

    OpenWEC is a free and open source (GPLv3) implementation of a Windows Event Collector server running on GNU/Linux and written in Rust.

    View on GitHub↗0
  • aptnotes/dataaptnotes avatar

    aptnotes/data

    1,794View on GitHub↗

    APTnotes data

    View on GitHub↗1,794
  • captaingeech42/ransomwatchC

    captainGeech42/ransomwatch

    0View on GitHub↗
    View on GitHub↗0
  • cert-ee/cuckoo3C

    cert-ee/cuckoo3

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/drakvuf-sandboxCERT-Polska avatar

    CERT-Polska/drakvuf-sandbox

    1,305View on GitHub↗

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

    Pythonmalwaremalware-analysismalware-research
    View on GitHub↗1,305
  • cert-polska/kartonC

    CERT-Polska/karton

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/mwdb-coreC

    CERT-Polska/mwdb-core

    0View on GitHub↗
    View on GitHub↗0
  • certsocietegenerale/fircertsocietegenerale avatar

    certsocietegenerale/FIR

    2,009View on GitHub↗

    Fast Incident Response

    JavaScript
    View on GitHub↗2,009
  • certsocietegenerale/raidlinecertsocietegenerale avatar

    certsocietegenerale/rAIdline

    24View on GitHub↗

    IR drill plateform

    Shell
    View on GitHub↗24
  • checkpointsw/showstopperCheckPointSW avatar

    CheckPointSW/showstopper

    223View on GitHub↗

    Contributed by Check Point Software Technologies LTD. Programmed by Yaraslau Harakhavik

    C++
    View on GitHub↗223
  • cisofy/lynisCISOfy avatar

    CISOfy/lynis

    15,284View on GitHub↗

    Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom

    Shellauditingcompliancedevops
    View on GitHub↗15,284
  • capacitorset/box-jsCapacitorSet avatar

    CapacitorSet/box-js

    673View on GitHub↗

    A tool for studying JavaScript malware.

    JavaScript
    View on GitHub↗673