Malcom - Malware Communications Analyzer
Principalele funcționalități ale tomchop/malcom sunt: Malware Analysis, Network Analysis.
Alternativele open-source pentru tomchop/malcom includ: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… zeek/zeek — Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… activecm/rita — Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through… advanced-threat-research/iocs — Repository containing IOCs, CSV and MISP JSON from our blogs. advanced-threat-research/darkside-config-extract.
Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.