awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to tomchop/malcom

Open-source alternatives to Malcom

30 open-source projects similar to tomchop/malcom, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Malcom alternative.

  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • zeek/zeekzeek avatar

    zeek/zeek

    7,735View on GitHub↗

    Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app

    C++brodfirndr
    View on GitHub↗7,735
  • mishakorzik/allhackingtoolsmishakorzik avatar

    mishakorzik/AllHackingTools

    5,186View on GitHub↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    Shellall-in-onebruteforcecibersecurity
    View on GitHub↗5,186

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • activecm/ritaactivecm avatar

    activecm/rita

    579View on GitHub↗

    Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

    Go
    View on GitHub↗579
  • advanced-threat-research/iocsadvanced-threat-research avatar

    advanced-threat-research/IOCs

    83View on GitHub↗

    Repository containing IOCs, CSV and MISP JSON from our blogs

    HTML
    View on GitHub↗83
  • akamai/ludaA

    akamai/luda

    0View on GitHub↗
    View on GitHub↗0
  • advanced-threat-research/darkside-config-extractA

    advanced-threat-research/DarkSide-Config-Extract

    0View on GitHub↗
    View on GitHub↗0
  • aol/molochaol avatar

    aol/moloch

    7,399View on GitHub↗

    Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad

    C
    View on GitHub↗7,399
  • aptnotes/dataaptnotes avatar

    aptnotes/data

    1,794View on GitHub↗

    APTnotes data

    View on GitHub↗1,794
  • ashishb/android-malwareashishb avatar

    ashishb/android-malware

    1,209View on GitHub↗

    Collection of android malware samples

    Shell
    View on GitHub↗1,209
  • blacksnufkin/litterboxBlackSnufkin avatar

    BlackSnufkin/LitterBox

    1,469View on GitHub↗

    A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

    YARAaidocker-composemalware-analysis
    View on GitHub↗1,469
  • buffer/libemubuffer avatar

    buffer/libemu

    156View on GitHub↗

    x86 emulation and shellcode detection

    C
    View on GitHub↗156
  • buffer/pylibemubuffer avatar

    buffer/pylibemu

    129View on GitHub↗

    A Libemu Cython wrapper

    Python
    View on GitHub↗129
  • capacitorset/box-jsCapacitorSet avatar

    CapacitorSet/box-js

    673View on GitHub↗

    A tool for studying JavaScript malware.

    JavaScript
    View on GitHub↗673
  • cert-ee/cuckoo3C

    cert-ee/cuckoo3

    0View on GitHub↗
    View on GitHub↗0
  • captaingeech42/ransomwatchC

    captainGeech42/ransomwatch

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/drakvuf-sandboxCERT-Polska avatar

    CERT-Polska/drakvuf-sandbox

    1,305View on GitHub↗

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

    Pythonmalwaremalware-analysismalware-research
    View on GitHub↗1,305
  • cert-polska/kartonC

    CERT-Polska/karton

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/mwdb-coreC

    CERT-Polska/mwdb-core

    0View on GitHub↗
    View on GitHub↗0
  • ch3k1/squidmagicch3k1 avatar

    ch3k1/squidmagic

    81View on GitHub↗

    analyze a web-based network traffic 🕶 to detect central command and control servers

    Python
    View on GitHub↗81
  • checkpointsw/showstopperCheckPointSW avatar

    CheckPointSW/showstopper

    223View on GitHub↗

    Contributed by Check Point Software Technologies LTD. Programmed by Yaraslau Harakhavik

    C++
    View on GitHub↗223
  • cmu-sei/cyobstractC

    cmu-sei/cyobstract

    0View on GitHub↗
    View on GitHub↗0
  • countercept/snakeC

    countercept/snake

    0View on GitHub↗
    View on GitHub↗0
  • cred-club/artifC

    CRED-CLUB/ARTIF

    0View on GitHub↗
    View on GitHub↗0
  • criticalpathsecurity/zeek-intelligence-feedsC

    CriticalPathSecurity/Zeek-Intelligence-Feeds

    0View on GitHub↗
    View on GitHub↗0
  • csvl/sema-toolchainC

    csvl/SEMA-ToolChain

    0View on GitHub↗
    View on GitHub↗0
  • cybercentrecanada/cccs-yaraCybercentreCanada avatar

    CybercentreCanada/CCCS-Yara

    119View on GitHub↗

    YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA

    Python
    View on GitHub↗119
  • d4stiny/spectreD

    D4stiny/spectre

    0View on GitHub↗
    View on GitHub↗0
  • doctorwebltd/malware-iocsDoctorWebLtd avatar

    DoctorWebLtd/malware-iocs

    242View on GitHub↗
    View on GitHub↗242
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882