malware-analysis
5 resources across 2 kinds
Tools
- Open ↗de4pydual-uselicence
A Python deobfuscator and analysis toolkit for malware analysts and reverse engineers, featuring an LLM-assisted deobfuscation engine (via Ollama), legacy deobfuscators (Jawbreaker, BlankOBF), a packer/metadata analyzer, process monitoring, and a PySide6 GUI. Licensed CC BY-NC 4.0 (non-commercial).
- Open ↗is-maliciouscloud costpassive
MIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.
Frameworks & agents
- Open ↗Agentic Malware Analysiscloud costhigh-risk
Kali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Open ↗Claude Code RE Toolkitactivehigh-risk
Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.
- Open ↗
Agent skills for defensive malware analysis (re-ioc-extraction and re-unpacker), shipped for both Claude Code and OpenAI Codex, for evidence-first IOC extraction and static-first unpacking plans.