Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images. Prior to Binwalk v2.3.3, extracted archives could create symlinks which point anywhere on the file system, potentially resulting in a directory traversal attack if subsequent extraction utilities blindly follow these symlinks. Binwalk makes use of many third-party extraction utilities which may have unpatched security issues; Binwalk v2.3.3 and later allows external extraction tools to be run as an unprivileged user using the run-as command line option (this requires Binwalk itself to be run with root privileges). Additionally, Binwalk v2.3.3 and later will refuse to perform extraction as root unless --run-as=root is specified. Even though many major Linux distros are still shipping Python 2.7 as the default interpreter in their currently stable release, Binwalk support has moved exclusively to Python 3.
FEATURES
SIMILAR TOOLS
A PowerShell module for interacting with VirusTotal to analyze suspicious files and URLs.
A tool to detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.
Fernflower is an analytical decompiler for Java with command-line options and support for external classes.
A new age tool for binary analysis that uses statistical visualizations to help find patterns in large amounts of binary data.
A program to manage yara ruleset in a database with support for different databases and configuration options.
A Go library for manipulating YARA rulesets with the ability to programatically change metadata, rule names, and more.
Dynamic binary analysis library with various analysis and emulation capabilities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.