Fnord is a pattern extractor for obfuscated code that extracts byte sequences and creates statistics by processing the file with a sliding window to extract sequences of varying lengths, presenting the most frequent sequences in a table with details like length, occurrences, sequence, and entropy. It also generates an experimental YARA rule by calculating a score based on the length and occurrences of sequences, processing each sequence to detect interesting ones using a list of keywords, and calculating Levenshtein distance to skip irrelevant sequences.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
An application security platform that combines SCA, SAST, container security, dependency management, and AI model risk analysis with integrated workflows for development and security teams.
StaCoAn is a cross-platform tool for static code analysis on mobile applications, emphasizing the identification of security vulnerabilities.
A tool for brute-forcing GET and POST parameters to discover potential vulnerabilities in web applications.
A serverless application that demonstrates common serverless security flaws and weaknesses
Revelo is an experimental Javascript deobfuscator tool with features to analyze and deobfuscate Javascript code.
An API security platform that discovers, documents, and tests APIs throughout the development lifecycle while maintaining a centralized catalog of all API assets.
An API security platform that provides automated security testing, runtime protection, and lifecycle management for APIs through integrated tools and controls.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.