Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches). Uses: PE-sieve (the library version). PE-sieve FAQ - Frequently Asked Questions Read Wiki Clone Use recursive clone to get the repo together with all the submodules: git clone --recursive https://github.com/hasherezade/hollows_hunter.git Builds Download the latest release, or read more. Available also via Chocolatey
FEATURES
ALTERNATIVES
A collaborative malware analysis framework with various features for automated analysis tasks.
A Python library to interface with a cuckoo-modified instance.
A tool that scans a corpus of malware and builds a YARA rule to detect similar code sections.
Tools for working with Android .dex and Java .class files, including dex-reader/writer, d2j-dex2jar, and smali/baksmali.
A simple framework for extracting actionable data from Android malware
Blazingly fast Yara queries for malware analysts with an analyst-friendly web GUI.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.