This tool aims to provide a collaborative malware analysis framework. It features sample storage, semi-automated malware analysis, IDA Pro collaboration, online disassembly, binary matching with the MACHOC fuzzy hash algorithm, Yara matching, and automated hotpoints detection. Additionally, it allows sharing IDA Pro information from the WebUI, taking notes directly from IDA, and provides feature documentation. The tool also offers plugins/tasks for analysis tasks and an engine to automate analysis tasks by identifying points of interest inside the malicious binary.
FEATURES
SIMILAR TOOLS
Krakatau provides an assembler and disassembler for Java bytecode, supporting conversion, creation, examination, comparison, and decompilation of Java binaries.
A developer added malicious code to a popular open-source package, wiping files on computers in Russia and Belarus as a protest.
KLara is a distributed system written in Python that helps Threat Intelligence researchers hunt for new malware using Yara.
A framework for reverse engineering Flutter apps with modified Flutter library for dynamic analysis and traffic monitoring.
A tool for translating Dalvik bytecode to Java bytecode for analyzing Android applications.
Identifies 137 malicious npm packages and gathers system information to a remote server.
A library and command line interface for extracting URLs, IP addresses, MD5/SHA hashes, email addresses, and YARA rules from text corpora.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.