RTFSig Logo

RTFSig

0
Free
Visit Website

RTFSig is a tool designed to make it easy to signature potentially unique parts of RTF files. It requires Python 3 and some basic libraries, which are handled automatically if installed using pip. The tool scans RTF files for unique tags, prints details to the screen, and saves a Yara rule. Basic output is shown on the console, which can be used to search VirusTotal.

FEATURES

ALTERNATIVES

Repository of scripts, signatures, and IOCs related to various malware analysis topics.

Binary analysis and management framework for organizing malware and exploit samples.

Powerful debugging tool with extensive features and extensions for memory dump analysis and crash dump analysis.

A generator for YARA rules that creates rules from strings found in malware files while removing strings from goodware files.

A dataset release policy for the Android Malware Genome Project, requiring authentication and justification for access to the dataset.

A tool that recovers passwords from pixelized screenshots

FLARE Obfuscated String Solver (FLOSS) automatically extracts and deobfuscates strings from malware binaries using advanced static analysis techniques.

KLara is a distributed system written in Python that helps Threat Intelligence researchers hunt for new malware using Yara.