Static File Analyzer (SFA) Logo

Static File Analyzer (SFA)

0
Free
Visit Website

Static File Analyzer (SFA) is a tool written in Python that acts as a bridge between ClamAV and YARA rules, allowing for deep analysis of malicious files. It can score suspect files, build visual tree graphs for quick display of embedded files, compute indicators of compromise, and extract specific patterns like URLs, hosts, and IPs. SFA uses ClamAV to extract embedded files and create JSON trees, then sends them to YARA for rule checking. It is easy to use, available as a Docker image, and has a web interface integrated in an API.

FEATURES

ALTERNATIVES

A web-based manager for Yara rules, allowing for storage, editing, and management of Yara rules.

A command line utility for searching and downloading exploits

A collection of publicly available YARA rules for detecting and classifying malware.

Guide on emulating Raspberry Pi with QEMU and exploring Arm TrustZone research.

A library for running basic functions from stripped binaries cross platform.

A tool for processing compiled YARA rules in IDA.

A 32-bit assembler level analyzing debugger for Microsoft Windows.

YARA rules for ProcFilter to detect malware and threats

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved