Malwrologist (@DissectMalware)
  • Stars
    star
    1,177
  • Global Rank 26,160 (Top 1.0 %)
  • Followers 365
  • Following 5
  • Registered about 10 years ago
  • Most used languages
    Python
    63.2 %
    HTML
    10.5 %
    C#
    10.5 %
    JavaScript
    5.3 %
    C++
    5.3 %
    Dockerfile
    5.3 %

Top repositories

1

XLMMacroDeobfuscator

Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)
Python
561
star
2

batch_deobfuscator

Deobfuscate batch scripts obfuscated using string substitution and escape character techniques.
Python
138
star
3

pyOneNote

A python library to parse OneNote (.one) files
Python
110
star
4

MalwareCMDMonitor

Shows command lines used by latest instances analyzed on Hybrid-Analysis
Python
44
star
5

base64_substring

Generate a Yara rule to find base64-encoded files containg a specific keyword
Python
40
star
6

yaradbg-frontend

JavaScript
36
star
7

ClipboardWatcher

Monitor the textual data pasted into Windows clipboard
C#
29
star
8

OfficeForensicTools

A set of tools for collecting forensic information
Python
25
star
9

PySameSame

This is a python version of samesame repo to generate homograph strings
HTML
24
star
10

xlrd2

xlrd2 is a variant of xlrd that is actively maintained
Python
24
star
11

yaradbg-backend

Python
24
star
12

WinNativeIO

Using Undocumented NTDLL Functions to Read/Write/Delete File
C++
20
star
13

pyxlsb2

an Excel 2007+ Binary Workbook (xlsb) parser for Python
Python
19
star
14

MDIExtractor

Python
15
star
15

npp-langs-4-sec

Notepad++ Syntax Highlighting for Languages Used by Cyber Security Professionals
15
star
16

IoCMiner

A Framework to Automatically Extract Indicators of Compromise (IoCs) from Twitter
Python
14
star
17

PhishCanary

Given a TLD zone file, PhishCanary extracts International Domain Names (IDNs) that are homoglyphs of specified target domain names.
Python
10
star
18

yaradbg-issues

7
star
19

yaradbg-container

A docker config file to run yaradbg in a container
Dockerfile
5
star
20

TLDExtractor

Accurately extract TLD, effective TLD, 2LD, 3LD, ... from a given domain name; by utilizing the Public Suffix List maintained by Mozilla Foundation
C#
3
star
21

document-samples

HTML
1
star