An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Malware Analysis GitHub Repositories
Explore popular GitHub repositories tagged “malware-analysis”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
UNIX-like reverse engineering framework and command-line toolset
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Defund the Police.
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
Program for determining types of files for Windows, Linux and MacOS.
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙♀️
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
The FLARE team's open-source tool to identify capabilities in executable files.
LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
Reverse Engineer's Toolkit
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.
IntelOwl: manage your Threat Intelligence at scale
Android virtual machine and deobfuscator
Tools and Techniques for Blue Team / Incident Response
A curated list of awesome YARA rules, tools, and people.
FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
State-of-the-art native debugging tools
Android Reverse-Engineering Workbench for VS Code
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Portable Executable reversing tool with a friendly GUI
Malware Configuration And Payload Extraction
oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
A curated list of awesome Android Reverse Engineering training, resources, and tools.