===== 🦠 Malware Analysis & CTI ===== [[../README|← Back to Index]] ==== Malware Analysis Platforms ==== Use these platforms to analyze suspicious files, URLs, or scripts, and identify malicious behavior, network activity, and indicators. * [[https://www.virustotal.com/|VirusTotal]] — Multi-engine malware scanner with IOC and sandbox integrations * [[https://www.hybrid-analysis.com/|Hybrid Analysis]] — Dynamic malware analysis platform showing behavior and network calls * [[https://any.run/|ANY.RUN]] — Interactive sandbox for live malware execution and observation * [[https://cuckoosandbox.org/|Cuckoo Sandbox]] — Open-source automated malware analysis system * [[https://analyze.intezer.com/|Intezer Analyze]] — Code-reuse and malware lineage analysis * [[https://www.joesecurity.org/|Joe Sandbox]] — Advanced commercial sandbox environment * [[https://bazaar.abuse.ch/|MalwareBazaar]] — Repository of malware samples and hashes ==== Malware Analysis Tools ==== Toolkits and utilities for static and dynamic analysis of binaries, scripts, and executables. * [[https://remnux.org/|Remnux]] — Linux distribution for reverse engineering and malware analysis * [[https://virustotal.github.io/yara/|YARA]] — Pattern-matching engine for malware detection and classification * [[https://www.winitor.com/|PEStudio]] — Windows executable analyzer for metadata and indicators * [[https://github.com/mandiant/capa|Capa]] — Detects capabilities and functionality in executable files * [[https://github.com/horsicq/DIE-engine|Die (Detect It Easy)]] — PE analysis tool for structure, entropy, and packers ==== Reverse Engineering & Disassembly ==== Tools for deep binary inspection, debugging, and reverse engineering of malware samples. * [[https://ghidra-sre.org/|Ghidra]] — Open-source reverse engineering suite developed by the NSA * [[https://hex-rays.com/ida-free/|IDA Free]] — Disassembler and debugger with visual graph analysis * [[https://binary.ninja/|Binary Ninja]] — Modern and scriptable reverse engineering platform * [[https://x64dbg.com/|x64dbg]] — Open-source Windows debugger for malware analysis ==== Network & Behavior Analysis ==== Monitor process activity, file system changes, and network communications of suspicious samples. * [[https://www.wireshark.org/|Wireshark]] — Network packet capture and protocol analyzer * [[https://learn.microsoft.com/en-us/sysinternals/downloads/procmon|Procmon]] — Real-time monitoring of file, registry, and process activity * [[https://www.fireeye.com/services/freeware/apatedns.html|ApateDNS]] — DNS redirection tool for malware network simulation * [[https://github.com/mandiant/flare-fakenet-ng|FakeNet-NG]] — Network emulation tool for capturing malware traffic ==== Malware Feeds & Repositories ==== Live sources of malware samples, indicators, and research materials. * [[https://malpedia.caad.fkie.fraunhofer.de/|Malpedia]] — Structured database of malware families and samples * [[https://vx-underground.org/|VX Underground]] — Archive of malware source code and research papers * [[https://urlhaus.abuse.ch/|URLhaus]] — Database of malicious URLs submitted by the community * [[https://feodotracker.abuse.ch/|Feodo Tracker]] — C2 tracking for banking trojans and botnets * [[https://malshare.com/|MalShare]] — Public malware repository with daily sample updates ==== Threat Intelligence Platforms ==== Platforms for collecting, structuring, and sharing threat intelligence data. * [[https://www.misp-project.org/|MISP]] — Open-source platform for sharing threat intelligence and IOCs * [[https://www.opencti.io/en/|OpenCTI]] — Knowledge graph for cyber threat intelligence management * [[https://yeti-platform.github.io/|YETI]] — Framework for storing and correlating threat data * [[https://threatconnect.com/|ThreatConnect]] — Commercial CTI platform with automation and analytics * [[https://www.eclecticiq.com/platform|EclecticIQ Platform]] — Enterprise-grade CTI management and analysis platform * [[https://www.aboutintel.com/|AboutIntel]] - Freemium TI and AS monitor to deliver relevant, actionable security insights. Without the noise. ==== IOC Enrichment & Internet Scanners ==== Tools for IOC enrichment, infrastructure mapping, and exposure analysis of malicious ecosystems. * [[https://silentpush.com|SilentPush]] - Track, monitor and counteract global threat activity. * [[https://validin.com|Validin]] - Explore and track threats across key attributes for public infrastructure tracking * [[https://www.threatminer.org/|ThreatMiner]] — Data mining for IOCs, malware, SSL, and related artifacts * [[https://abuse.ch/|Abuse.ch]] — Home to ThreatFox, Feodo Tracker, URLhaus, and SSLBL projects * [[https://www.greynoise.io/|GreyNoise]] — Contextual intelligence on internet-scanning IPs * [[https://otx.alienvault.com/|AlienVault OTX]] — Community threat intelligence sharing platform * [[https://maltiverse.com/|Maltiverse]] — IOC enrichment with threat classification and context * [[https://www.shodan.io/|Shodan]] — Internet-wide search engine for exposed systems * [[https://censys.io/|Censys]] — Search engine for internet infrastructure and certificates * [[https://www.binaryedge.io/|BinaryEdge]] — Real-time internet scanning and asset discovery for threat analysis * [[https://www.criminalip.io/|CriminalIP]] — Attack surface and exposure analysis platform * [[https://fofa.so/|FOFA]] — Cyber asset search engine widely used in China for exposure research * [[https://workshop.censys.io/|Censys Workshop]] — Research environment showcasing Censys experimental tools