User Tools

Site Tools


cybersecurity:osint.bkp:docs_malware-cti

๐Ÿฆ  Malware Analysis & CTI

Malware Analysis Platforms

Use these platforms to analyze suspicious files, URLs, or scripts, and identify malicious behavior, network activity, and indicators.

  • VirusTotal โ€” Multi-engine malware scanner with IOC and sandbox integrations
  • Hybrid Analysis โ€” Dynamic malware analysis platform showing behavior and network calls
  • ANY.RUN โ€” Interactive sandbox for live malware execution and observation
  • Cuckoo Sandbox โ€” Open-source automated malware analysis system
  • Intezer Analyze โ€” Code-reuse and malware lineage analysis
  • Joe Sandbox โ€” Advanced commercial sandbox environment
  • MalwareBazaar โ€” Repository of malware samples and hashes

Malware Analysis Tools

Toolkits and utilities for static and dynamic analysis of binaries, scripts, and executables.

  • Remnux โ€” Linux distribution for reverse engineering and malware analysis
  • YARA โ€” Pattern-matching engine for malware detection and classification
  • PEStudio โ€” Windows executable analyzer for metadata and indicators
  • Capa โ€” Detects capabilities and functionality in executable files
  • Die (Detect It Easy) โ€” PE analysis tool for structure, entropy, and packers

Reverse Engineering & Disassembly

Tools for deep binary inspection, debugging, and reverse engineering of malware samples.

  • Ghidra โ€” Open-source reverse engineering suite developed by the NSA
  • IDA Free โ€” Disassembler and debugger with visual graph analysis
  • Binary Ninja โ€” Modern and scriptable reverse engineering platform
  • x64dbg โ€” Open-source Windows debugger for malware analysis

Network & Behavior Analysis

Monitor process activity, file system changes, and network communications of suspicious samples.

  • Wireshark โ€” Network packet capture and protocol analyzer
  • Procmon โ€” Real-time monitoring of file, registry, and process activity
  • ApateDNS โ€” DNS redirection tool for malware network simulation
  • FakeNet-NG โ€” Network emulation tool for capturing malware traffic

Malware Feeds & Repositories

Live sources of malware samples, indicators, and research materials.

  • Malpedia โ€” Structured database of malware families and samples
  • VX Underground โ€” Archive of malware source code and research papers
  • URLhaus โ€” Database of malicious URLs submitted by the community
  • Feodo Tracker โ€” C2 tracking for banking trojans and botnets
  • MalShare โ€” Public malware repository with daily sample updates

Threat Intelligence Platforms

Platforms for collecting, structuring, and sharing threat intelligence data.

  • MISP โ€” Open-source platform for sharing threat intelligence and IOCs
  • OpenCTI โ€” Knowledge graph for cyber threat intelligence management
  • YETI โ€” Framework for storing and correlating threat data
  • ThreatConnect โ€” Commercial CTI platform with automation and analytics
  • EclecticIQ Platform โ€” Enterprise-grade CTI management and analysis platform
  • AboutIntel - Freemium TI and AS monitor to deliver relevant, actionable security insights. Without the noise.

IOC Enrichment & Internet Scanners

Tools for IOC enrichment, infrastructure mapping, and exposure analysis of malicious ecosystems.

  • SilentPush - Track, monitor and counteract global threat activity.
  • Validin - Explore and track threats across key attributes for public infrastructure tracking
  • ThreatMiner โ€” Data mining for IOCs, malware, SSL, and related artifacts
  • Abuse.ch โ€” Home to ThreatFox, Feodo Tracker, URLhaus, and SSLBL projects
  • GreyNoise โ€” Contextual intelligence on internet-scanning IPs
  • AlienVault OTX โ€” Community threat intelligence sharing platform
  • Maltiverse โ€” IOC enrichment with threat classification and context
  • Shodan โ€” Internet-wide search engine for exposed systems
  • Censys โ€” Search engine for internet infrastructure and certificates
  • BinaryEdge โ€” Real-time internet scanning and asset discovery for threat analysis
  • CriminalIP โ€” Attack surface and exposure analysis platform
  • FOFA โ€” Cyber asset search engine widely used in China for exposure research
  • Censys Workshop โ€” Research environment showcasing Censys experimental tools
cybersecurity/osint.bkp/docs_malware-cti.txt ยท Last modified: by 127.0.0.1