Skip to main content

Malware Analysis Tools

WebsiteDescription
RemnuxA Linux Toolkit for Malware Analysis
Capacapa detects capabilities in executable files. You run it against a PE, ELF, .NET module, shellcode file, or a sandbox report and it tells you what it thinks the program can do. For example, it might suggest that the file is a backdoor, is capable of installing services, or relies on HTTP to communicate.
Resource HackerA freeware resource compiler & decompiler for Windows® applications
PE-bearPE-bear is a multiplatform reversing tool for PE files. Its objective is to deliver fast and flexible “first view” for malware analysts, stable and capable to handle malformed PE files.
Unpac meAutomated malware unpacking and artifact extraction
Detect It Easy (DiE)Program for determining types of files for Windows, Linux and MacOS.
string sifterStringSifter is a machine learning tool that automatically ranks strings based on their relevance for malware analysis.
procdotProcDOT is a powerful tool for visual malware analysis that integrates data from tools like Sysinternals' Procmon and network sniffers. It creates interactive graphs to visualize and correlate malware activities, including thread injection detection and network interaction.
Recorded Future TriageFree, public Sandbox