- AnalyzePE – Wrapper for a variety of tools for reporting on Windows PE files.
- chkrootkit – Local Linux rootkit detection.
- ClamAV – Open source antivirus engine.
- ExifTool – Read, write and edit file metadata.
- hashdeep – Compute digest hashes with a variety of algorithms.
- MASTIFF – Static analysis framework.
- MultiScanner – Modular file scanning/analysis framework
- nsrllookup – A tool for looking up hashes in NIST’s National Software Reference Library database.
- packerid – A cross-platform Python alternative to PEiD.
- PEiD – Packer identifier for Windows binaries.
- PEV – A multiplatform toolkit to work with PE files, providing feature-rich tools for proper analysis of suspicious binaries.
- Rootkit Hunter – Detect Linux rootkits.
- ssdeep – Compute fuzzy hashes.
- totalhash.py – Python script for easy searching of the TotalHash.com database.
- TrID – File identifier.
- YARA – Pattern matching tool for analysts.
Detection and Classification
最新推荐文章于 2024-09-05 21:00:49 发布