|10 months ago||about 1 month ago|
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Auditing NodeJs modules with YARA rules
1 project | dev.to | 6 Apr 2021
To achieve this, I started setting up a small project. It is available at https://github.com/rpgeeganage/audit-node-modules-with-yara
Node Module supplier chain attack detect using YARA rules
1 project | news.ycombinator.com | 30 Mar 2021
Audit Node Module folder with YARA rules
1 project | reddit.com/r/ReverseEngineering | 24 Mar 20211 project | reddit.com/r/Malware | 24 Mar 2021
GitHub Repo: https://github.com/rpgeeganage/audit-node-modules-with-yara
Identifying packers, crypters or protectors
3 projects | reddit.com/r/Malware | 24 May 2021
As others have mentioned, looking at entropy is a good metric to generically determine whether or not a given sample is being packed / obfuscated in some way. Doing static analysis on the binary format itself (I'm assuming PE for Windows is the goal) is also useful, such as checking whether or not a section's raw size on disk is much smaller than the virtual size allocated in-memory for that section, which is a reliable indication of packing behavior. This project looks useful for introspecting such behaviors.
blackeko/PEpper - An open source script to perform malware static analysis on Portable Executable
1 project | reddit.com/r/GithubSecurityTools | 24 May 2021
What are some alternatives?
Mobile-Security-Framework-MobSF - Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
solidarity - Solidarity is an environment checker for project dependencies across multiple machines.
Detect-It-Easy - Program for determining types of files for Windows, Linux and MacOS.