Python Malware

Open-source Python projects categorized as Malware

Top 23 Python Malware Projects

  • hosts

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    Project mention: Does PiHole block porn? | /r/pihole | 2023-12-06

    Not by default but a blocklist can be found here https://github.com/StevenBlack/hosts

  • wifiphisher

    The Rogue Access Point Framework

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

  • theZoo

    A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

    Project mention: TheZoo a.k.a. Malware DB | news.ycombinator.com | 2023-08-18
  • volatility

    An advanced memory forensics framework

    Project mention: What is the appropriate uncompressed kernel ELF to use with dwarf2json? [ 5.19.0-42-generic #43~22.04.1-Ubuntu ], in order to create generate a custom symbols table to conduct linux memory forensics on Ubuntu 22.04? | /r/computerforensics | 2023-05-28

    I need this to create generate a custom symbols table (using dwarf2json), in order to run a memory dump acquired by Ubuntu 22.04, as Ubuntu 22.04 kernel does not work anymore with volatility 2 (Issue here: volatilityfoundation/volatility#828)

  • pyWhat

    🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

  • maltrail

    Malicious traffic detection system

    Project mention: Maltrail: Malicious traffic detection system | /r/selfhosted | 2023-07-05

    I just wanted to tell you about Maltrail (https://github.com/stamparm/maltrail/).

  • qiling

    A True Instrumentable Binary Emulation Framework

    Project mention: Qiling: A True Instrumentable Binary Emulation Framework | news.ycombinator.com | 2024-04-01
  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

  • flare-floss

    FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

  • malwoverview

    Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest and it is able to scan Android devices against VT.

  • volatility3

    Volatility 3.0 development

    Project mention: Volatility 3 2.4.1 - New Linux and Windows plugins | /r/blueteamsec | 2023-04-22
  • APT_REPORT

    Interesting APT Report Collection And Some Special IOC

  • CAPEv2

    Malware Configuration And Payload Extraction

  • yarGen

    yarGen is a generator for YARA rules

  • ThePhish

    ThePhish: an automated phishing email analysis tool

    Project mention: How do you deal with phising emails at your company? | /r/cybersecurity | 2023-05-14
  • drakvuf-sandbox

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

  • intelmq

    IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

  • empyrean

    Easy to use and open-source stealer that's super effective

  • Luna-Grabber

    The best discord token grabber made in python

    Project mention: EMERGENCY~!!!! Have been Doxxed | /r/pchelp | 2023-07-05

    I believe the program is something called Luna Grabber which has the ability to know if it is being used on a VM or not. However, there isn't much data on how to actually remove it from the computer. https://github.com/Smug246/Luna-Grabber

  • opensquat

    The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains.

    Project mention: Have I Been Squatted? | news.ycombinator.com | 2023-11-27

    A different solution that runs locally is opensquat.

    https://github.com/atenreiro/opensquat

  • packj

    Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

    Project mention: Rust Without Crates.io | news.ycombinator.com | 2023-11-14

    Creator of Packj [1] here. How do you envision sandboxing/security policies will be specified? Per-lib policies when you've hundreds of dependencies will become overwhelming. Having built an eBPF-based sandbox [2], I anticipate that accuracy will be another challenge here: too restrictive will block functionality, too permissive defeats the purpose.

    1. https://github.com/ossillate-inc/packj flags malicious/risky NPM/PyPI/RubyGems/Rust/Maven/PHP packages by carrying out static+dynamic+metadata analysis.

  • Python-Rootkit

    Python Remote Administration Tool (RAT) to gain meterpreter session

  • misp-galaxy

    Clusters and elements to attach to MISP events or attributes (like threat actors)

    Project mention: Foreign Travel Risks | /r/cybersecurity | 2023-04-26

    MISP Threat Actor Galaxy

  • MalConfScan

    Volatility plugin for extracts configuration data of known malware

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020). The latest post mention was on 2024-04-01.

Python Malware related posts

Index

What are some of the best open-source Malware projects in Python? This list will help you:

Project Stars
1 hosts 25,373
2 wifiphisher 12,659
3 theZoo 10,654
4 volatility 6,890
5 pyWhat 6,338
6 maltrail 5,721
7 qiling 4,817
8 flare-floss 3,000
9 malwoverview 2,693
10 volatility3 2,184
11 APT_REPORT 2,167
12 CAPEv2 1,636
13 yarGen 1,444
14 ThePhish 1,005
15 drakvuf-sandbox 979
16 intelmq 922
17 empyrean 901
18 Luna-Grabber 721
19 opensquat 647
20 packj 612
21 Python-Rootkit 548
22 misp-galaxy 478
23 MalConfScan 467
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com