Deobfuscation
Examine Static Properties
Last updated
Examine Static Properties
Last updated
Decode and otherwise analyze data using this browser app.
Website: Author: GCHQ License: Apache License 2.0: Notes: cyberchef State File:
Perform static analysis of various aspects of malicious code.
Website:
Author: The MITRE Corporation,
License: License 2.0:
Notes: Malchive command-line tools start with the prefix malutil-
. See for details.
State File:
Analyze Cobalt Strike beacons.
Website: Author: Didier Stevens: License: Public Domain Notes: For an overview of this tool, see the article. State File:
Decrypt Cobalt Strike metadata.
Website: Author: Didier Stevens: License: Public Domain State File:
Analyze Cobalt Strike beacons.
Perform set operations on lines or bytes in text files.
Analyze XOR-encoded data.
Python3 Decoders for Remote Access Trojans
Parsing configuration information from malware.
Display Unicode character properties.
Decode and otherwise analyze data using this command-line tool and Python library.
Extract and deobfuscate patterns from suspicious files.
Locate and decode strings encoded in Base64 and other common encodings.
Implement a XOR known plaintext attack.
Help guess a file's 256-byte XOR by using frequency analysis.
Deobfuscate XOR'ed files.
Bruteforce XOR'ed strings to find those that are English words.
Bruteforce an XOR-encoded file.
Locate and decode stack strings in executable files.
Search an XOR'ed file for indications of executable binaries.
Cut out a part of a data stream.
Decompose structured binary data with format strings.
Translate bytes according to a Python expression.
Search for XOR encoded strings in a file.
Locate and decode strings obfuscated using common techniques.
Extract and deobfuscate strings from PE executables.
Website: Author: Aon / Stroz Friedberg License: Apache License 2.0: Notes: csce, list-cs-settings State File:
Website: Author: Didier Stevens: License: Public Domain State File:
Website: Author: Aleksei Hellman License: MIT License: State File:
Website: Author: Kevin Breen: License: MIT License: Notes: malconf State File:
Website: Author: Defense Cyber Crime Center - United States Government License: Some parts Public Domain, some MIT License: Notes: mwcp State File:
Website: Author: Radovan Garabik License: GNU General Public License (GPL) v3: State File:
Website: Author: securisec: License: GNU General Public License (GPL) v3: Notes: chepy State File:
Website: Author: Philippe Lagadec: License: Free, custom license: Notes: balbuzard, bbcrack, bbharvest, bbtrans State File:
Website: Author: Didier Stevens: License: Public Domain Notes: base64dump.py State File:
Website: Author: Didier Stevens: License: Public Domain State File:
Website: Author: Glenn P. Edwards Jr. License: Free, unknown license State File:
Website: Author: Thomas Chopitea License: Apache License 2.0: State File:
Website: Author: Alexander Hanel, Trenton Tait License: Free, unknown license State File:
Website: Author: Jose Miguel Esparza License: Free, unknown license State File:
Website: Author: TotalHash License: Free, unknown license State File:
Website: Author: Alexander Hanel License: Free, unknown license State File:
Website: Author: Didier Stevens: License: Public Domain State File:
Website: Author: Didier Stevens: License: Public Domain State File:
Website: Author: Didier Stevens: License: Public Domain State File:
Website: Author: Didier Stevens License: Free, unknown license State File:
Website: Author: Didier Stevens: License: Public Domain Notes: xorsearch State File:
Website: Author: FireEye Inc, Willi Ballenthin: , Moritz Raabe License: Apache License 2.0: Notes: floss State File: