{"repo":"JusticeRage/Manalyze","free":true,"listed":false,"github":"https://github.com/JusticeRage/Manalyze","clone":"git clone https://github.com/JusticeRage/Manalyze.git","description":"A static analyzer for PE executables.","language":"YARA","stars":1131,"topics":["malware","static","analysis","pe"],"license":"GPL-3.0","category":"dev-tools","readme_excerpt":"# Manalyze Introduction Manalyze is a static analysis tool for PE files that you can use to conduct primary assessment on an executable (or set of executables). It collects weak signals that could indicate malicious behavior and displays information that can help a subsequent manual analysis. If you want to see some sample reports generated by the tool, feel free to try out the web service I created for it: manalyzer.org. Table of Contents - A static analyzer for PE files - How to build - Generating ClamAV rules - Usage - People using Manalyze - Contact A static analyzer for PE files Manalyze was written in C++ for Windows and Linux and is released under the terms of the GPLv3 license. It is a robust parser for PE files with a flexible plugin architecture which allows users to statically analyze files in-depth. Manalyze... - Identifies a PE's compiler - Detects packed executables - Applies ClamAV signatures - Searches for suspicious strings - Looks for malicious import combinations (i.e. WriteProcessMemory + CreateRemoteThread ) - Detects cryptographic constants (just like IDA's findcrypt plugin) - Can submit hashes to VirusTotal - Verifies authenticode signatures (on Windows only) How to build There are few things I hate more than checking out an open-source project and spending two hours trying to build it. This is why I did my best to make Manalyze as easy to build as possible. If these few lines don't work for you, then I have failed at my job and you should drop me a lin","default_branch":null,"files":null,"tree":[],"storefront":"/r/JusticeRage","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JusticeRage/Manalyze/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}