{"repo":"dobin/avred","free":true,"listed":false,"github":"https://github.com/dobin/avred","clone":"git clone https://github.com/dobin/avred.git","description":"Analyse your malware to surgically obfuscate it","language":"Python","stars":545,"topics":["amsi","antivirus","antivirus-evasion","malware","malware-development","obfuscation"],"license":"GPL-3.0","category":"dev-tools","readme_excerpt":"avred AntiVirus REDucer for AntiVirus REDteaming. Avred is being used to identify which parts of a file are identified by a Antivirus, and tries to show as much possible information and context about each match. This includes: Section names of matches Verification of matches Augmentation of matches as disassembled code or data references It is mainly used to make it easier for RedTeamers to obfuscate their tools against static analysis. All Antivirus are supported (AMSI is being used). Check it out: avred.r00ted.ch Slides: HITB Slides Cracking The Shield.pdf Comparison to ThreatCheck Compared to ThreatCheck, avred has multiple features: Shows all matches (not just one) Verifies the matches to make sure they work Shows more information of matches Shows relevance of match, so you can target the weakest one Supports all AV Background Most antivirus engines rely on strings or other bytes sequences to recognize malware. This project helps to automatically recover these signatures (matches). The difference to similar projects is: Knowledge of internal file structures. Can extract vbaProject.bin and modify it Knows about PE sections and scan each one individually Knows .NET streams Supports any Antivirus (thanks to AMSI server via HTTP) Shows detailed information about each match (disassembly etc.) Verifies the matches Supported files: PE (EXE) files, r2 disassembly PE .NET files, dncil disassembly Word files, pcodedmp disassembly Example Screenshots Fileinfo: File details: File mat","default_branch":null,"files":null,"tree":[],"storefront":"/r/dobin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dobin/avred/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}