{"repo":"dod-cyber-crime-center/DC3-MWCP","free":true,"listed":false,"github":"https://github.com/dod-cyber-crime-center/DC3-MWCP","clone":"git clone https://github.com/dod-cyber-crime-center/DC3-MWCP.git","description":"DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, filenames, and mutex names.","language":"Python","stars":349,"topics":["python","malware-analysis","automation","config-dump","framework","malware-automation"],"license":null,"category":"security-tools","readme_excerpt":"DC3-MWCP Changelog Releases DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, filenames, and mutex names. A parser module is usually created per malware family. DC3-MWCP is designed to help ensure consistency in parser function and output, ease parser development, and facilitate parser sharing. DC3-MWCP supports both analyst directed analysis and large-scale automated execution, utilizing either the native python API, a REST API, or a provided command line tool. DC3-MWCP is authored by the Defense Cyber Crime Center (DC3). - Install - Builtin Parsers - Dragodis Support - DC3-Kordesii Support - Usage - CLI Tool - REST API - Python API - Schema - STIX Output - YARA Matching - Helper Utilities Guides - Parser Development - Parser Components - Parser Installation - Parser Testing - Python Style Guide - Malstruct Tutorial - Style Guide - Testing Install By default, only the dependencies needed to run the base framework are installed. To use the builtin parsers or specific features the optional dependencies may need to be installed: Builtin Parsers DC3-MWCP includes a handful of builtin parsers to get you started. These can be used as-is, subclassed, or included in your own parser groups. To use the builtin parsers, you must ensure the parsers extra is installed: To view the available parsers: Parsers are installed under the dc3 source nam","default_branch":null,"files":null,"tree":[],"storefront":"/r/dod-cyber-crime-center","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dod-cyber-crime-center/DC3-MWCP/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}