{"repo":"nheijmans/malzoo","free":true,"listed":false,"github":"https://github.com/nheijmans/malzoo","clone":"git clone https://github.com/nheijmans/malzoo.git","description":"Mass static malware analysis tool","language":"Python","stars":95,"topics":["python","wiki-page","splunk","mongodb","elasticsearch","malware-analysis","automation","email-parsing"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"What is MalZoo? MalZoo is a mass static malware analysis tool that collects the information in a Mongo database and moves the malware samples to a repository directory based on the first 4 chars of the MD5 hash. It was build as a internship project to analyze sample sets of 50 G.B.+ (e.g. from http://virusshare.com). A few examples where it can be used for: - Use the collected information to visualize the results (e.g. see most used compile languages, packers etc.) - Gather intell of large open source malware repositories (original intend of the project) - Monitor a mailbox, analyze the emails and attachments Installation information on VM's and bare-metal For more information on installation and collection of data, check out the Wiki of this repository. Cloud Serverless deployment For the deployment in the AWS Cloud with a Serverless architecture, check out the repository Malzoo Serverless for an auto-deployment solution. Docker container deployment If you would like to deploy the Malzoo project in a Docker container, you can start very easily with pulling the image from Docker Hub And then start a container from there. More instructions further below. Information collected See the wiki page Information collected which data is collected for which sample. Installation See the wiki page Installation to install MalZoo. The best option is to use the auto installation script bootstrap.sh and once that is done running you only have to execute Configuration After the installation y","default_branch":null,"files":null,"tree":[],"storefront":"/r/nheijmans","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nheijmans/malzoo/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}