Repositories
-
capa-rules
Standard collection of rules for capa: the tool for enumerating the capabilities of programs
-
capa
The FLARE team's open-source tool to identify capabilities in executable files.
-
-
HXTool
HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physical workstation. HXTool provides additional features and capabilities over the standard FireEye HX web user interface. HXTool uses the fully documented REST API that comes with the FireEye HX for communication w…
-
commando-vm
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com
-
FIDL
A sane API for IDA Pro's decompiler. Useful for malware RE and vulnerability research
-
jest-environment-serverless
Testing your Serverless projects with Jest the easy way!
-
-
jitm
JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.
-
ThreatPursuit-VM
Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.
-
stringsifter
A machine learning tool that ranks strings based on their relevance for malware analysis.
-
flare-fakenet-ng
[Suspended] FakeNet-NG - Next Generation Dynamic Network Analysis Tool
-
-
-
flare-floss
FireEye Labs Obfuscated String Solver - Automatically extract obfuscated strings from malware.
-
flare-floss-testfiles
Resources for testing FLOSS by the FLARE team.
-
flare-ida
IDA Pro utilities from FLARE team
-
muse-technical-challenge
Muse Technical Challenge Stencil Component Starter
-
DFUR-Splunk-App
The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.
-
dod-example-apps
Example applications for FireEye's Detection on Demand service