Analysis & Sandboxing
CAPEv2
Open-source malware sandbox derived from Cuckoo. Automated behavioral analysis with memory dumps, API tracing, and network capture.
Ghidra
NSA's open-source software reverse engineering framework. Disassembly, decompilation, and scripting for binary analysis.
YARA
Pattern matching tool for malware researchers. Write rules to identify and classify malware families based on binary patterns.
OSINT Tools
Shodan
Search engine for internet-connected devices. Discover exposed services, vulnerabilities, and infrastructure across the internet.
Maltego
Visual link analysis tool for OSINT investigations. Map relationships between entities across data sources.
SpiderFoot
Automated OSINT collection and reconnaissance framework. Integrates 200+ data sources for comprehensive footprinting.
Intel Platforms
VirusTotal
Multi-engine malware scanning and threat intelligence aggregation. File and URL analysis with community-driven intelligence.
AlienVault OTX
Open threat exchange platform. Community-contributed IOCs, pulses, and threat data for collaborative defense.
MISP
Open-source threat intelligence sharing platform. Structured IOC sharing with taxonomies and correlation engine.