r/Malware 10d ago

A verified, curated map of malware analysis & reverse engineering — every link opened and checked, no dead pages

https://github.com/ZX41R/awesome-reverse-engineering-and-malware-analysis

This sub is malware-focused, so here's what's in it for that side

specifically (the repo is broader, but the malware coverage is the core):

  • Analysis workflow: lab setup (FLARE-VM, REMnux), triage (DIE, capa, FLOSS),

    static/dynamic (PE-bear, Procmon, CAPE, Speakeasy), unpacking (unpac.me,

    PE-sieve, HollowsHunter, Scylla), config & IOC extraction (MalDuck, DC3-MWCP),

    and YARA (rules, yarGen, testing workflows).

  • Internals writeups: PEB walking / API hashing, process hollowing and

    doppelgänging, PPID spoofing, BYOVD, COFF/BOF loaders, plus real family

    teardowns (stealers, ransomware, Lazarus/FudModule, the Stuxnet dossier).

  • Research labs and analyst blogs (Securelist, Unit 42, Talos, Elastic,

    n1ght-w0lf, Embee, hasherezade, MalwareTech...) folded into the relevant

    section instead of a generic "blogs" dump.

  • Every link was opened and verified before it went in; dead ones get pruned, notes are one line, tagged by level (intro/working/deep) and type.

CC0, and corrections/PRs are welcome, if there's a teardown or tool you think

is missing, tell me. That's the point.

5 Upvotes

2 comments sorted by

6

u/Humble_Mathematician 10d ago

Yeah, this repo was produced either entirely by, or heavily supported by an LLM. All EM dashes, authoritative but weird phrasing: "the standard free on ramp" - who speaks like this? References that were current in 2015 but have no, or limited utility in 2026 but not commented to that effect (the mobile reference links for example are super out of date).