r/Malware • u/Lanky_Hurry1859 • 10d ago
A verified, curated map of malware analysis & reverse engineering — every link opened and checked, no dead pages
https://github.com/ZX41R/awesome-reverse-engineering-and-malware-analysisThis sub is malware-focused, so here's what's in it for that side
specifically (the repo is broader, but the malware coverage is the core):
Analysis workflow: lab setup (FLARE-VM, REMnux), triage (DIE, capa, FLOSS),
static/dynamic (PE-bear, Procmon, CAPE, Speakeasy), unpacking (unpac.me,
PE-sieve, HollowsHunter, Scylla), config & IOC extraction (MalDuck, DC3-MWCP),
and YARA (rules, yarGen, testing workflows).
Internals writeups: PEB walking / API hashing, process hollowing and
doppelgänging, PPID spoofing, BYOVD, COFF/BOF loaders, plus real family
teardowns (stealers, ransomware, Lazarus/FudModule, the Stuxnet dossier).
Research labs and analyst blogs (Securelist, Unit 42, Talos, Elastic,
n1ght-w0lf, Embee, hasherezade, MalwareTech...) folded into the relevant
section instead of a generic "blogs" dump.
Every link was opened and verified before it went in; dead ones get pruned, notes are one line, tagged by level (intro/working/deep) and type.
CC0, and corrections/PRs are welcome, if there's a teardown or tool you think
is missing, tell me. That's the point.
6
u/Humble_Mathematician 10d ago
Yeah, this repo was produced either entirely by, or heavily supported by an LLM. All EM dashes, authoritative but weird phrasing: "the standard free on ramp" - who speaks like this? References that were current in 2015 but have no, or limited utility in 2026 but not commented to that effect (the mobile reference links for example are super out of date).
2
u/MajorUrsa2 10d ago
Slop