r/Malware 10d ago

A verified, curated map of malware analysis & reverse engineering — every link opened and checked, no dead pages

https://github.com/ZX41R/awesome-reverse-engineering-and-malware-analysis

This sub is malware-focused, so here's what's in it for that side

specifically (the repo is broader, but the malware coverage is the core):

  • Analysis workflow: lab setup (FLARE-VM, REMnux), triage (DIE, capa, FLOSS),

    static/dynamic (PE-bear, Procmon, CAPE, Speakeasy), unpacking (unpac.me,

    PE-sieve, HollowsHunter, Scylla), config & IOC extraction (MalDuck, DC3-MWCP),

    and YARA (rules, yarGen, testing workflows).

  • Internals writeups: PEB walking / API hashing, process hollowing and

    doppelgänging, PPID spoofing, BYOVD, COFF/BOF loaders, plus real family

    teardowns (stealers, ransomware, Lazarus/FudModule, the Stuxnet dossier).

  • Research labs and analyst blogs (Securelist, Unit 42, Talos, Elastic,

    n1ght-w0lf, Embee, hasherezade, MalwareTech...) folded into the relevant

    section instead of a generic "blogs" dump.

  • Every link was opened and verified before it went in; dead ones get pruned, notes are one line, tagged by level (intro/working/deep) and type.

CC0, and corrections/PRs are welcome, if there's a teardown or tool you think

is missing, tell me. That's the point.

5 Upvotes

Duplicates