Ross ROSS = Recommend OSS · open-source software intelligence for agents

ayoubfaouzi/al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. observed · 2026-08-28

github.com/ayoubfaouzi/al-khaser · C++ · GPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

73/100

  • Activity 90
  • Release rhythm 36
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 492
  • age_days: 3947
  • days_rel: 218
  • days_push: 63
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

7108 stars · 1255 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debugging, anti-VM, anti-sandbox, timing attacks, and code injection. It is intended to stress-test anti-malware systems and verify that analysis environments are properly hidden.

Use cases

  • test whether my sandbox solution is detectable by malware
  • verify my anti-debugging plugin is effective
  • check if my malware analysis VM is well hidden
  • stress test antivirus detection of common malware tricks
  • demonstrate anti-VM and anti-emulation techniques
  • evaluate sandbox evasion via timing attacks

When to choose

  • you build or harden sandboxes, VMs, or anti-malware tooling and need a comprehensive test suite of evasion techniques
  • you research or teach malware anti-analysis behavior on Windows

When to avoid

  • you need a real defensive tool that detects or blocks malware
  • you want a cross-platform or non-Windows testing tool
  • you lack authorization to run evasion techniques in your environment

Facets

application · maturity active

security penetration-testing vulnerability-scanning security penetration-testing reverse-engineering windows cpp anti-analysis anti-debugging anti-vm anti-sandbox malware-techniques poc av-testing

1 source

Member repositories

RepositoryRoleHealth v2
ayoubfaouzi/al-khasermain73

For agents

markdown · JSON · MCP: product_card(name="ayoubfaouzi/al-khaser")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem