# rshipp/awesome-malware-analysis

Defund the Police.

Repository: https://github.com/rshipp/awesome-malware-analysis
Canonical: https://ross.abutalabs.com/products/awesome-malware-analysis
Homepage: https://gazafunds.com/
License: NOASSERTION
License Family: other
Topics: malware-analysis, awesome, awesome-list, list, malware-samples, analysis-framework, dynamic-analysis, static-analysis, threat-intelligence, automated-analysis, domain-analysis, network-traffic, threatintel, malware-collection, malware-research, threat-sharing, chinese-translation, chinese, drop-ice
Last push: 2024-06-07T05:09:47+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 4134, "days_push": 817, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 14158, forks 2690 (observed 2026-08-28T04:11:05.645433+00:00)

## What it is
A curated awesome-list of malware analysis tools and resources covering collection, threat intelligence, sandboxing, deobfuscation, debugging, memory forensics, and network analysis. It is a reference catalog of links rather than a runnable tool, with a Chinese translation available.

## Use cases
- find tools for analyzing malware samples
- learn malware analysis and reverse engineering
- discover honeypots for collecting malware
- find online sandboxes to scan suspicious files
- locate threat intelligence resources and feeds
- find memory forensics and deobfuscation tools
- build a malware analysis lab toolkit

## When to choose
- you need a starting point to discover malware analysis tooling
- you are compiling a security research or SOC toolkit
- you want curated learning resources for reverse engineering

## When to avoid
- you need an actual analysis tool rather than a list of links
- you need guaranteed up-to-date or maintained tool recommendations
- you need a runnable software component in your pipeline

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, developer-tools
- domain: security, reverse-engineering, awesome-lists
- platform: cross-platform
- tags: awesome-list, malware-analysis, threat-intelligence, reverse-engineering, forensics, sandboxing, curated-list

## Member repositories
- rshipp/awesome-malware-analysis (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:05.645433+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:12:46.598915+00:00, confidence not recorded.
  - readme: https://github.com/rshipp/awesome-malware-analysis (fetched 2026-08-28T04:11:05.645433+00:00, sha be511aa045ac)
  - homepage: https://gazafunds.com/ (fetched 2026-08-29T08:06:52.877224+00:00, sha 7af063c994f2)
  - site_page: https://gazafunds.com/about (fetched 2026-08-29T08:06:52.879786+00:00, sha 1406b3a0b3e2)
  - site_page: https://gazafunds.com/docs (fetched 2026-08-29T08:06:52.881979+00:00, sha 78e8a71f8342)
- Data as of 2026-08-30T08:39:29.467469+00:00.
