{"adoption": {"forks": 201, "observed_at": "2026-08-28T04:05:39.981898+00:00", "stars": 1816}, "canonical_url": "https://ross.abutalabs.com/products/awesome-malware-development", "card": {"archived": false, "artifact_type": "learning-resource", "description": "Curated resources for malware dev, reverse engineering, and defensive security research.", "domain": ["security", "penetration-testing", "reverse-engineering", "tutorials", "awesome-lists"], "enriched": true, "function": ["security", "reverse-engineering", "penetration-testing", "documentation"], "health_score": 65, "homepage": null, "language": null, "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["rootkit-io/awesome-malware-development"], "name": "rootkit-io/awesome-malware-development", "platform": ["cross-platform", "windows"], "pushed_at": "2026-04-01T12:44:37+00:00", "repo": "rootkit-io/awesome-malware-development", "stars": 1816, "tags": ["awesome-list", "malware-development", "red-team", "edr-evasion", "rootkits", "offensive-security", "curated-resources", "linux"], "topics": ["malware", "malware-development", "malware-research"], "urls": [], "use_cases": ["learn malware development from beginner to advanced", "find resources on EDR and antivirus evasion techniques", "study rootkit and kernel driver development", "research red-team implant and C2 tooling", "find malware development tutorials in Rust, Nim, or Go", "build a learning path for offensive security research"], "what_it_is": "A curated awesome-list of resources for malware development, rootkits, EDR evasion, and red-team tooling, intended for educational and defensive security research. It aggregates articles, courses, books, talks, and open-source proof-of-concept projects with a learning roadmap.", "when_to_avoid": ["you need working production tooling rather than links and references", "you want defensive-only content without offensive techniques", "you cannot legally access offensive security material in your jurisdiction"], "when_to_choose": ["you need a curated starting point for studying malware development or evasion", "you want up-to-date (2025-2026) articles on EDR bypass and modern techniques", "you are a security researcher or red-teamer collecting reference material"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/awesome-malware-development", "repo": "rootkit-io/awesome-malware-development", "role": "main", "score": 66}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.981898+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:20:36.812874+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f8b240baae0dc22672d6339c905845836be17ab9a4ed24301574281896880dcf", "fetched_at": "2026-08-28T04:05:39.981898+00:00", "kind": "readme", "missing": false, "url": "https://github.com/rootkit-io/awesome-malware-development"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 75, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:39:23.370411+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1602, "days_push": 154, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 66, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}