{"adoption": {"forks": 541, "observed_at": "2026-08-28T04:08:36.214920+00:00", "stars": 4138}, "canonical_url": "https://ross.abutalabs.com/products/flare-floss", "card": {"archived": false, "artifact_type": "cli-tool", "description": "FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.", "domain": ["security", "reverse-engineering", "developer-tools"], "enriched": true, "function": ["reverse-engineering", "security", "parser", "developer-tools"], "health_score": 98, "homepage": null, "language": "Python", "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["mandiant/flare-floss"], "name": "mandiant/flare-floss", "platform": ["python", "cli", "windows"], "pushed_at": "2026-08-26T12:03:48+00:00", "repo": "mandiant/flare-floss", "stars": 4138, "tags": ["malware-analysis", "deobfuscation", "static-analysis", "strings-extraction", "flare", "linux", "macos"], "topics": ["malware", "deobfuscation", "strings", "flare", "malware-analysis", "gsoc-2026"], "urls": [], "use_cases": ["extract obfuscated strings from malware binaries", "deobfuscate stack strings in an executable", "find hidden C2 domains in a malware sample", "extract strings from Go and Rust binaries", "enhance basic static analysis of unknown binaries", "decode strings built at runtime on the stack"], "what_it_is": "FLOSS (FLARE Obfuscated String Solver) is a Python CLI tool from Mandiant that automatically extracts and deobfuscates strings from malware binaries using advanced static analysis. It recovers static, stack, tight, and decoded strings, plus language-specific strings from Go and Rust binaries.", "when_to_avoid": ["you need dynamic analysis or sandbox detonation of malware", "the binary is packed and you haven't unpacked it first", "you need interactive disassembly rather than string extraction"], "when_to_choose": ["analyzing malware samples during triage or reverse engineering", "strings.exe output misses strings because they are obfuscated or stack-constructed", "you need automated deobfuscation of decoded strings in binaries", "inspecting Go or Rust executables with non-standard string formats"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/flare-floss", "repo": "mandiant/flare-floss", "role": "main", "score": 67}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:08:36.214920+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:23:00.329884+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "96b4de4cef5e25c3d4b9101428ca5b9073f395b2e74d7b0c984ba294c18752c2", "fetched_at": "2026-08-28T04:08:36.214920+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/flare-floss"}, {"content_hash": "a673145d7bd8a388294a0a32285f2141c0a8ecf2d3ae02d6c58bf75620f955f0", "fetched_at": "2026-08-29T09:13:59.735406+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/flare-floss/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3836, "days_push": 7, "days_rel": 706, "gap_med": null, "n_releases_24m": 1}, "score": 67, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}