Awesome Executable Packing
Executable Packingを扱う資料や関連プロジェクトをまとめたAwesomeリストです。
目次
:books: 文献
文書
- :earth_americas: a.out (FreeBSD manual pages)
- :earth_americas: A.out binary format
- :earth_americas: About anti-debug tricks
- :bar_chart: Android packers: Separating from the pack
- :pushpin: Anti debugging protection techniques with examples
- :notebook: Anti-unpacker tricks
- :page_facing_up: Anti-unpacker tricks - Part 14 (and previous parts)
- :bar_chart: API deobfuscator: Resolving obfuscated API functions in modern packers
- :earth_americas: Armouring the ELF: Binary encryption on the UNIX platform
- :green_book: The art of memory forensics: Detecting malware and threats in Windows, Linux, and mac memory
- :bar_chart: The art of unpacking
- :earth_americas: Awesome executable packing
- :earth_americas: Awesome LLVM security
- :pushpin: Cloak and dagger: Unpacking hidden malware attacks
- :book: Cluster analysis
- :earth_americas: Clustering algorithms
- :earth_americas: COM binary format
- :earth_americas: Common object file format (COFF)
- :earth_americas: Comparison of executable file formats
- :newspaper: A complexity measure
- :newspaper: Cyclomatic complexity density and software maintenance productivity
- :bar_chart: Dealing with virtualization packers
- :earth_americas: Defacto2
- :newspaper: Do we need hundreds of classifiers to solve real world classification problems?
- :bar_chart: Dynamic binary analysis and obfuscated codes
- :earth_americas: elf (FreeBSD manual pages)
- :pushpin: Entropy and the distinctive signs of packer PE files
- :notebook: Evading machine learning malware detection
- :earth_americas: Executable and linkable format (ELF)
- :clipboard: Executable and linking format (ELF) specification
- :earth_americas: Executable file formats
- :pushpin: Explained: Packer, crypter, and protector
- :earth_americas: FatELF: Universal binaries for Linux (HALTED)
- :newspaper: Feature selection: A data perspective
- :notebook: Gunpack: Un outil générique d’unpacking de malwares
- :newspaper: How to use t-SNE effectively
- :clipboard: Hyperion: Implementation of a PE-Crypter
- :scroll: Implementing your own generic unpacker
- :earth_americas: Learn symbolic execution and angr
- :bar_chart: LIEF: Library to instrument executable formats
- :pushpin: Mach-O - A look at apple executable files
- :earth_americas: Mach-O file format reference
- :bar_chart: Mach-O internals
- :book: Machine learning
- :pushpin: Making our own executable packer
- :earth_americas: The malware analyst’s guide to aPLib decompression
- :newspaper: The matthews correlation coefficient (MCC) should replace the ROC AUC as the standard metric for assessing binary classification
- :clipboard: Microsoft portable executable and common object file format specification
- :earth_americas: MITRE ATT&CK | T1027.002 | obfuscated files or information: Software packing - Enterprise
- :earth_americas: MITRE ATT&CK | T1406.002 | obfuscated files or information: Software packing - Mobile
- :earth_americas: MZ disk operating system (DOS)
- :bar_chart: NotPacked++: Evading static packing detection
- :earth_americas: OllyDbg OEP finder scripts
- :bookmark: On the worst-case complexity of timsort
- :bar_chart: One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
- :scroll: One packer to rule them all: Empirical identification, comparison and circumvention of current antivirus detection techniques
- :newspaper: Packer analysis report debugging and unpacking the NsPack 3.4 and 3.7 packer
- :pushpin: Packer detection tool evaluation
- :page_facing_up: Packers
- :pushpin: Packers/Protectors for Linux
- :bar_chart: Packing-box: Breaking detectors & visualizing packing
- :bar_chart: Packing-box: Improving detection of executable packing
- :bar_chart: Packing-box: Playing with executable packing
- :pushpin: Parsing mach-O files
- :green_book: Pattern recognition and machine learning (Information science and statistics)
- :earth_americas: PE format - Win32 apps
- :scroll: PinDemonium: A DBI-based generic unpacker for Windows executables
- :earth_americas: Portable executable (PE)
- :green_book: Practical malware analysis: The hands-on guide to dissecting malicious software
- :pushpin: ProtectMyTooling - Don’t detect tools, detect techniques
- :bar_chart: Qualitative and quantitative evaluation of software packers
- :bar_chart: Reverse engineering malware: Binary obfuscation and protection
- :bar_chart: Runtime packers testing experiences
- :bar_chart: Runtime packers: The hidden problem?
- :newspaper: Standards and policies on packer use
- :green_book: Surreptitious software: Obfuscation, watermarking, and tamperproofing for software protection
- :bookmark: A survey of dimensionality reduction techniques
- :bar_chart: TitanMist: Your first step to reversing nirvana
- :pushpin: Tuts 4 you - UnPackMe (.NET)
- :pushpin: Tuts 4 you | unpackme
- :green_book: The “Ultimate” anti-debugging reference
- :page_facing_up: Unpacking binary 101
- :pushpin: Unpacking the potential of “Packing box”
- :pushpin: Unpacking, reversing, patching
- :bar_chart: Virtual machine obfuscation
- :bar_chart: WaveAtlas: Surfing through the landscape of current malware packers
- :bar_chart: We can still crack you! General unpacking method for Android Packer (NO ROOT)
- :bar_chart: When malware is packing heat
- :clipboard: Win32 portable executable packing uncovered
- :pushpin: Writing a packer
- :pushpin: Writing a PE packer
- :pushpin: Writing a simple PE packer in detail
- :earth_americas: x86 disassembly/Windows executable files
- :earth_americas: YARA - The pattern matching swiss knife for malware researchers.
科学研究
- :newspaper: 2-SPIFF: A 2-stage packer identification method based on function call graph and file attributes (December 2021) :star:
- :newspaper: Absent extreme learning machine algorithm with application to packed executable identification (January 2016)
- :newspaper: An accurate packer identification method using support vector machine (January 2014)
- :notebook: Adaptive unpacking of Android Apps (May 2017)
- :mortar_board: Advanced feature engineering for static detection of executable packing (June 2024) :star:
- :newspaper: Advanced preprocessing of binary executable files and its usage in retargetable decompilation (December 2014)
- :newspaper: Adversarial attacks against Windows PE malware detection: A survey of the state-of-the-art (May 2023) :star:
- :newspaper: Adversarial EXEmples: A survey and experimental evaluation of practical attacks on machine learning for windows malware detection (September 2021) :star:
- :mortar_board: Adversarial learning on static detection techniques for executable packing (June 2023) :star:
- :notebook: Adversarial malware binaries: Evading deep learning for malware detection in executables (September 2018) :star:
- :mortar_board: Adversarial tool for breaking static detection of executable packing (August 2024) :star:
- :notebook: Adversarially robust assembly language model for packed executables detection (November 2025) :star:
- :newspaper: All-in-one framework for detection, unpacking, and verification for malware analysis (January 2019) :star:
- :newspaper: Analysis of machine learning approaches to packing detection (October 2023) :star: :star:
- :newspaper: Anti-emulation trends in modern packers: A survey on the evolution of anti-emulation techniques in UPA packers (May 2018)
- :newspaper: API-MalDetect: Automated malware detection framework for windows based on API calls and deep learning techniques (September 2023) :star:
- :mortar_board: An application of machine learning to analysis of packed mac malware (May 2022) :star:
- :notebook: Application of string kernel based support vector machine for malware packer identification (August 2013)
- :newspaper: The application research of virtual machine in packers (August 2011)
- :notebook: AppSpear: Bytecode decrypting and DEX reassembling for packed Android malware (November 2015)
- :newspaper: The arms race: Adversarial search defeats entropy used to detect malware (October 2018)
- :closed_book: Assessing static and dynamic features for packing detection (October 2024) :star:
- :page_facing_up: Assessing the impact of packing on machine learning-based malware detection and classification systems (September 2025) :star:
- :newspaper: Auditing static machine learning anti-Malware tools against metamorphic attacks (March 2021) :star:
- :mortar_board: Automated static analysis of virtual-machine packers (August 2013)
- :newspaper: Automatic analysis of malware behavior using machine learning (December 2011)
- :newspaper: Automatic generation of adversarial examples for interpreting malware classifiers (March 2020)
- :notebook: Automatic static unpacking of malware binaries (October 2009)
- :newspaper: BareUnpack: Generic unpacking on the bare-metal operating system (December 2018)
- :newspaper: Benchmark for filter methods for feature selection in high-dimensional classification data (March 2020) :star:
- :newspaper: Beyond the sandbox: Leveraging symbolic execution for evasive malware classification (February 2025) :star:
- :newspaper: Binary-code obfuscations in prevalent packer tools (October 2013)
- :newspaper: BinStat tool for recognition of packed executables (September 2010)
- :newspaper: Birds of a feature: Intrafamily clustering for version identification of packed malware (September 2020) :star:
- :notebook: BitBlaze: A new approach to computer security via binary analysis (December 2008)
- :notebook: BODMAS: An open dataset for learning based temporal analysis of PE malware (May 2021) :star:
- :notebook: Boosting scalability in anomaly-based packed executable filtering (November 2011)
- :mortar_board: Building a malware mutation tool (June 2024)
- :mortar_board: Building a smart and automated tool for packed malware detections using machine learning (June 2020)
- :mortar_board: Building high-quality datasets of packed executables - Enhancing static detection models via curated packed binary datasets (August 2025) :star:
- :newspaper: Bypassing anti-analysis of commercial protector methods using DBI tools (January 2021) :star:
- :newspaper: Bypassing heaven’s gate technique using black-box testing (November 2023) :star:
- :notebook: BYTEWEIGHT: Learning to recognize functions in binary code (August 2014)
- :notebook: ByteWise: A case study in neural network obfuscation identification (January 2018)
- :notebook: Certified robustness of static deep learning-based malware detectors against patch and append attacks (November 2023) :star:
- :notebook: Challenging anti-virus through evolutionary malware obfuscation (April 2016)
- :notebook: Chosen-instruction attack against commercial code virtualization obfuscators (April 2022) :star:
- :newspaper: Classification of malware by using structural entropy on convolutional neural networks (April 2018)
- :newspaper: Classification of packed executables for accurate computer virus detection (October 2008)
- :notebook: Classifying packed malware represented as control flow graphs using deep graph convolutional neural network (March 2020) :star:
- :notebook: Classifying packed programs as malicious software detected (December 2016)
- :newspaper: A close look at a daily dataset of malware samples (January 2019) :star:
- :mortar_board: Code obfuscation techniques for software protection (April 2012)
- :notebook: Collective classification for packed executable identification (September 2011)
- :newspaper: A compact multi-step framework for packing identification in portable executable files for malware analysis (February 2024) :star:
- :notebook: A comparative analysis of classifiers in the recognition of packed executables (November 2019) :star:
- :newspaper: A comparative analysis of software protection schemes (June 2014)
- :notebook: A comparative assessment of malware classification using binary texture analysis and dynamic analysis (September 2011)
- :notebook: Comparing malware samples for unpacking: A feasibility study (August 2016)
- :mortar_board: Complexity-based packed executable classification with high accuracy (December 2008)
- :notebook: A comprehensive solution for obfuscation detection and removal based on comparative analysis of deobfuscation tools (October 2021) :star:
- :mortar_board: Computational-intelligence techniques for malware generation (October 2015)
- :newspaper: Conceptual and empirical comparison of dimensionality reduction algorithms (PCA, KPCA, LDA, MDS, SVD, LLE, ISOMAP, LE, ICA, t-SNE) (May 2021)
- :newspaper: A consistently-executing graph-based approach for malware packer identification (April 2019) :star:
- :newspaper: Construction and evaluation of the new heuristic malware detection mechanism based on executable files static analysis (August 2018)
- :notebook: A control flow graph-based signature for packer identification (October 2017) :star:
- :newspaper: Control flow-based opcode behavior analysis for malware detection (July 2014)
- :notebook: Countering entropy measure attacks on packed software detection (January 2012)
- :notebook: Cryptographic function detection in obfuscated binaries via bit-precise symbolic loop mapping (May 2017)
- :bookmark: Deceiving end-to-end deep learning malware detectors using adversarial examples (January 2019) :star:
- :notebook: Deceiving portable executable malware classifiers into targeted misclassification with practical adversarial examples (March 2020)
- :page_facing_up: Decoding the secrets of machine learning in malware classification: A deep dive into datasets, feature extraction, and model performance (November 2023) :star:
- :notebook: Denial-of-service attacks on host-based generic unpackers (December 2009)
- :mortar_board: Deobfuscation of packed and virtualization-obfuscation protected binaries (June 2011)
- :closed_book: Deobfuscation of virtualization-obfuscated code through symbolic execution and compilation optimization (April 2018)
- :notebook: Deobfuscation of virtualization-obfuscated software: A semantics-based approach (October 2011)
- :notebook: Design and development of a new scanning core engine for malware detection (October 2012)
- :mortar_board: Design and implementation of a modular executable packer - Experimenting with packing techniques and static detection (June 2025) :star:
- :notebook: Design and performance evaluation of binary code packing for protecting embedded software against reverse engineering (May 2010)
- :newspaper: Detecting obfuscated malware using reduced opcode set and optimised runtime trace (May 2016)
- :notebook: Detecting obfuscated viruses using cosine similarity analysis (March 2007)
- :notebook: Detecting packed executable file: Supervised or anomaly detection method? (August 2016)
- :newspaper: Detecting packed executables based on raw binary data (June 2010)
- :notebook: Detecting packed executables using steganalysis (December 2014)
- :mortar_board: Detecting packed PE files: Executable file analysis for the Windows operating system (June 2021) :star:
- :notebook: Detecting traditional packers, decisively (October 2013)
- :newspaper: Detecting unknown malicious code by applying classification techniques on opcode patterns (February 2012)
- :notebook: Detection of metamorphic malware packers using multilayered LSTM networks (November 2020) :star:
- :notebook: Detection of packed executables using support vector machines (July 2011)
- :notebook: Detection of packed malware (August 2012)
- :notebook: DexHunter: Toward extracting hidden code from packed Android applications (September 2015)
- :notebook: Disabling anti-debugging techniques for unpacking system in user-level debugger (October 2019)
- :newspaper: DroidPDF: The obfuscation resilient packer detection framework for Android Apps (July 2020)
- :notebook: Dynamic binary instrumentation for deobfuscation and unpacking (November 2009)
- :notebook: Dynamic classification of packing algorithms for inspecting executables using entropy analysis (October 2013)
- :notebook: A dynamic heuristic method for detecting packed malware using naive bayes (November 2019) :star:
- :newspaper: Effective, efficient, and robust packing detection and classification (May 2019) :star2: :star2: :star2:
- :newspaper: An efficient algorithm to extract control flow-based features for ioT malware detection (April 2021) :star:
- :notebook: Efficient and automatic instrumentation for packed binaries (June 2009)
- :newspaper: Efficient automatic original entry point detection (January 2019)
- :newspaper: An efficient block-discriminant identification of packed malware (August 2015)
- :notebook: Efficient malware packer identification using support vector machines with spectrum kernel (July 2013)
- :newspaper: Efficient SVM based packer identification with binary diffing measures (July 2019)
- :newspaper: ELF-Miner: Using structural knowledge and data mining methods to detect new (Linux) malicious executables (March 2012)
- :notebook: EMBER2024 - A benchmark dataset for holistic evaluation of malware classifiers (August 2025) :star:
- :bookmark: EMBER: An open dataset for training static PE malware machine learning models (April 2018) :star: :star:
- :notebook: An empirical evaluation of an unpacking method implemented with dynamic binary instrumentation (September 2011)
- :notebook: Encoded executable file detection technique via executable file header analysis (April 2009)
- :newspaper: Enhanced metamorphic techniques-A case study against havex malware (August 2021) :star:
- :notebook: Enhancing machine learning based malware detection model by reinforcement learning (November 2018)
- :notebook: Entropy analysis to classify unknown packing algorithms for malware detection (May 2016) :star:
- :newspaper: An entropy-based distance measure for analyzing and detecting metamorphic malware (June 2018)
- :notebook: Entropy-driven visualization in gview: Unveiling the unknown in binary file formats (September 2024) :star:
- :newspaper: ERMDS: A obfuscation dataset for evaluating robustness of learning-based malware detection system (May 2023)
- :notebook: ESCAPE: Entropy score analysis of packed executable (October 2012)
- :notebook: Ether: Malware analysis via hardware virtualization extensions (October 2008)
- :notebook: Eureka: A framework for enabling static malware analysis (October 2008)
- :newspaper: Evading anti-malware engines with deep reinforcement learning (March 2019) :star:
- :notebook: Evading packing detection: Breaking heuristic-based static detectors (July 2024) :star:
- :notebook: Experimental comparison of machine learning models in malware packing detection (September 2020) :star:
- :notebook: An experimental study on identifying obfuscation techniques in packer (June 2016)
- :notebook: Experimental toolkit for manipulating executable packing (June 2024) :star: :star:
- :mortar_board: Experimental toolkit for studying executable packing - Analysis of the state-of-the-art packing detection techniques (June 2022) :star:
- :notebook: Exploring adversarial examples in malware detection (May 2019) :star:
- :newspaper: Fast and robust fixed-point algorithms for independent component analysis (May 1999)
- :notebook: A fast flowgraph based classification system for packed and polymorphic malware on the endhost (April 2010)
- :notebook: A fast randomness test that preserves local detail (October 2008)
- :newspaper: Feature selection for malware detection based on reinforcement learning (December 2019)
- :newspaper: Feature selection for packer classification based on association rule mining (August 2024) :star:
- :notebook: Feature set reduction for the detection of packed executables (June 2014)
- :newspaper: File packing from the malware perspective: Techniques, analysis approaches, and directions for enhancements (December 2022) :star: :star:
- :notebook: Fileprints: Identifying file types by n-gram analysis (June 2005)
- :notebook: A fine-grained classification approach for the packed malicious code (October 2012)
- :newspaper: A framework for metamorphic malware analysis and real-time detection (February 2015)
- :newspaper: Functionality-preserving black-box optimization of adversarial windows malware (May 2021) :star:
- :newspaper: G3MD: Mining frequent opcode sub-graphs for metamorphic malware detection of existing families (December 2018)
- :bookmark: Generating adversarial malware examples for black-box attacks based on GAN (February 2020) :star:
- :notebook: A generic approach to automatic deobfuscation of executable code (May 2015) :star:
- :notebook: Generic black-box end-to-end attack against state of the art API call based malware classifiers (September 2018) :star:
- :newspaper: Generic packing detection using several complexity analysis for accurate malware detection (January 2014)
- :notebook: Generic unpacker of executable files (April 2015)
- :notebook: Generic unpacking method based on detecting original entry point (November 2013)
- :bookmark: Generic unpacking of self-modifying, aggressive, packed binary programs (May 2009)
- :notebook: Generic unpacking techniques (February 2009)
- :notebook: Generic unpacking using entropy analysis (October 2010)
- :notebook: GUARD: Generic API de-obfuscation and obfuscated malware unpacking with sIAT (March 2025) :star:
- :newspaper: Hashing-based encryption and anti-debugger support for packing multiple files into single executable (February 2018)
- :notebook: A heuristic approach for detection of obfuscated malware (June 2009)
- :newspaper: A heuristics-based static analysis approach for detecting packed PE binaries (October 2013)
- :notebook: Highlighting the impact of packed executable alterations with unsupervised learning (April 2025) :star:
- :newspaper: Hunting for metamorphic engines (November 2006)
- :newspaper: Identifying malware packers through multilayer feature engineering in static analysis (February 2024) :star:
- :notebook: An implementation of a generic unpacking method on Bochs Emulator (September 2009)
- :newspaper: An improved method for packed malware detection using PE header and section table information (September 2019)
- :newspaper: Improving malware detection using multi-view ensemble learning (August 2016) :star:
- :scroll: Incremental clustering of malware packers using features based on transformed CFG (November 2022) :star:
- :notebook: Information theoretic method for classification of packed and encoded files (September 2015)
- :notebook: Instructions-based detection of sophisticated obfuscation and packing (October 2014)
- :bookmark: Intriguing properties of adversarial ML attacks in the problem space (March 2020) :star:
- :bookmark: Intriguing properties of neural networks (February 2014)
- :newspaper: A learning model to detect maliciousness of portable executable using integrated feature set (January 2017)
- :bookmark: Learning to evade static PE machine learning malware models via reinforcement learning (January 2018) :star:
- :notebook: Limits of static analysis for malware detection (December 2007)
- :green_book: Longitudinal study of the prevalence of malware evasive techniques (December 2021) :star:
- :bookmark: MAB-Malware: A reinforcement learning framework for attacking static malware classifiers (April 2021) :star:
- :notebook: A machine-learning-based framework for supporting malware detection and analysis (September 2021) :star:
- :mortar_board: Maitland: Analysis of packed and encrypted malware via paravirtualization extensions (June 2012)
- :notebook: Mal-EVE: Static detection model for evasive malware (August 2015)
- :newspaper: Mal-flux: Rendering hidden code of packed binary executable (March 2019)
- :newspaper: Mal-XT: Higher accuracy hidden-code extraction of packed binary executable (November 2018)
- :newspaper: Mal-xtract: Hidden code extraction using memory analysis (January 2017)
- :newspaper: MaliCage: A packed malware family classification framework based on DNN and GAN (August 2022) :star:
- :newspaper: The MALICIA dataset: Identification and analysis of drive-by download operations (February 2015)
- :newspaper: Malware analysis using multiple API sequence mining control flow graph (July 2017)
- :newspaper: Malware analysis using visualized images and entropy graphs (February 2015)
- :mortar_board: Malware detection through opcode sequence analysis using machine learning (June 2015)
- :notebook: Malware family classification method based on static feature extraction (December 2017)
- :notebook: Malware images: Visualization and automatic classification (July 2011)
- :notebook: Malware makeover: Breaking ML-based static analysis by modifying executable bytes (May 2021) :star:
- :notebook: Malware obfuscation techniques: A brief survey (November 2010)
- :notebook: Malware obfuscation through evolutionary packers (July 2015)
- :newspaper: Malwise - An effective and efficient classification system for packed and polymorphic malware (June 2013)
- :notebook: McBoost: Boosting scalability in malware collection and analysis using statistical classification of executables (December 2008)
- :closed_book: Measuring and defeating anti-instrumentation-equipped malware (June 2017)
- :notebook: Memory behavior-based automatic malware unpacking in stealth debugging environment (October 2010)
- :notebook: MetaAware: Identifying metamorphic malware (December 2007)
- :notebook: Metadata recovery from obfuscated programs using machine learning (December 2016)
- :newspaper: Metamorphic malware detection based on support vector machine classification of malware sub-signatures (September 2016)
- :newspaper: Metamorphic malware identification using engine-specific patterns based on co-opcode graphs (August 2020) :star:
- :newspaper: Mimicking anti-viruses with machine learning and entropy profiles (2019-05-21)
- :notebook: MLxPack: Investigating the effects of packers on ML-based malware detection systems using static and dynamic traits (May 2022) :star:
- :notebook: Modern Linux malware exposed (June 2018)
- :newspaper: MSG: Missing-sequence generator for metamorphic malware detection (March 2025) :star:
- :notebook: MutantX-S: Scalable malware clustering based on static features (June 2013)
- :notebook: The new signature generation method based on an unpacking algorithm and procedure for a packer detection (February 2011)
- :bookmark: Novel feature extraction, selection and fusion for effective malware family classification (March 2016)
- :newspaper: A novel framework for image-based malware detection with a deep neural network (October 2021) :star:
- :notebook: Obfuscation-resilient executable payload extraction from packed malware (August 2021) :star:
- :newspaper: Obfuscation: The hidden malware (August 2011)
- :notebook: Obfuscation: Where are we in anti-DSE protections? (a first attempt) (December 2019)
- :notebook: Obfuscator-LLVM: Software protection for the masses (May 2015)
- :notebook: OmniUnpack: Fast, generic, and safe unpacking of malware (December 2007)
- :newspaper: On deceiving malware classification with section injection (August 2022) :star:
- :bookmark: On evaluating adversarial robustness (February 2019) :star:
- :notebook: On the (Im)possibility of obfuscating programs (August 2001)
- :newspaper: On the (im)possibility of obfuscating programs (2) (April 2012)
- :newspaper: On the adoption of anomaly detection for packed executable filtering (June 2014)
- :notebook: On the feasibility of malware unpacking via hardware-assisted loop profiling (August 2023) :star:
- :newspaper: Opcode sequences as representation of executables for data-mining-based unknown malware detection (May 2013) :star:
- :newspaper: Opcodes as predictor for malware (January 2008)
- :notebook: OPEM: A static-dynamic approach for machine-learning-based malware detection (September 2012)
- :newspaper: Original entry point detection based on graph similarity (April 2024) :star:
- :newspaper: An original entry point detection method with candidate-sorting for more effective generic unpacking (January 2015)
- :notebook: Packed code detection using shannon entropy and homomorphic encrypted executables (October 2024) :star:
- :newspaper: Packed malware detection using entropy related analysis: A survey (November 2015)
- :newspaper: Packed malware variants detection using deep belief networks (March 2020)
- :notebook: Packed PE file detection for malware forensics (December 2009)
- :newspaper: Packer classification based on association rule mining (July 2022) :star:
- :notebook: Packer classifier based on PE header information (April 2015)
- :newspaper: Packer detection for multi-layer executables using entropy analysis (March 2017) :star:
- :notebook: Packer identification based on metadata signature (December 2017) :star:
- :notebook: Packer identification method based on byte sequences (November 2018)
- :notebook: Packer identification method for multi-layer executables with k-Nearest neighbor of entropies (October 2020) :star:
- :notebook: Packer identification using byte plot and Markov plot (September 2015)
- :notebook: Packer identification using hidden Markov model (November 2017)
- :mortar_board: Packer-complexity analysis in PANDA (January 2018)
- :notebook: PackGenome: Automatically generating robust YARA rules for accurate malware packer detection (November 2023) :star:
- :bookmark: PackHero: A scalable graph-based approach for efficient packer identification (July 2025) :star:
- :mortar_board: Packing detection and classification relying on machine learning to stop malware propagation (December 2021) :star:
- :mortar_board: Pandora’s Bochs: Automatic unpacking of malware (January 2008)
- :notebook: Pattern recognition techniques for the classification of malware packers (July 2010)
- :newspaper: PE file features in detection of packed executables (January 2012)
- :notebook: PE file header analysis-based packed PE file detection technique (PHAD) (October 2008)
- :notebook: PE-Miner: Mining structural information to detect malicious executables in realtime (September 2009)
- :notebook: PE-Probe: Leveraging packer detection and structural information to detect malicious portable executables (June 2009)
- :notebook: PEAL - Packed executable analysis (January 2012)
- :newspaper: Performance evaluation of filter-based feature selection techniques in classifying portable executable files (January 2018) :star:
- :newspaper: PEzoNG: Advanced packer for automated evasion on Windows (December 2022) :star:
- :newspaper: Pitfalls in machine learning for computer security (October 2024)
- :notebook: PolyPack: An automated online packing service for optimal antivirus evasion (August 2009)
- :notebook: PolyUnpack: Automating the hidden-code extraction of unpack-executing malware (December 2006)
- :newspaper: Potent and stealthy control flow obfuscation by stack based self-modifying code (April 2013)
- :newspaper: Practical attacks on machine learning: A case study on adversarial windows malware (September 2022) :star:
- :notebook: Preprocessing of binary executable files towards retargetable decompilation (July 2013)
- :notebook: Prevalence and impact of low-entropy packing schemes in the malware ecosystem (February 2020) :star:
- :notebook: Program obfuscation by strong cryptography (February 2010)
- :notebook: RAMBO: Run-Time packer analysis with multiple branch observation (July 2016)
- :mortar_board: REFORM: A framework for malware packer analysis using information theory and statistical methods (April 2010)
- :notebook: Renovo: A hidden code extractor for packed executables (November 2007)
- :notebook: RePEconstruct: Reconstructing binaries with self-modifying code and import address table destruction (October 2016)
- :notebook: RePEF — A system for restoring packed executable file for malware analysis (July 2011)
- :newspaper: Replacement attacks against VM-protected applications (September 2012)
- :notebook: Research and implementation of compression shell unpacking technology for PE file (May 2009)
- :newspaper: Research and implementation of packing technology for PE files (January 2013)
- :notebook: Research of software information hiding algorithm based on packing technology (September 2020)
- :newspaper: Resurrecting anti-virtualization and anti-debugging: Unhooking your hooks (March 2021) :star:
- :newspaper: Revealing packed malware (September 2008)
- :notebook: Reverse engineering self-modifying code: Unpacker extraction (October 2010)
- :mortar_board: Robust static analysis of portable executable malware (December 2014)
- :notebook: SATURN - Software deobfuscation framework based on LLVM (November 2019)
- :newspaper: SCORE: Source code optimization & reconstruction (July 2020)
- :notebook: SE-PAC: A self-evolving packer classifier against rapid packers evolution (April 2021) :star:
- :newspaper: Secure and advanced unpacking using computer emulation (August 2007)
- :notebook: Semi-supervised learning for packed executable detection (September 2011)
- :notebook: Semi-supervised learning for unknown malware detection (April 2011)
- :newspaper: Sensitive system calls based packed malware variants detection using principal component initialized multilayers neural networks (September 2018)
- :newspaper: Sequential opcode embedding-based malware detection method (March 2022) :star:
- :newspaper: Singular value decomposition and metamorphic detection (November 2015)
- :newspaper: SMASH: A malware detection method based on multi-feature ensemble learning (August 2019)
- :newspaper: Software protection through anti-debugging (May 2007)
- :notebook: SoK: (state of) the art of war: Offensive techniques in binary analysis (May 2016)
- :notebook: SoK: Automatic deobfuscation of virtualization-protected applications (August 2021) :star:
- :notebook: SoK: Deep packer inspection: A longitudinal study of the complexity of run-time packers (May 2015) :star:
- :mortar_board: Source-free binary mutation for offense and defense (December 2014)
- :notebook: SPADE: Signature based packer detection (August 2012)
- :notebook: Static analysis method on portable executable files for REMNUX based malware identification (October 2019)
- :notebook: Static analysis of executables to detect malicious patterns (August 2003)
- :mortar_board: Static features exploration for executable packing with unsupervised learning (June 2023) :star:
- :newspaper: Static malware detection & subterfuge: Quantifying the robustness of machine learning and current anti-virus (June 2018)
- :notebook: A static, packer-agnostic filter to detect similar malware samples (July 2012)
- :newspaper: Structural analysis of binary executable headers for malware detection optimization (May 2017)
- :newspaper: Structural entropy and metamorphic malware (November 2013)
- :notebook: Structural feature based anomaly detection for packed executable identification (June 2011)
- :notebook: The study of evasion of packed PE from static detection (June 2012)
- :notebook: A study of the packer problem and its solutions (September 2008)
- :newspaper: A survey on adversarial attacks for malware analysis (December 2024) :star:
- :newspaper: A survey on automated dynamic malware-analysis techniques and tools (March 2008)
- :notebook: A survey on machine learning-based detection and classification technology of malware (September 2021) :star:
- :newspaper: A survey on malware analysis techniques: Static, dynamic, hybrid and memory analysis (September 2018)
- :notebook: Survey on malware evasion techniques: State of the art and challenges (February 2012)
- :newspaper: A survey on run-time packers and mitigation techniques (November 2023) :star: :star:
- :notebook: Symbolic deobfuscation: From virtualized code back to the original (July 2018)
- :notebook: Symbolic execution of obfuscated code (October 2015) :star:
- :notebook: Syntia: Synthesizing the semantics of obfuscated code (August 2017)
- :newspaper: A systematical and longitudinal study of evasive behaviors in windows malware (February 2022) :star:
- :bookmark: Technical report on the cleverhans v2.1.0 adversarial examples library (June 2018) :star:
- :notebook: Things you may not know about Android (Un) packers: A systematic study based on whole-system emulation. (February 2018)
- :notebook: Thwarting real-time dynamic unpacking (January 2011)
- :notebook: A token strengthened encryption packer to prevent reverse engineering PE files (January 2015)
- :notebook: Toward generic unpacking techniques for malware analysis with quantification of code revelation (August 2009)
- :notebook: Towards paving the way for large-scale Windows malware analysis: Generic binary unpacking with orders-of-magnitude performance boost (October 2018) :star:
- :notebook: Towards static analysis of virtualization-obfuscated binaries (October 2012)
- :bookmark: Transcending transcend: Revisiting malware classification in the presence of concept drift (December 2021) :star:
- :notebook: Tutorial: An overview of malware detection and evasion techniques (December 2018)
- :newspaper: Two techniques for detecting packed portable executable files (June 2013)
- :notebook: Unconditional self-modifying code elimination with dynamic compiler optimizations (October 2010)
- :notebook: Understanding Linux malware (May 2018)
- :notebook: Unknown malcode detection using OPCODE representation (December 2008)
- :notebook: A unpacking and reconstruction system-agunpacker (January 2009)
- :mortar_board: Unpacking framework for packed malicious executables (July 2013)
- :closed_book: Unpacking malware in the real world: A step-by step guide (July 2024) :star:
- :newspaper: Unpacking techniques and tools in malware analysis (September 2012)
- :notebook: Unpacking virtualization obfuscators (August 2009)
- :mortar_board: Unsupervised clustering machine learning on packed executable (June 2022) :star:
- :newspaper: UnThemida: Commercial obfuscation technique analysis with a fully obfuscated program (July 2018) :star:
- :newspaper: Using entropy analysis to find encrypted and packed malware (March 2007)
- :notebook: VABox: A virtualization-based analysis framework of virtualization-obfuscated packed executables (June 2021) :star:
- :notebook: VMAttack: Deobfuscating virtualization-based packed binaries (August 2017)
- :notebook: VMHunt: A verifiable approach to partially-virtualized binary code simplification (October 2018) :star:
- :notebook: VMRe: A reverse framework of virtual machine protection packed binaries (June 2019)
- :newspaper: Watermarking, tamper-proofing, and obfuscation - Tools for software protection (August 2002)
- :newspaper: Wavelet decomposition of software entropy reveals symptoms of malicious code (December 2016)
- :notebook: When malware is packin’ heat; limits of machine learning classifiers based on static analysis features (January 2020) :star: :star:
- :newspaper: WYSINWYX: What you see is not what you execute (August 2010)
- :newspaper: x64Unpack: Hybrid emulation unpacker for 64-bit Windows Environments and detailed analysis results on VMProtect 3.4 (July 2020) :star:
- :notebook: Xunpack: Cross-Architecture unpacking for Linux IoT malware (October 2023) :star:
:bookmark_tabs: データセット
- BODMAS - DLS’21論文用コード - BODMAS: PEマルウェアのベースド分析に基づく時系列分析用オープンデータセット
- Contagio - 最新のマルウェアサンプル、脅威、観察、分析の収集
- CyberCrime - C²トラッキングとマルウェアデータベース
- Dataset of Packed ELF - パッケージされたELFサンプルのコンパイル
- Dataset of Packed PE - オリジナルデータセットPackingDataのクリーンバージョン。Notpackedフォルダからパッケージされたサンプルを削除し、パッカーフォルダに格納されたがパッキングに失敗したサンプル(元のアンパッケージ済み実行ファイルとハッシュが同じ)も削除。
- Ember - PEファイルから抽出された特徴量を収集したベンチマークデータセット
- Ember2024 - EMBER2017およびEMBER2018データセットへのアップデート
- FFRI Dataset Scripts - FFRIデータセットのようなデータセットの作成
- MaleX - 1,044,394のWindows実行ファイルバイナリと、それらに対応する画像表現を含む、マルウェアおよび良性実行ファイルサンプルのキュレートされたデータセット。そのうち864,669がマルウェア、179,725が良性とラベル付けされている。
- Malfease - 約5,000のパッケージされたマルウェアサンプルを収集したデータセット
- Malheur - 悪意のあるソフトウェア(マルウェア)の記録された行動を含み、マルウェア行動の分類およびクラスタリング手法の開発に使用された(2011年のJCS論文を参照)。
- Malicia - 2013年に11ヶ月間、500台のドライブバイダウンロードサーバーから収集された11,688件の悪意のあるPEファイル(終了済み)。
- MalShare - 研究者にサンプル、悪意のあるフィード、Yara結果のアクセスを提供する無料マルウェアリポジトリ
- Malware Archive - マルウェアサンプル、分析演習、その他興味深いリソース
- The Malware Museum - 1980年代および1990年代に家庭用コンピュータに配布されたマルウェアプログラム(通常はウイルス)の収集
- MalwareBazaar - abuse.chが運営するプロジェクト。マルウェアサンプルを収集・共有し、ITセキュリティ研究者および脅威分析士が自らの顧客や構成員をサイバー脅威から守るために支援するもの。
- MalwareGallery - インターネット上にあるもう一つのマルウェアコレクション。
- MalwareSamples - インターネット上にある最悪のファイルの中から最も良いものを提供する。
- MalwareTips - マルウェアおよびサイバー脅威に関する最新情報とリソースを提供するコミュニティ運営プラットフォーム。
- OARC Malware Dataset - OARCが2005年9月から2006年1月までの間、メールトラップ、ユーザーの提出、ハーネットなどから収集した3,467サンプルの半公開データセット。資格のある学術および産業研究者に要望に基づいて提供可能。
- Open Malware Project - マルウェアサンプルのオンラインコレクション(以前はOffensive Computing)
- PackingData - 元のデータセット。サンプルPEファイルが、ASPack、BeRoEXEPacker、exe32pack、eXpressor、FSG、JDPack、MEW、Molebox、MPRESS、Neolite、NSPack、Pckman、PECompact、PEtite、RLPack、UPX、WinUpack、Yoda’s CrypterおよびYoda’s Protectorなど、多様なパッカーでパッケージ化されたデータセット。
- Packware - 論文『When Malware is Packing Heat』における実験を再現するために必要なデータセットとコード。
- RCE Lab - Crackme、keygenme、serialme;「tuts4you」フォルダには多数のパッケージ化されたバイナリが含まれている。
- Runtime Packers Testset - 10の一般的なマルウェアファイルのデータセット。約40のランタイムパッカーで、500以上のバージョンとオプションでパッケージ化され、合計約5,000のサンプルが含まれている。
- SAC - スロバキアアンチウイルスセンター、AVIRおよびESET社の非営利プロジェクト;パッカー、検出器、アンパッカーを含む。
- SOREL - Sophos-ReversingLabs 2及百万サンプルデータセット。
- theZoo - マルウェア分析の可能性を公開・提供するためのプロジェクト。
- ViruSign - 別のオンラインマルウェアデータベース。
- VirusSamples - インターネット上において最も悪質なファイルの代表例。
- VirusShare - 4400万以上のサンプルを含むオンラインウイルスデータベース。
- VirusSign - デジタル世界におけるマルウェア対策を目的とした巨大なデータベース。
- VirusTotal - マルウェア検出を目的としたファイル分析ウェブサービス。
- VX Heaven - コンピュータウイルスに関する情報提供を目的としたサイト。
- VX Underground - PL-CERTが開発したオープンソースMWDB Pythonアプリケーション。2010年以降のAPTサンプルおよび750万以上の悪意あるバイナリを含むマルウェアデータベースを保持。
- VXvault - オンラインマルウェアデータベース。
- WildList - セキュリティ専門家が報告した野生のマルウェアを共有したリスト。
:package: パッカー
2010年以降
- Alienyze - Windows 32ビット実行ファイル向けの高度なソフトウェア保護およびセキュリティ。
- Alternate EXE Packer - 実行ファイル(EXE)またはDLLに対してUPX 3.96を使用した圧縮ツール。
- Amber - 位置に依存しない(反射的)PEローダー。ネイティブPEファイル(EXE、DLL、SYS)のメモリ内実行を可能にする。
- Andromeda - マルウェアキャンペーンにおけるRunPE技術を用いたカスタムパッカー。AV対策手法の回避を目的としたもの。
- APKProtect - JavaおよびC++をサポートするAPK暗号化とシェル保護。
- Armadillo - PEファイルの保護に、ライセンスマネージャーおよびワッパーシステムを統合。
- ASM Guard - コンパイルされたネイティブコード(ネイティブファイル)を圧縮・複雑化し、リバースエンジニアリングを防ぐためのリバース保護機能を提供。リソースの保護、DRMの追加、最適化されたローダーへのパッキングを実現。
- ASPack - Win32 EXEファイルのパッキングを提供し、非専門的なリバースエンジニアリングから保護する高度なソリューション。
- ASProtect 32 - ソフトウェア開発者向けのマルチ機能EXEパッキングツール。32ビットアプリケーションを保護するための組み込みアプリケーションコピー保護システムを備える。
- ASProtect 64 - Windows上で配布されるソフトウェア製品(インターネットや物理メディア上)の不正使用、産業的および家庭用コピー、プロフェッショナルなハッキングおよび分析を防ぐための64ビットアプリケーションおよび.NETアプリケーションの保護ツール。
- Astral-PE - ネイティブWindows PEファイル(x32/x6-4)向けの低レベル変換器(ヘッダー/エントリーポイントの暗号化)。
- AutoIT - 合法的な実行ファイル暗号化サービス。
- AxProtector - 保護したいソフトウェア全体を暗号化し、セキュリティシェルを適用。その後、あなたのソフトウェアに最高レベルのアンディバッグおよびアンディディアスマイズ手法をインジェクト。
- Backpack
- BangCle - 第二世代Android強化保護を用いた保護ツール。動的にメモリから暗号化されたDEXファイルを読み込む。
- Bero - 32ビットWindows実行ファイル向けのBEP(Bero EXE Packer)。
- BIN-crypter - クリッカーおよびデコンパイラに対するEXE保護ソフトウェア。
- BoxedApp Packer
- Code Virtualizer - Windows、LinuxおよびmacOSアプリケーション向けの強力なコード暗号化システム。開発者がリバースエンジニアリングから敏感なコード領域を保護できるように、コード仮想化に基づく非常に強い暗号化を提供。
- ConfuserEx - .NETアプリケーション向けのオープンソース・無料保護ツール。
- Crinkler - Windows向けの圧縮リンクエラー。特に、数キロバイト程度のサイズの実行ファイルに特化。
- DarkCrypt - Total Commanderに組み込まれたシンプルかつ強力なプラグイン。100アルゴリズムと5モードを使用したファイル暗号化を実現。
- DexGuard - モバイルアプリケーション保護向けのAndroidアプリ暗号化およびセキュリティプロトコル。
- DexProtector - AndroidおよびiOSアプリケーションを静的および動的分析、不正使用、改ざんから保護するマルチレイヤーRASPソリューション。
- DotBundle - .NETアプリケーションまたは.NETライブラリを圧縮・暗号化・パスワード保護するためのGUIツール。
- DotNetZ - シンプルで軽量なC言語で書かれたコマンドラインツールで、Microsoft .NET Frameworkの実行ファイルを圧縮およびパッケージ化できる。
- ElecKey - ソフトウェア保護、コピー保護、ライセンス管理を完全に解決するソフトウェアとツールのセット。
- ELF Packer - 64ビットELFファイルを暗号化し、実行時に入力で復号する。
- ELF-Encrypter - さまざまなアルゴリズムを使用してELFバイナリを暗号化するプログラムのコレクション。
- ELF-Packer - シンプルなポリモーフィックx86_64実行時コードセグメント暗号化ツール。
- ELFCrypt - RC4暗号を使用したシンプルなELF暗号化ツール。
- ELFkickers - ELFファイルをアクセスおよび操作するプログラムのコレクション。
- ELFuck - sk2によるi386用のオリジナル版ELFパッカー(sdによる)。
- Enigma Protector - 実行ファイルのライセンスおよび保護を専門的に提供するシステム。
- Enigma Virtual Box - Windows用のアプリケーション仮想化システム。
- Eronona-Packer - win32環境下のexeファイル用のパッカー。
- EXE Bundle - アプリケーションファイルを1つのPE32ファイルにまとめる。
- EXE Stealth - Anti-cracking protection and licensing tool for PE files featuring compression and encryption polymorphic technology.
- Ezuri - シンプルなLinux ELF実行時暗号化ツール。
- GzExe - シェルスクリプトで実行可能な実行ファイルを圧縮するユーティリティ。
- hXOR-Packer - Huffman圧縮とXOR暗号を用いたPEパッカー。
- Hyperion
- LIAPP - 最も簡単で最も強力なモバイルアプリケーションセキュリティソリューション。
- LM-X License Manager - さまざまなレベルのセキュリティを強制することで、製品のパリティ防止を実現し、時間の節約とビジネスリスクの軽減を達成する。
- LZPACK - LZPACK - ANSI Cで書かれたPopCom!対応CP/M-80実行ファイル圧縮ツール。48K CP/M-80、CP/M-86、MS-DOS、UNIX、およびその他のプラットフォームで動作。
- m0dern_p4cker - ELFバイナリ向けの現代的なパッカー(Linux実行ファイルのみ対応)。
- MidgetPack - ELFバイナリパッカー(例:burneye、upxやその他のツール)。
- MPRESS - LZMAで圧縮し、PE、.NETまたはMach-Oプログラムを逆エンジニアリングから保護します
- NetCrypt - .NET実行ファイル向けの概念実証パッカー。逆エンジニアリングの基本原理を説明するための出発点を提供するように設計されています
- .netshrink - LZMAを使用したWindowsまたはLinuxの.NETアプリケーション実行ファイル向けの実行ファイル圧縮ツール
- NPack - Can compress 32bits and 64bits exe, dll, ocx, scr Windows program.
- Obsidium - 32ビットおよび64ビットWindowsソフトウェアアプリケーションおよびゲームを逆エンジニアリングから保護するための、コスト効率的かつ実装が容易であり、信頼性があり非侵襲的なプロフェッショナルなソフトウェア保護およびライセンスシステム
- oplzkwp - ELFの暗号化用ライブラリ;PRESENとblake244を使用して、実行時に行き先のデータを暗号化します
- Origami - .NETアセンブリを圧縮するパッカー(PEフォーマットをデータストレージに悪用)
- OS-X_Packer - Mach-Oファイルフォーマット向けのバイナリパッカー
- Pakkero - Goで書かれたバイナリパッカー。趣味や教育目的のために作成されました
- Pakr - macOSのMach-Oバンドル向けのメモリ内パッカー
- Papaw - LZMA、ZstandardまたはDeflate圧縮を使用したELF実行ファイル向けの緩やかにライセンスされたパッカー
- PE-Packer - 32ビットPEファイル向けのシンプルパッカー
- PE-Toy - PEファイルパッカー
- PELock - Windows実行ファイル向けのソフトウェア保護システム;アプリケーションの改ざんや逆エンジニアリングを防ぎ、ソフトウェアライセンスキー管理に幅広いサポートを提供します。時間試用期間のサポートも含みます
- PePacker - .textセクションを暗号化し、最後のセクションの末尾にデクリプトスタブを追加するシンプルPEパッカー。私はシンプルなPEファイルパッカーをリリースしました。
- PEShield - PE-SHiELDは、32ビットWindowsのEXEファイルを暗号化し、それらを実行可能に残すプログラムです
- PESpin
- PEtite - 無料のWin32(Windows 、95/98/2000/NT/XP/Vista/7など)実行ファイル(EXE/DLLなど)圧縮ツール
- PEzoNG - Windows環境において非常に低い検出率を目標とした、自動的にステルスバイナリを作成するためのフレームワーク
- PEzor - オープンソースのシェルコードおよびPEパッカー
- pocrypt - GNU/Linux ELF64向けのナチュラルな概念実証暗号化ツール
- ProtectMyTooling - 複数パッカーをチェーンで接続できるマルチパッカーのラッパー
- ps2-packer - PS2で実行可能なパッケージ化されたELFファイルを作成します
- RapidEXE - PHP/Pythonスクリプトをスタンドアローン実行ファイルに変換するためのシンプルかつ効率的な方法
- sherlocked
- Silent-Packer - Silent Packerは純粋Cで書かれたELF/PEパッカーです
- Simple-PE32-Packer - aPLib圧縮ライブラリを使用したシンプルなPE32パッカー
- SimpleDPack - PE構造を学習または調査するための非常にシンプルなWindows EXEパッキングツール
- Smart Packer - 32ビットおよび64ビットアプリケーションにDLL、データファイル、第三者ランタイムを1つの実行ファイルにパッキングし、インストールなしで即時実行します
- Squishy - 64kbデモシーン向けに開発された現代的なパッカーで、32ビットおよび6-4ビット実行ファイルをターゲットにします
- theArk - Windows x86 PEパッカー(C++で書かれた)
- Themida - Renovoの紙から:Themidaは元のx86命令を、自らのランダム化された命令セット内の仮想命令に変換し、実行時においてそれらの仮想命令を解釈します
- TinyLoad - Windows向けのシンプルなPEパッカーで、カスタム仮想マシンを使用して実行ファイルを圧縮・暗号化し、セルフエクストラクトスタブに変換します
- UPX - 実行ファイル用の究極のパッカー
- VirtualMachineObfuscationPoC - 仮想マシンを用いた暗号化手法
- VMProtect - 非標準アーキテクチャの仮想マシン上でコードを実行することで、ソフトウェアの分析やクラックを極めて困難にします
- Ward - ELFパッカーのシンプルな実装で、メモリ内に悪意あるELFをロードするためのステルスドロッパーを作成します
- Woody Wood Packer - ELFパッカー - 実行可能なELFバイナリターゲットに暗号化し、自訂解暗号コードを注入します
- xorPacker - すべてのPEファイルに対応するシンプルなパッカーで、EXEをXOR実装で暗号化します
- XyrisPack
- zELF - Linux x86_64向けのモジュラーフォーマットELF64パッカーで、22の圧縮コード、機械学習ベースのコード選択、静的およびPIEバイナリの両方をサポートします
- ZProtect - メタデータエンティティをリネームし、高度な暗号化手法をサポートして保護スキームを強化し、逆エンジニアリングを完全に防ぎます
2000〜2010年
- 20to4 - 約20kの最高品質のコードとデータを4k未満に詰め込み可能な実行ファイル圧縮ツール
- ACProtect - Windows実行ファイルをパirateから保護するためのアプリケーションで、RSAを使用して登録キーとアンロックコードを作成・検証します
- AHPack - PEおよびPE+ファイルパッカー
- Application Protector - Windowsアプリケーションを保護するツール
- AT4RE Protector - ASMで書かれた非常にシンプルなPEファイル保護ツール
- AverCryptor - ノートを暗号化する小さな便利なユーティリティ。そのノートに任意のプライベート情報を保存できる。これは、ウイルス対策ソフトからあなたの感染を隠すのを助ける。
- BurnEye - ELF暗号化プログラム、x86-linuxバイナリ
- ByteBoozer - コモドール64の実行ファイルパッカー
- cryptelf - バイナリを変更し、実行時暗号化を処理するコードを追加、プログラムのEPを変更し、.noteセグメントをLOADに変更。.textセクションをキーバイトとXORで暗号化。
- CryptExec - オンデマンド関数抽出を用いた次世代実行時バイナリ暗号化
- EXE Guarder - PEファイルにライセンスツールを提供し、圧縮およびパスワード通知を指定できる。
- EXE Wrapper - 非認可実行からEXEファイルをパスワードで保護。
- Exe32Pack - Win32のEXE、DLLなどに圧縮し、実行時に動的に展開。
- EXECryptor - EXEプログラムから逆エンジニアリング、分析、変更、クラッキングを防ぐ。
- ExeFog - シンプルなWin3TPEファイルパッカー
- eXPressor - このツールを圧縮器として使うと、EXEファイルを通常のサイズの半分に圧縮できる。
- FSG - Fast Small Good、小さなEXE向けの完璧な圧縮ツール、例:
- GHF Protector - オープンソースエンジンMorphineおよびAHPackに基づく実行ファイルパッカー/保護ツール
- HackStop - EXEおよびCOMプログラムの暗号化および保護ツール
- Kkrunchy - 64kのイントロ向けに主に設計された小さなEXEパッカー
- Laturi - macOS 1k、4kおよびおそらく64Kイントロ用に設計されたリンカーおよび圧縮ツール
- mPack - マリオパッカー シンプルなWin32 PE実行ファイル圧縮ツール
- NSPack - 32/64ビットexe、dll、ocx、scrのWindowsプログラム圧縮ツール
- NTPacker - PEファイル圧縮器で、aPlibによる圧縮および/またはXORによる暗号化を用いる
- PECompact - 第三者プラグインを備えたWindows実行ファイル圧縮ツールで、逆エンジニアリング対策を提供
- RDMC - DMCアルゴリズムに基づく圧縮器
- RLPack - 実行ファイルおよび動的リンクライブラリを小さく圧縮し、圧縮後のファイルの機能に影響を与えない
- RSCC - ROSE Super COM Crypt;300~400B以上60kB未満のファイル向けのポリモーフィック暗号化器
- RUCC - ROSE Ultra COM圧縮器;624をベースとしたCOMおよびEXE圧縮ツール
- Sentinel HASP Envelope - ターゲットアプリケーションを安全なシールで保護するアプリケーションで、逆エンジニアリングおよびその他の反デバッグ対策を防ぐ手段を提供
- sePACKER - シンプルな実行ファイル圧縮器は、実行ファイルのコードセクションを圧縮してバイナリファイルのサイズを縮小
- Shiva - Linux環境下のELF実行ファイルの暗号化ツール
- tElock - 開発者が自らの作業を保護し、実行ファイルのサイズを縮小したい場合に役立つ実用ツール
- TTProtect - ソフトウェア開発者向けに、PEアプリケーションに対する不正改変やデコンパイルを防ぐプロフェッショナルな保護ツール
- UPack - Windows PEファイルの圧縮
- UPX-Scrambler - UPX(1.06まで)で圧縮されたファイルをスクラムし、‘-d’オプションで展開できないようにする
- WinUpack - Upack(Windows PEファイルから自己展開アーカイブを作成するコマンドラインツール)のグラフィカルインターフェース
- x86.Virtualizer - x86仮想化ツール
- XComp - PE32イメージファイルのパッキングおよび再構成
- Yoda Crypter - ポリモーフィック暗号化、softice検出、反デバッグAPI、反ダンプなどに対応し、インポートテーブルを暗号化し、PEヘッダーを削除
- Yoda Protector - 無料、オープンソース、32ビットWindowsソフトウェア保護ツール
2000年以前
- 32Lite - Watcom C/C++コンパイラで作成された実行ファイルの圧縮ツール
- 624 - COMパッカーで、25000バイト未満のCOMプログラムを短縮できる
- ABK Scrambler - ABKprotからリコードされたCOMファイルの暗号化・保護ツール
- AEP - COMおよびEXEファイル用の追加暗号保護
- AINEXE - DOS実行ファイルパッカー(AINアーカイバーセットの一部)
- aPack - 16ビットリアルモードDOS実行ファイル(.EXEおよび.COM)圧縮ツール
- AVPack - EXEまたはCOMファイルを暗号化し、そのファイルがあなたのPC上でしか起動できないようにする
- AXE - プログラム圧縮ツール
- BIN-Lock - COMファイルの暗号化により逆エンジニアリングを防ぐ
- BitLok - COMおよびEXEファイルの保護ツール
- CauseWay Compressor - DOS EXEファイルの圧縮ツール
- CC Pro - COMおよびEXE実行ファイルの圧縮ツ及
- CEXE - 入力EXEを小さな実行ファイルに圧縮(WinNT、Win2000以降でのみ実行可能。Win95またはWin98では実行されない)
- COMProtector - DOS .COMファイルに対して、ランダムな暗号化を行い、複数のアンディバグ技術を追加してセキュリティエノールを追加する
- CrackStop - DOS EXEファイルにセキュリティエノールを付加し、クラッカーから保護するツール
- Crunch - COMおよびEXEファイル用のファイル暗号化ツール
- EPack - EXEおよびCOMファイルの圧縮ツール;DOS/Windows95ファイルに対応
- ExeGuard - DOS EXEファイルの無料保護ツール。アンディバグ技術を用いてハッキング、分析、展開を防ぐ
- EXELOCK 666 - .EXEファイルを保護するためのユーティリティ。ライマーがコピーを解読できないようにする
- Fire-Pack
- FSE - 最終幻想セキュリティエノール無料ソフトでCOMおよびEXEプログラムを保護
- Gardian Angel - COMおよびEXEファイルの暗号化および保護を、多様なアンディバグ技術を用いて実現
- JMCryptExe - DOS EXE暗号化ツール
- LGLZ - DOS EXEおよびCOMファイルの改良LZ77による圧縮
- LzExe - MS-DOS実行ファイル圧縮ツール
- Mask - 暗号化およびアンディバグ技術を用いてCOMプログラムのクラックを防ぐツール
- Megalite - MS-DOS実行ファイル圧縮ツール
- Mess - HackStopと同じ機能を提供するが、非商業利用向けに無料ソフトウェアである
- Morphine - PEファイルの暗号化アプリケーション
- Neolite - Windows 32ビットEXEファイルおよびDLLの圧縮
- PACK - 実行ファイル圧縮ツール
- Pack-Ice
- PCShrink - Windows 9x/NT実行ファイル圧縮ツ及にaPLib圧縮ライブラリを用いる
- PE Diminisher - aPLib圧縮ライブラリを用いたシンプルなPEパッカー
- PE-Protector - Windows 9x/ME向けの実行ファイルPEの逆エンジニアリングやクラック防止に非常に強い保護を提供する暗号化・保護ツール
- PEBundle - DLLを物理的に実行ファイルに接続し、メモリ内の依存関係を解決
- PEPack - PE-SHiELDの新バージョンのコードをもとにしたPE圧縮ツール
- PKlite - DOSおよびWindows実行ファイルを圧縮する使いやすいファイル圧縮プログラム
- Pro-Pack - DOS実行ファイル圧縮ツール
- RERP - ROSEのEXEリロケーションパッカー
- RJCrush - オーバーレイを圧縮できるEXEおよびCOMファイル圧縮ツール
- Scorpion - EXEおよびCOMファイルの暗号化および保護ツール
- SecuPack - Win32実行ファイル圧縮ツール
- Shrinker - 16および32ビットのWindowsおよびリアルモードDOSプログラムを70%まで圧縮
- SPack
- $PIRIT - COM/EXE実行ファイルの多様性を持つ暗号化エンクリプタ
- SysPack - デバイスドライバー用の圧縮ツール
- T-Pack - 小規模ファイル(BBSアドレスなど)向けのLZ77によるCOMファイル圧縮
- TinyProg - EXEおよびCOMプログラムの圧縮
- TRAP - EXEおよびCOMファイルの暗号化と保護
- Vacuum - DOS32実行ファイル用の実行時圧縮
- VGCrypt - PE crypter for Win95/98/NT.
- WinLite - DOS環境下でのWindows実行ファイル(例:Pklite、Diet、Wwpackなど)を圧縮
- WWPack - EXEファイルを圧縮し、リロケーションテーブルを最適化し、ヘッダーを最適化し、EXEファイルをハッキングから保護
- XE - PE32イメージファイルのパッキングおよび再構成
- XorCopy - COMファイル用のXORベース暗号化
- XORER - COMファイル用のXORベース暗号化
- XPA - DOS実行ファイル用のパッキングツール
- XPack - EXE/COM/SYS実行ファイルの圧縮
:wrench: ツール
- Android Unpacker - デフォン22で発表されたAndroidハッカー保護レベル0
- Angr - プラットフォームに依存しないバイナリ分析フレームワーク
- APKiD - Androidアプリケーション識別子(パッキング、保護、暗号化、異常な動作など)—PEiD for Android
- aPLib - aPACKが使用するアルゴリズムに基づく圧縮ライブラリ
- AppSpear - ダルヴィックおよびARTに適したユニバーサルかつ自動化されたアンパッキングシステム
- Assiste (Packer) - Assiste.comのパッカー例リスト
- AVClass - Pythonでマルウェアサンプルをタグ/ラベル付けするツール
- Bintropy - バイナリファイルに圧縮または暗号化されたバイトが含まれている可能性を推定するプロトタイプ分析ツール
- BinUnpack - メモリアクセス監視に煩雑な処理を要せず、非常に小さい実行時のオーバヘッドを導入するアンパッキング手法
- Binutils - GNU BinutilsはLinux用のバイナリツールのコレクション(主にReadelfを含む)
- BitBlaze - 静的および動的分析技術、具体的かつ符号化された実行、システム全体のエミュレーションおよびバイナリインストルメンテーションを組み合わせた分析プラットフォームで、現実のセキュリティ問題に関する最先端研究を支援
- Capa - PE、ELF、または.NET実行ファイル内の機能を特定するオープンソースツール
- Capstone - 軽量でマルチプラットフォーム、マルチアーキテクチャ対応のディスアセンブリフレームワーク
- Cave-Finder - PEイメージ(x86 / x64)内のコードケーブを検出するツール(PEファイルにコードを配置できる空き領域を検出)
- CFF Explorer - PE32/64および.NETエディタ、Explorer Suiteの一部
- ChkEXE - ほぼすべてのEXE/COMパッカー、暗号化ツール、保護ツールを特定するツール
- Clamscan Unpacker - ClamAVから派生したアンパッキングツール
- COM2EXE - COMファイルをEXEフォーマットに変換する無料ツール
- de4dot - .NETのデオブフスクエーターおよびアンパッキングツール
- de4js - JavaScriptのデオブフスクエーターおよびアンパッキングツール
- Defacto2 Analyzers Archive - 1990年代および2000年代のMS-DOSおよびWindows32向けの60件のバイナリファイル分析ツールのコレクション
- Defacto2 Packers Archive - 1990年代および2000年代のMS-DOSおよびWindows32向けの460件のバイナリおよびデータファイルパッカーのコレクション
- Defacto2 Unpackers Archive - 1990年代および2000年代のMS-DOSおよびWindows32向けの152件のバイナリファイルアンパッキングツールのコレクション
- DIE - Detect It Easy ; ファイルの種類を特定するプログラム
- DSFF - データセットを交換し、ARFF(Weka用)、CSVまたはPacking-Boxのデータ構造に変換するためのデータセットファイルフォーマット
- DynamoRIO - プログラム実行中に、プログラムのいかなる部分に対してもコード変換をサポートする実行時コード操作システム
- Emulator - Symantec Endpoint Protector (v14以降) が、カスタムウイルスパッカー内部に隠れているマルウェアを特定・発動・除去するために、即座に仮想マシンを生成する機能
- EtherUnpack - 精度の高いユニバーサル自動アンパッカー(PolyUnpackの後継)
- Eureka - バイナリ静的解析用準備フレームワーク。統計的ビッグラム分析と粗粒度実行トレースに基づく新しいバイナリアンパッキング戦略を実装
- EXEInfo-PE - 実行可能ファイル(PEファイル)に対する高速検出
- ExeScan - 実行ファイル分析ツール。最も有名なEXE/COM保護、パッカー、コンバーターおよびコンパイラを検出
- EXETools - 逆エンジニアリングおよび実行ファイルパッキング関連トピックのフォーラム
- FUU - 高速ユニバーサルアンパッカー
- GetTyp - DOSベースのファイルフォーマット検出プログラム(特殊文字列およびバイトコードに基づく)
- GUnpacker - OEP位置決定と復号コードのダンプを行うシェルツール
- Gym-Malware - OpenAIのgym向けのマルウェア操作環境
- IDR - インタラクティブなDelphi再構築ツール
- ImpREC - パッケージされたプログラムのインポートテーブルを修復するために使用できる
- Justin - 即時(Just-In-Time)AVスキャン;一般向けアンパッキングソリューション
- Language 2000 - 最高レベルのコンパイラ検出ツール
- LIEF - 実行ファイル形式をインストルメントするライブラリ;PE、ELF、Mach-O、DEX形式のパース、変更および再構築を行うPythonパッケージ
- Lissom - Retargetable decompiler consisting of a preprocessing part and a decompilation core.
- LordPE - PEヘッダーの閲覧、編集、再構築ツール
- Malheur - マルウェアの行動を自動分析するツール(悪意のあるソフトウェアがサンドボックス環境で記録されたデータに基づく)
- MalUnpack - PE-sieveに基づく動的アンパッカー
- Manalyze - PEファイルに柔軟なプラグインアーキテクチャを備えた頑健なパーサー。ユーザーがファイルを静的に深層分析できるようになる
- MRC - (Mandiant Red Curtain) インシデントレスポンダー向け無料ソフト。マルウェアの分析を支援;実行ファイル(.exe、.dllなど)を指定基準に基づいて異常性を判定する
- .NET Deobfuscator - .NET デオブフスケータおよびアンパッキングツールのリスト
- NotPacked++ - パッキングサンプルを変更して静的パッキング検出を回避する攻撃ツール
- Oedipus - 機械学習アルゴリズムを用いて、ブフスケされたプログラムに対するメタデータ回復攻撃を実装するPythonフレームワーク
- OEPdet - 自動的に元のエントリポイントを検出するツール
- OllyDbg Scripts - 多数のパッカーに対応したアンパッキング用OllyDbgスクリプトのコレクション
- OmniUnpack - 実時間で実行をモニタリングし、パッキング層の削除を検出することで、高速かつ汎用的に安全にマルウェアをアンパッキングする新しい技術
- PackerAttacker - メモリとコードのホックを用いてパッカーを検出するツール
- PackerBreaker - 高度なエミュレーション技術を用いて、パッキング・圧縮・暗号化されたプログラムのほとんどをアンパッキング・解圧・復号するためのツール
- PackerGrind - パッキング行動を追跡し、Androidパッキングアプリをアンパッキングするためのアダプティブアンパッキングツール
- PackerID - PEidシグネチャを用いたpackerid.pyのフォークで、追加の出力タイプ・フォーマット、デジタル署名の抽出、ディスアセンブルサポートを備えている
- PackID - PEiDと同じデータベース構文を使用したマルチプラットフォームパッカー識別ツール/ライブラリ
- Packing-Box - パッキング関連ツールを多数収録したDockerイメージおよび、機械学習に使用するパッキング実行ファイルのデータセット作成用
- PANDA - アーキテクチャに依存しない動的解析プラットフォーム
- PANDI - PANDAに基づいた動的パッキング検出ソリューション
- Pandora’s Bochs - Bochs PCエミュレータへの拡張により、アンパッキングスタブの実行をモニタリングして元のコードを抽出できるようになる
- PCjs - JavaScriptを用いて、オリジナルROM、元の速度で動作するCPU、早期のIBMビデオカードおよびモニタを用いてIBM PC体験を再現
- PE Compression Test - 少数のサンプル実行ファイルを用いてテストしたパッカーのリスト(圧縮サイズの比較用)
- PE Detective - このGUIツールは、単一のPEファイルまたは全体のディレクトリ(再帰的に)をスキャンし、完全なレポートを生成できる
- PE-bear - PEファイル向けのフリーソフトウェアリバースエンジニアリングツールで、マルウェア分析者が速く柔軟に「最初の視点」を提供し、形式が不正なPEファイルにも安定して対応できる
- PEdump - Rubyを使用してWindows PEファイルをダンプする
- Pefeats - PEファイルから機械学習アルゴリズムに使用できる119の特徴量を抽出するためのユーティリティ
- Pefile - マルチプラットフォームのPythonモジュールで、Portable Executableファイルを解析・処理する
- PEFrame - PEマルウェアおよび一般的な疑わしいファイルに対する静的解析を行うツール
- PEiD - パッケージされたエクスエキュブル識別ツール
- PEiD (CLI) - PEiDのPython実装で、新たにシグネチャを作成するための追加ツールを備える
- PEiD (yara) - YARAを用いたPEiDの別の実装
- PeLib - PEファイル操作用のライブラリ
- PEPack - Unixパッケージ”pev”に含まれるPEファイルパッキング検出ツール
- PEscan - PEファイルをスキャンして構成方法を特定するCLIツール
- PETools - PEファイルの操作に用いる、古いスタイルの逆エンジニアリングツール(2002年以降の長い歴史を持つ)
- PEview - 32ビットのPortable Executable(PE)およびComponent Object File Format(COFF)ファイルの構造と内容を、迅速かつ簡単に閲覧できるようにするツール
- PExplorer - 自社開発ソフトウェアや、ソースコードがない第三者のWindowsアプリケーションおよびライブラリの内部動作を検査するための、機能が最も豊富なプログラム
- Pin - IA-32、x86-64およびMIC指令アーキテクチャ向けの動的バイナリインストルメンテーションフレームワークで、動的プログラム分析ツールの作成を可能にする
- PINdemonium - PINの機能を活用したPEファイルのアンパッキングツール
- PolyUnpack - PEファイルの元の隠されたコードを抽出するための一般アプローチの実装試み(ヒューリスティック仮定なし)
- PortEx - PEファイルに対する静的マルウェア分析用のJavaライブラリで、PEの異常性や構造の耐性に焦点を当てたもの
- PROTECTiON iD - PEファイルに基づくシグネチャスキャナー
- ProTools - プログラマー向けツール、真のWinBlozeプログラマー向けに開発されたすべてのツールとユーティリティを提供するウェブサイト(パッカー、暗号化ツールなど)
- PyPackerDetect - 実行ファイルがパッキングされているかどうかを検出するための小さなPythonスクリプト/ライブラリ
- PyPackerDetect (refactored) - 元のプロジェクトをPythonパッケージに完全にリファクタリングし、実行ファイルがパッキングされているかどうかを検出するコンソールスクリプトを提供する
- PyPeid - PEiDのもう一つの実装(yara-pythonによる)
- Quick Unpack - 一般向けのアンパッキングツール(アンパッキングプロセスの進行を支援)
- RDG Packer Detector - パッキング検出ツール
- Reko - マシンコードバイナリ向けの無料デコンパイラ
- REMINDer - エントロピー値とWRITE属性に基づくエントリーポイントセクションのパッキング検出ツール
- REMnux - Linux向けの逆エンジニアリングおよび悪意あるソフトウェアの分析ツール
- Renovo - TEMU(BitBlazeの動的解析コンポーネント)をベースにした、新たに生成されたコードの実行とプログラム開始後のメモリ書き込みをモニタリングした検出ツール
- ResourceHacker - 32ビットおよび64ビットWindowsアプリケーション向けのリソースエディタ
- RetDec - LLVMをベースとしたリターゲット可能なマシンコードデコンパイラ
- RTD - Rose Patch - TinyProt/Rosetinyアンパッカー
- RUPP - ROSE SWE UnPaCKER PaCKaGE(DOS実行ファイル用のみ)
- SAFE - 実行ファイル向けの静的解析ツール(要約で提供)
- SecML Malware - 機械学習を用いたWindowsマルウェア検出器に対する敵対的攻撃の構築
- ShowStopper - マルウェア研究者向けの、アンチデバッグ技術の探索やテスト、または標準アンチデバッグ手法と衝突するデバッガープラグインやその他のソリューションの検証を支援するツール
- StudPE - PEビューアおよびエディタ(32/64ビット)
- SymPack - 安全でポータブルであり、広く効果的だが一般化されていないパッキング検出およびアンパッキング用のライブラリ;ノートンアンチウイルスソリューションの一部
- Titanium Platform - 機械学習を活用したハイブリッドクラウドプラットフォーム。数千のファイルタイプをスケールアップして収集し、機械学習によるバイナリ分析で脅威検出を加速し、10B以上のファイルインデックスを継続的に監視して将来の脅威を検出
- TrID - バイナリ署名からファイルタイプを特定するユーティリティ
- Triton - 動的バイナリ分析ライブラリ
- Tuts 4 You - 非商用、独立したコミュニティ。逆コードエンジニアリングに関する知識と情報の共有を目的としている
- Unipacker - Windowsバイナリ向けの自動かつプラットフォームに依存しないアンパッキングツール(エミュレーションベース)
- UnpacMe - 自動化されたマルウェアアンパッキングサービス
- Unpckarc - 複数のヒューリスティクスを用いたパッケージ済み実行ファイルの検出ツール
- UU - ユニバーサルアンパッカー
- Uundo - ユニバーサルアンダーモー - ユニバーサルアンパッカー
- Uunp (IDA Pro plugin) - IDA Proデバッガープラグインモジュール(パッケージ済みバイナリの分析およびアンパッキングを自動化)
- UUP - ユニバーサルEXEファイルアンパッカー
- VMHunt - 仮想化されたバイナリコードの分析に用いるツールセット(現在は32ビットトレースのみをサポート)
- VMUnpacker - 仮想マシン技術を用いたアンパッカー
- Winbindex - Windowsバイナリの一覧(EXE、DLL、SYSファイルなどの実行ファイルのダウンロードリンクを含む)
- yarGen - YARAルール生成ツール - 主な原理は、マルウェアファイル内の文字列からYARAルールを作成し、良好なソフトウェアファイルにも存在する文字列をすべて削除すること
コントリビューション
コントリビューションを歓迎します。最初にコントリビューションガイドラインを確認してください。