Balbuzard - Documentation

This is the documentation home page for the Balbuzard tools. The online version is here, and a copy can be found in the balbuzard/doc subfolder of the package.

Balbuzard is a package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domain names, known file headers, interesting strings, etc). It can also crack malware obfuscation such as XOR, ROL, etc by bruteforcing and checking for those patterns.

Balbuzard tools

When to use these tools

5 minutes demo

See the Demo page to see examples and test the tools by yourself in a few minutes using the provided samples.

Help wanted:

Documentation pages

See http://www.decalage.info/python/balbuzard for more info and other tools.