You're Invited:Meet the Socket Team at BlackHat and DEF CON in Las Vegas, Aug 7-8.RSVP
Socket
Socket
Sign inDemoInstall

github.com/andrewstucki/fingerprint

Package Overview
Dependencies
Alerts
File Explorer
Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

github.com/andrewstucki/fingerprint


Version published

Readme

Source

Fingerprint

build status

This repo serves as an experimental library for fingerprinting various files similar to how VirusTotal does.

Besides some general file hashes and file type analysis, it contains some additional parsing modules for Elf, PE, and Mach-o binaries. Included in these are section entropy calculations and imported/exported symbols. Additionally it has implementations of telfhash (Elf), imphash (PE), and symhash (Mach-o) fuzzy symbol hashing algorithms that are fairly useful in malware analysis.

The only dependency required is the capstone library (used for enumerating call sites through disassembling stripped elf binaries for telfhash calculations).

FAQs

Package last updated on 26 Mar 2021

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc