Skip to content

Repository files navigation

pipeline status

Dockerfiles for the CinCan project

This repository will automatically build and publish Docker images into Docker Hub, GitHub Container Registry and Quay.io using GitLab CI.

The pipeline will try to build a new image for each directory that has changessince the latest passed commit, once provided tests have been passed. The most of the tools are tested with real samples to see that they work as excepted.

README description of each tool is synchronized into Docker Hub as well.

Actual images can be found from:

For adding a new tool or upgrading the version of existing one, see CONTRIBUTING.md

For running these tools, take an additional look for cincan-command.

Description of the current tools

Linux tools

Stable

Tool nameDescriptionInputPlatform
7zipCommand line port of 7-Zip which provides utilities to (un)pack compressed archives7z, ZIP, GZIP, BZIP2, XZ, TAR, APM, ARJ, CAB, CHM, CPIO, CramFS, DEB, DMG, FAT, HFS, ISO, LZH, LZMA, LZMA2, MBR, MSI, MSLZ, NSIS, NTFS, RAR, RPM, SquashFS, UDF,VHD, WIM, XAR, ZLinux
access-log-visualizationVisualizing webserver's access log data to help detecting malicious activityaccess.log (Apache)Linux
apktoolA tool for reverse engineering 3rd party, closed, binary Android apps..apk, .jarLinux
binwalkFirmware Analysis ToolbinaryLinux
box-psbox-ps - A Powershell sandboxing utility used to deobfuscate PowerShell scriptsps1, psm1Linux
cfrClass File Reader - another java decompiler.jar -fileLinux
clamavClamAV virus scannerAny file or directory.Linux
dex2jarTool to decompile dex files to jarAPK fileLinux
eml_parserParse .eml email filesemlLinux
feature_extractorFeature_extractorlist of possible IoCsLinux
fernflowerAnalytical decompiler for Java.jar, .class, .zipLinux
flawfinderFlawfinder - Finds possible security weaknesses in C/C++ source codeC/C++ codeLinux
flossFireEye Labs Obfuscated String SolverMalware with (obfuscated) stringsLinux
ghidra-decompilerGhidra Headless AnalyzerAny software binary in native instructions.Linux
ilspyILSpy (console only) - version 7.1.0.NET AssemblyLinux
ioc_stringsExtracts urls, hashes, emails, ips, domains and base64 (other) from a file.File/DirectoryLinux
iocextractAdvanced Indicator of Compromise (IOC) extractorFile, STDINLinux
jadxjadx - Dex to Java decompiler.apk, .dex, .jar, .class, .smali, .zip, .aar, .arscLinux
jd-cliCommand line wrapper around JD Core Java Decompiler. Decompiles .dex and .jar -files to java..jar -fileLinux
jsunpack-nJsunpack-n - Emulates browser functionality, detect exploits etc.PDF, URL, PCAP, JavaScript, SWFLinux
luadecluadec: Lua decompiler.luac .luaLinux
manalyzeManalyze - a static analyzer for PE executablesPE filesLinux
mvtMVT - Mobile Verification Toolkit by AmnestyAndroid backup, Android filesystem dump, Android device with adb iTunes/Finder backup, iOS filesystem dumpLinux
oledumpA Program to analyse OLE files..doc, .xls, .pptLinux
oletoolsOletools - a set of tools to analyze Microsoft OLE2 files.doc, .dot, .docm, .dotm, .xml, .mht, .xls, .xlsm, .xlsb, .pptm, .ppsm, VBA/VBScript sourceLinux
osslsigncodeosslsigncodeexe/sys/dllLinux
output-standardizerGenerate md report from Cincan's Concourse pipelines, or convert single tool output to JSON.cincan/binwalk, cincan/pdf2john, cincan/pdfxray_lite and cincan/strings outputsLinux
pastelyzerpastelyzer - find security and privacy related artifacts from text documentstextLinux
pdf-parserPDF-parser - parse PDF to identify fundamental elementsPDFLinux
pdfidPDFID - scan PDFs for certain keywords, triage potentially malicious filesPDFLinux
pdfxray-litePDF X-RAY Lite 1.0 to analyze PDF files for malicious objects.PDFLinux
peepdfPowerful Python tool to analyze PDF documents.PDFLinux
peframePEframe - static analysis for PE executables and MS office documentsPELinux
pyocrOptical character recognition (OCR) wrapper for Tesseract OCR enginePDF, png, jpgLinux
pywhoisPywhois - retrieve information from IP addressesIP / list of IPsLinux
radamsaRadamsa is a test case generator for robustness testing, a.k.a. a fuzzer.Any dataLinux
radare2Radare2 is complete unix-like framework for reverse engineering and binary analysisELF, Mach-O, Fatmach-O, PE, PE+, MZ, COFF, OMF, TE, XBE, BIOS/UEFI, Dyldcache, DEX, ART, CGC, Java class, Android boot image, Plan9 executable, ZIMG, MBN/SBL bootloader, ELF coredump, MDMP (Windows minidump), WASM (WebAssembly binary), Commodore VICE emulator, QNX, Game Boy (Advance), Nintendo DS ROMs and Nintendo 3DS FIRMs, various filesystems.Linux
regripperExtract data from Windows registryWindows registry hive filesLinux
scrape-websiteHeadless Chromium web browserurl, jsonLinux
sleuthkitA collection of command line tools that allows you to analyze disk images and recover files.raw, ewf, vmdk, vhdLinux
snowman-decompileSnowman-decompile - a native code to C/C++ decompilerELF Mach-O PE LELinux
ssdcSsdeep based clustering tool*Linux
ssdeepSsdeep - For computing context triggered piecewise hashes (CTPH), also called fuzzy hashes.*Linux
steghideA Steganography program - hide data (and extract) in various kinds of image- and audio-files.JPEG, BMP, WAV, AULinux
trufflehogTruffleHog Searches through git repositories for accidentally committed secretsgit repositoryLinux
tsharkA Tool for parsing PCAP and capturing network traffic.PCAP, network trafficLinux
vipermonkeyA VBA parser and emulation engine to analyze malicious macros.doc, .dot, .docm, .dotm, .xml, .mht, .xls, .xlsm, .xlsb, .pptm, .ppsm, VBA/VBScript sourceLinux
virustotalOfficial CLI for VirusTotal API. Analyze suspicious files and URLs to detect malware.Linux
volatilityVolatility - An advanced memory forensics framework - 2.6.1 a438e76- Raw linear sample (dd) - Hibernation file (from Windows 7 and earlier) - Crash dump file - VirtualBox ELF64 core dump - VMware saved state and snapshot files - EWF format (E01) - LiME format - Mach-O file format - QEMU virtual machine dumps - Firewire - HPAK (FDPro)Linux
xsvFast CSV command line toolkitcsv, tsvLinux
yaraYara - The pattern matching swiss knifeAny file as targetLinux
zstegdetect stegano-hidden data in PNG and BMPPNG, BMPLinux

In Development

Tool nameDescriptionInputPlatform
headless-thunderbirdHeadless Thunderbird to screenshot email messagesemlLinux
ioc_parserA tool to extract indicators of compromise from security reportsPDF, txt, xlsx, htmlLinux
pdf2johnJohn the Ripper for extracting hash from PDF filesEncrypted PDFLinux

Not maintained anymore

It is very possible that some of these are not working.

Tool nameDescriptionInputPlatform
add2git-lfsADD2GIT-LFSLinux
binary-analysis-tool-batBinary Analysis Tool BAT with extra toolsbinaryLinux
c-ciConcourse CILinux
c-workerConcourse WorkerLinux
dns-toolsLinux
hyperscanHigh-performance regular expression matching libraryLinux
identify-fileIdentify-fileLinux
keyfinderKeyfinderfilesystem, APKLinux
pdf-toolsThe DidierStevensSuite by Didier StevensLinux
pdfexaminerUpload a PDF to www.pdfexaminer.com/pdfapi.php and get resultsPDF filesLinux
pe-scannerGet information of a PE (portable executable) filePE/EXE/DLLLinux
python-extract-codeExtract codePELinux
r2-bin-carverR2 bin carvermemory dumpsLinux
s3-resource-simpleSimple S3 Resource for Concourse CILinux
shellcode2exeConvert shellcodes into executable files, for multiple platforms.shellcodeLinux
suricataSuricataLinux
twiggyTwiggy analyzes a binary's call graph.wasm, partial ELF & Mach-O supportLinux
vba2graphGenerate call graphs from VBA codeoffice documents such as .doc, .xls, .basLinux
xmldumpParse XML files.XMLLinux

About

MIRROR of https://gitlab.com/CinCan/tools - InfoSec tools packaged by CinCan as Docker images. See packages in Container Registry: https://github.com/orgs/cincanproject/packages

Topics

Resources

Contributing

Stars

4 stars

Watchers

1 watching

Forks

Used by

Contributors

Languages