Hexora – detection and analysis of malicious Python scripts
Hexora – detection and analysis of malicious Python scripts
I made a new library to detect malicious and harmful behaviour in Python scripts. It uses static analysis with semantic modeling. Even when the code is pretty obfuscated, it can still detect it. For example, it can infer that getattr(sys.modules["built"+"ins"], "".join(reversed(["al","ev"])))("1+1") Is basically: eval("1+1"). Currently, I'm testing it on public files where some of them implement malicious behavior, as well as past malicious packages on PyPI. You can see some of the detection examples here: https://github.com/rushter/hexora/blob/main/docs/examples.md I'd love to hear your feedback and ideas on how to improve this and identify missing rules.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Incorrect prediction on native model
Similar products
Redis Lua scripts as typed Python functions
Naive Corner Detection Python Implementation
Monte Carlo Analysis of 'Chutes and Ladders' with Python
Hexora – static analysis tool for malicious Python scripts
Wolverine: Give your Python scripts regenerative healing abilities
NixSH, run Bash/Python or any scripts with the power of Nix
Wooey Web UIs for Python Scripts
Scripts for Trello
mruby-rake, compile your ruby scripts to mruby executable
I made a compiler/VM for untrusted scripts