Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. [email protected]
Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.
A sane API for IDA Pro's decompiler. Useful for malware RE and vulnerability research
ETW Python Library
Automatic analysis of SWF files based on some heuristics. Extensible via plugins.