Wednesday, March 19, 2025
HomeLinuxREMnux - A Linux-based Malware Analysis Toolkit for Malware Researchers

REMnux – A Linux-based Malware Analysis Toolkit for Malware Researchers

Published on

SIEM as a Service

Follow Us on Google News

REMnux is a Linux distro for malware researchers that has a curated collection of free tools used for examining executables, documents, scripts, and other forms of malicious code. The tools help researchers to find, install, and configure the tools.

The initial release was before 10 years, now a new version REMnux 7 is released. It can be installed as a virtual appliance or standalone operating system or can be run as a docker container.

The distro is based on Ubuntu, created and maintained by Lenny Zeltser, an instructor and author at SANSInstitute.

New REMnux v7

With the new version, all the tools have been refreshed, some of the old tools have been retired and many new tools have been added.

Number of new tools has been added with the latest version to perform the following tasks

  • Examine Static Properties
  • Statically Analyze Code
  • Dynamically Reverse-Engineer Code
  • Perform Memory Forensics
  • Explore Network Interactions
  • Investigate System Interactions
  • Check static properties
  • Gather and analyze data
  • Static code analysis

Zeltser also scheduled a webcast What’s New in REMnux on July 28, 2020, to showcase the new distro, if you are interested you can join.

Also, the documentation is revamped let anyone become familiar with its tools and also explains the distro’s building blocks.

Zeltser also released a new cheat sheet that outlines the tools and commands for analyzing malware using the REMnux v7.

You can add REMnux as a virtual appliance, install the distro on a dedicated system, add it to an existing one, or Run REMnux as a container.

Malware Analysis Course: Certified Malware Analyst Course where you learn about Exploit Development, Expert Malware Analysis, Threat Research & Reverse Engineering

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

Free Open Source Penetration Testing Distro BackBox Linux 6 Released with new Hacking Tools

Powerful Penetration Testing Distro Kali Linux Now available in Windows 10

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

CISA Warns of Supply-Chain Attack Exploiting GitHub Action Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm over a critical...

MirrorFace Hackers Modify AsyncRAT Execution for Stealthy Deployment in Windows Sandbox

In a significant development, the China-aligned advanced persistent threat (APT) group known as MirrorFace...

11 State-Sponsored Threat Actors Exploit 8-Year-Old Windows Shortcut Flaw

Cybersecurity researchers have discovered that multiple state-sponsored threat actors have been exploiting an eight-year-old...

Advanced Cyber Attack Exploits Booking Websites to Deploy LummaStealer Malware

A sophisticated cyberattack has been uncovered, targeting booking websites to spread the LummaStealer malware....

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

PoC Exploit Released for Linux Kernel Use-After-Free Vulnerability

A proof-of-concept (PoC) exploit has been released for a use-after-free vulnerability in the Linux...

Hackers Exploiting Exposed Jupyter Notebooks to Deploy Cryptominers

Cado Security Labs has identified a sophisticated cryptomining campaign exploiting misconfigured Jupyter Notebooks, targeting...

New Linux Kernel Code Written in Rust Aims to Eliminate Memory Safety Bugs

The integration of Rust into the Linux kernel is a significant step forward in...