Skip to main content
Elastic Security Labs Banner Image

Elastic Security Labs - nightMARE

This directory contains the nightMARE (Malware Analysis & Reverse Engineering) library. nightMARE is a central module that will allow for an efficient and logical approach to automating various reverse engineering functions.

The nightMARE library is born from the need to refactor our code base into reusable bricks. We want to concentrate logics and dependencies into a single library in order to speed up tool developement for members of the Elastic Security Labs team.

By open sourcing our library to the community we hope that it'll contribute to our battle against threats.

Please note that this library is still young and under developement. Pull requests are welcome.
Example usage: https://www.elastic.co/security-labs/unpacking-icedid

Malware modules

Module Description
nightmare.malware.blister Implement BLISTER algorithms
nightmare.malware.ghostpulse Implement GHOSTPULSE algorithms
nightmare.malware.deprecated.icedid Implement ICEDID algorithms (deprecated)
nightmare.malware.latrodectus Implement LATRODECTUS algorithms
nightmare.malware.lobshot Implement LOBSHOT algorithms
nightmare.malware.lumma Implement LUMMA algorithms
nightmare.malware.netwire Implement NETWIRE algorithms
nightmare.malware.redlinestealer Implement REDLINESTEALER algorithms
nightmare.malware.revstealer Implement REVSTEALER algorithms
nightmare.malware.remcos Implement REMCOS algorithms
nightmare.malware.smokeloader Implement SMOKELOADER algorithms
nightmare.malware.stealc Implement STEALC algorithms
nightmare.malware.telepuz Implement TELEPUZ algorithms
nightmare.malware.vidar Implement VIDAR algorithms
nightmare.malware.warmcookie Implement WARMCOOKIE algorithms
nightmare.malware.xorddos Implement XORDDOS algorithms

Requirements

  • Python >= 3.10 is required.
  • Rizin v0.8.1 must be installed and available in the system's PATH environment variable.

Install

pip install nightmare-lib

or

git clone https://github.com/elastic/nightMARE
python -m pip install ./nightMARE

Test

Download the corpus from here and place the archive in the tests folder to run the tests. Warning: The archive contains malware; testing should be performed in a virtual machine for safety.

py.test

How to Contribute

Contributors must sign a Contributor License Agreement before contributing code to any Elastic repositories.

License

nightMARE uses the Elastic License version 2.

Metadata

Release files for nightMARE-lib 0.19.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for nightMARE-lib 0.19.0
File Size Uploaded
nightmare_lib-0.19.0.tar.gz 63.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for nightMARE-lib 0.19.0
File Interpreter ABI Platform
nightmare_lib-0.19.0-py3-none-any.whl Python 3 none any Details

Total release size: 150.8 kB

Release files / nightmare_lib-0.19.0.tar.gz

Download URL nightmare_lib-0.19.0.tar.gz
Size 63.7 kB
Tags Source
SHA-256 checksum
How to use checksums
0b0b9837d2f5434ed7f6e6e86ea33d9b570aa8fdc8df9d39f3c1d4717f6003d9
BLAKE2b-256 checksum
How to use checksums
f040ee625aa9229f82492112655651b6c14b5909bc75d6dbe149df66bac34c65
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / nightmare_lib-0.19.0-py3-none-any.whl

Download URL nightmare_lib-0.19.0-py3-none-any.whl
Size 87.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
df8e22a1037551bc0d8592ffafc56d609f2acf9e5b739c58a4be3d35fc019007
BLAKE2b-256 checksum
How to use checksums
16084a4306b3e7e9a89acf4e3ba64eac0b368a56647d64a47d4bcdd2d7e5df25
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

0.19.0 This release

2 release files

0.18.0

2 release files

0.17.0

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.14.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page