Skip to main content

REMINDer Tweet

Detect packers on executable files using a simple entropy-based heuristic.

PyPi Python Versions Build Status License

REMINDer (REsponse tool for Malware INDication) is an implementation based on this paper into a Python package with a console script to detect whether an executable is packed using a simple heuristic.

lief is used for binary parsing.

$ pip install reminder-detector
$ reminder --help
[...]
usage examples:
- reminder program.exe
- reminder /bin/ls --entropy-threshold 6.9

Detection Mechanism

  1. Find the EP section
  2. Check whether it is writable
  3. If yes, check whether entropy is beyond a threshold (depending on the executable format)
  4. If yes, the input executable is packed ; otherwise, it is not

Related Projects

You may also like these:

Metadata

Release files for reminder-detector 1.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for reminder-detector 1.2.2
File Size Uploaded
reminder_detector-1.2.2.tar.gz 69.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for reminder-detector 1.2.2
File Interpreter ABI Platform
reminder_detector-1.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 101.5 kB

Release files / reminder_detector-1.2.2.tar.gz

Download URL reminder_detector-1.2.2.tar.gz
Size 69.8 kB
Tags Source
SHA-256 checksum
How to use checksums
a46de9903ae20942e8b4b24d2d196bca771811100b4e662d909e4648cc690c6b
BLAKE2b-256 checksum
How to use checksums
2bceebe18f0035567f985d8cdee7ac59fde08c4baac87e5526713399cd60b429
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.12.7

Release files / reminder_detector-1.2.2-py3-none-any.whl

Download URL reminder_detector-1.2.2-py3-none-any.whl
Size 31.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a61e8accf9c0152cc737c0975de163a9011c3ce9aed2f4b0233bb1ea9697fe59
BLAKE2b-256 checksum
How to use checksums
4699278a8641cf4ebd85fe27d531e391b6410c7b6df1fc02e33da73aad99c02d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.12.7

Release history Release notifications | RSS feed

This release

1.2.2 This release

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page