REMnux

Ubuntu based Distro with Containerized tooling available

REMnux Documentation

This site provides documentation for REMnuxarrow-up-right,® a free Linux toolkit for reverse-engineering and analyzing malware. REMnux strives to make it easier for forensic investigators and incident responders to start using the variety of freely-available tools that can examine malware, yet might be difficult to find or set up.

The heart of the project is the REMnux Linux distributionarrow-up-right based on Ubuntu This lightweight distro incorporates many tools for analyzing Windows and Linux malware, examining browser-based threats such as obfuscated JavaScript, exploring suspicious document files and taking apart other malicious artifacts. Investigators can also use the distro to intercept suspicious network traffic in an isolated lab when performing behavioral malware analysis.

Another REMnux initiative involves building Docker images of popular malware analysis toolsarrow-up-right. The goals of this effort is to allow investigators to conveniently utilize difficult-to-setup applications without having to install the REMnux distro. You can run Dockerized application containers as part of your existing environment.

REMnux is maintained by Lenny Zeltserarrow-up-right with extensive help from David Westcottarrow-up-right. You can learn the malware analysis techniques that make use of the tools installed and pre-configured on the REMnux distro by taking Reverse-Engineering Malware trainingarrow-up-right at SANS Institute.

Last updated