ar
Feedback
Reverse Engineering

Reverse Engineering

الذهاب إلى القناة على Telegram

Everything is open-source. The official community group: @reverseengineeringz

إظهار المزيد
4 786
المشتركون
لا توجد بيانات24 ساعات
+127 أيام
+5430 أيام
أرشيف المشاركات
Program-transformation.org is dedicated to collecting, organizing and disseminating information about all aspects of program transformation in order to share results across communities. http://www.program-transformation.org/

ImHex A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM. https://github.com/WerWolv/ImHex

SRP Streams in MS Office Documents Reveal Earlier Versions of Malicious Macros https://www.sans.org/blog/srp-streams-in-ms-office-documents-reveal-earlier-versions-of-malicious-macros/

Reverse Engineering: Process Hollowing | Process Doppelgang-ing Hybrid used by The Osiris Dropper https://youtu.be/VPKjHBQyMR0

CapaExplorer Capa analysis importer for Ghidra. https://github.com/reb311ion/CapaExplorer
CapaExplorer Capa analysis importer for Ghidra. https://github.com/reb311ion/CapaExplorer

Collection of malware source code for a variety of platforms in an array of different programming languages. https://github.com/vxunderground/MalwareSourceCode

Malware Behavior Catalog v2.0 The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting. https://github.com/MBCProject/mbc-markdown

Malware Capabilities Starting with version 4.1, MAEC offers a standard way of capturing the set of high-level abilities that a malware instance possesses, which we term Capabilities. For instance, to state that a malware instance is capable of exfiltrating data, one may simply specify a single MAEC "Data Exfiltration" Capability. We have defined an initial set of Capabilities for the MAEC v4.1 release, which is captured in detail in the hierarchy below. https://github.com/MAECProject/schemas/wiki/Malware-Capabilities

Ghidra 9.2 has been released! This version has improvements to analysis, the user interface, new open source based graphing, decompiler quality enhancements, and more! https://ghidra-sre.org/

uses Pe-sieve , Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches). https://github.com/hasherezade/hollows_hunter

Pe-sieve Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches). https://github.com/hasherezade/pe-sieve