Reverse Engineering
رفتن به کانال در Telegram
Everything is open-source. The official community group: @reverseengineeringz
نمایش بیشترکشور مشخص نشده استفناوری و برنامهها20 250
4 786
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+127 روز
+5430 روز
آرشیو پست ها
4 786
Digging Up the Past: Windows Registry Forensics Revisited
https://www.fireeye.com/blog/threat-research/2019/01/digging-up-the-past-windows-registry-forensics-revisited.html
4 786
Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories
https://github.com/malrev/ABD
4 786
MalConfScan
a Volatility plugin extracts configuration data of known malware. Volatility is an open-source memory forensics framework for incident response and malware analysis. This tool searches for malware in memory images and dumps configuration data. In addition, this tool has a function to list strings to which malicious code refers.
https://github.com/JPCERTCC/MalConfScan
4 786
Observing COM within Malicious Code
https://blog.malwarebytes.com/threat-analysis/2014/02/observing-com-within-malicious-code/
4 786
New Ursnif Variant Spreading by Word Document
https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document
4 786
Threat Research
Reversing Malware Command and Control: From Sockets to COM
https://www.fireeye.com/blog/threat-research/2010/08/reversing-malware-command-control-sockets.html
4 786
Latest malware news and threat information exchange forum. Malware analysis, indicators, reports and educational resources.
https://malware.news/
4 786
PE Tree
Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro to dump in-memory PE files and reconstruct imports.
https://github.com/blackberry/pe_tree
4 786
Take a look into the depths of
Windows kernels and
reveal more than 60000
undocumented structures
https://www.vergiliusproject.com/
4 786
script will annotate and bookmark the code with tags produced by tool Tiny Tracer
https://github.com/Dump-GUY/ghidra_scripts
4 786
capa detects capabilities in executable files. You run it against a PE file or shellcode and it tells you what it thinks the program can do. For example, it might suggest that the file is a backdoor, is capable of installing services, or relies on HTTP to communicate.
https://github.com/fireeye/capa
