Ghidra 9.2 has been released!
This version has improvements to analysis, the user interface, new open source based graphing, decompiler quality enhancements, and more!
https://ghidra-sre.org/
This version has improvements to analysis, the user interface, new open source based graphing, decompiler quality enhancements, and more!
https://ghidra-sre.org/
Reverse Engineering with Ghidra | HackadayU
https://www.youtube.com/playlist?list=PL_tws4AXg7auglkFo6ZRoWGXnWL0FHAEi
https://www.youtube.com/playlist?list=PL_tws4AXg7auglkFo6ZRoWGXnWL0FHAEi
Malware Capabilities
Starting with version 4.1, MAEC offers a standard way of capturing the set of high-level abilities that a malware instance possesses, which we term Capabilities. For instance, to state that a malware instance is capable of exfiltrating data, one may simply specify a single MAEC "Data Exfiltration" Capability. We have defined an initial set of Capabilities for the MAEC v4.1 release, which is captured in detail in the hierarchy below.
https://github.com/MAECProject/schemas/wiki/Malware-Capabilities
Starting with version 4.1, MAEC offers a standard way of capturing the set of high-level abilities that a malware instance possesses, which we term Capabilities. For instance, to state that a malware instance is capable of exfiltrating data, one may simply specify a single MAEC "Data Exfiltration" Capability. We have defined an initial set of Capabilities for the MAEC v4.1 release, which is captured in detail in the hierarchy below.
https://github.com/MAECProject/schemas/wiki/Malware-Capabilities
GitHub
Malware Capabilities
MAEC Schemas and Schema Development. Contribute to MAECProject/schemas development by creating an account on GitHub.
Malware Behavior Catalog v2.0
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting.
https://github.com/MBCProject/mbc-markdown
The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting.
https://github.com/MBCProject/mbc-markdown
GitHub
GitHub - MBCProject/mbc-markdown: MBC content in markdown
MBC content in markdown. Contribute to MBCProject/mbc-markdown development by creating an account on GitHub.
Collection of malware source code for a variety of platforms in an array of different programming languages.
https://github.com/vxunderground/MalwareSourceCode
https://github.com/vxunderground/MalwareSourceCode
GitHub
GitHub - vxunderground/MalwareSourceCode: Collection of malware source code for a variety of platforms in an array of different…
Collection of malware source code for a variety of platforms in an array of different programming languages. - vxunderground/MalwareSourceCode
Reverse Engineering: Process Hollowing | Process Doppelgang-ing Hybrid used by The Osiris Dropper
https://youtu.be/VPKjHBQyMR0
https://youtu.be/VPKjHBQyMR0
YouTube
Reverse Engineering: Process Hollowing | Process Doppelgang-ing Hybrid used by The Osiris Dropper
This Video is a follow-up on The Unpacking Of Osiris, Covering how the Dropper used a Hybrid of Process Hollowing + Process Dopplegang-ing for its Injection.
Unpacking Osiris: https://ghostinthehive.github.io/thehive/Unpacking-Osiris.html
Process Injection…
Unpacking Osiris: https://ghostinthehive.github.io/thehive/Unpacking-Osiris.html
Process Injection…
SRP Streams in MS Office Documents Reveal Earlier Versions of Malicious Macros
https://www.sans.org/blog/srp-streams-in-ms-office-documents-reveal-earlier-versions-of-malicious-macros/
https://www.sans.org/blog/srp-streams-in-ms-office-documents-reveal-earlier-versions-of-malicious-macros/
www.sans.org
SANS Digital Forensics and Incident Response Blog | SRP Streams in MS Office Documents Reveal Earlier Versions of Malicious Macros…
SANS Digital Forensics and Incident Response Blog blog pertaining to SRP Streams in MS Office Documents Reveal Earlier Versions of Malicious Macros
ImHex
A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM.
https://github.com/WerWolv/ImHex
A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM.
https://github.com/WerWolv/ImHex
GitHub
GitHub - WerWolv/ImHex: 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3…
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM. - WerWolv/ImHex
Program-transformation.org is dedicated to collecting, organizing and disseminating information about all aspects of program transformation in order to share results across communities.
http://www.program-transformation.org/
http://www.program-transformation.org/
pe_unmapper
convert beteween the PE alignments (raw and virtual).
https://github.com/hasherezade/libpeconv/tree/master/pe_unmapper
convert beteween the PE alignments (raw and virtual).
https://github.com/hasherezade/libpeconv/tree/master/pe_unmapper
GitHub
libpeconv/pe_unmapper at master · hasherezade/libpeconv
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl - hasherezade/libpeconv
Should we create a general reverse engineering community on Telegram to share resources and discuss related topics?
Anonymous Poll
95%
1
5%
0
The official community group is up 🥳🥳🎉
Please read and remember to stick to the rules. Make it a valuable place for learning and sharing knowledge with each other. If anything is unclear, please ask for clarification. After that.
[[ Rules ]]
- The sole language in the chat is English. Messages in any other language will be removed and a warning will be issued.
- Off-topic messages will be removed without warning. This is not a technical support channel.
- Although this is already covered in the "no off-topic" rule, the high amount of offenders caused this to be a specific rule: asking for help after a ransomware infection or for cracking a software is off-topic and thus not permitted.
- Be civil, clear and concise when asking a question. No one in this chat is obliged to answer your question. Help is given on a voluntary basis, and cannot be demanded as such. Depending on the severity of the offense, a warning will be given. After a few warnings, you will be removed from the group on a permanent basis.
- Copyrighted material which is not to be distributed, is not to be distributed in this channel. Any form of illegal content sharing is strictly forbidden. Breaking this rule results in a permanent ban.
- Any illegal activity is forbidden, causing you to be permanently removed from the group without warning.
Enjoy!
@reverseengineeringz
Please read and remember to stick to the rules. Make it a valuable place for learning and sharing knowledge with each other. If anything is unclear, please ask for clarification. After that.
[[ Rules ]]
- The sole language in the chat is English. Messages in any other language will be removed and a warning will be issued.
- Off-topic messages will be removed without warning. This is not a technical support channel.
- Although this is already covered in the "no off-topic" rule, the high amount of offenders caused this to be a specific rule: asking for help after a ransomware infection or for cracking a software is off-topic and thus not permitted.
- Be civil, clear and concise when asking a question. No one in this chat is obliged to answer your question. Help is given on a voluntary basis, and cannot be demanded as such. Depending on the severity of the offense, a warning will be given. After a few warnings, you will be removed from the group on a permanent basis.
- Copyrighted material which is not to be distributed, is not to be distributed in this channel. Any form of illegal content sharing is strictly forbidden. Breaking this rule results in a permanent ban.
- Any illegal activity is forbidden, causing you to be permanently removed from the group without warning.
Enjoy!
@reverseengineeringz
Reverse Engineering pinned «The official community group is up 🥳🥳🎉 Please read and remember to stick to the rules. Make it a valuable place for learning and sharing knowledge with each other. If anything is unclear, please ask for clarification. After that. [[ Rules ]] - The sole…»