Malwrologist

2.7K posts

Malwrologist

Malwrologist

@DissectMalware

Senior Security Engineer @Amazon. Ex Assistant Professor. Opinions are mine; not my employer's. DM is open. Author of xlmdeobfuscator and https://t.co/eh1fMHMADE

เข้าร่วม Şubat 2018
159 กำลังติดตาม15.2K ผู้ติดตาม
Malwrologist
Malwrologist@DissectMalware·
@kavehrazavi It's fascinating to witness how far a dedicated team of researchers can go! @kavehrazavi It's always fun to follow your research even though it is completely out of my field expertise.
English
1
0
1
496
Kav
Kav@kavehrazavi·
This took a significant amount of time and money, and now we know what DRAM vendors are doing in their sense amplifiers! Lots of research opportunities moving forward. All the images and the reverse engineered circuits are now publicly available.
Michele Marazzi@marazzi_michele

For the first time, we imaged and reverse engineered 6 modern DDR4/5 DRAM chips (comsec.ethz.ch/hifi-dram) Due to the incredibly small feature size of modern ICs, we use SEM combined with FIB reaching pixel resolutions as low as 3.4nm. Then we evaluate 10 years of DRAM research.

English
1
8
50
5.3K
Malwrologist
Malwrologist@DissectMalware·
@n3mes1s indeed : ) I need to update the description and include the features as it hasn't updated since v0.0.1
English
0
0
0
88
Giuseppe `N3mes1s`
Giuseppe `N3mes1s`@N3mes1s·
@DissectMalware Nice feature. This is an underrated one. Testing yara in a controlled env with edr will match everything and this was exact the reason a started a project like this one to have everything done in browser in mem
English
1
0
1
233
Thomas Roccia 🤘
Thomas Roccia 🤘@fr0gger_·
#100DaysOfYara Day 16: Do you like automatically generating Yara rules based on opcode? 💻 Well me too and I've got you covered with YaraToolkit v0.4.2! I added a new feature adapted from MKyara by @jelleverg. I've loved this tool for quite some time, so it was natural to include it! 👍 How can you use it? Drop a sample, specify the offset of your function or piece of code, select the size and options, and voilà! 🧙‍♂️ 🔗 Check this out: yaratoolkit.securitybreak.io #yara #infosec #tools #python #malware #reverseengineering
GIF
English
3
11
47
5K
Malwrologist
Malwrologist@DissectMalware·
Both #YaraDbg backend and frontend run in the docker container
English
0
2
3
5.2K
Malwrologist
Malwrologist@DissectMalware·
Want to run #YaraDbg locally on your system using #Docker? 1⃣ docker pull dissectmalware/yaradbg:latest 2⃣ docker run -p 7071:7071 -p 8081:80 -d dissectmalware/yaradbg:latest 3⃣ browse http://localhost:8081 Want to build the image yourself? github.com/DissectMalware…
English
1
10
30
8.2K
Malwrologist
Malwrologist@DissectMalware·
@AnFam17 @fr0gger_ Quick tip, rearrange the conditions first the check for whether it is PE and then the string match operation; will greatly improve perf
English
1
0
3
288
Greg Lesnewich
Greg Lesnewich@greglesnewich·
#100DaysofYARA one of the easiest ways to get bogged down with writing rules is the scaffolding - use a plug-in from your favorite text editor to ensure you get proper metadata, most syntax highlighting and some auto-completion! Sublime: packagecontrol.io/packages/Yara%…
GIF
English
3
7
27
3.2K
Malwrologist
Malwrologist@DissectMalware·
If you are interested to contribute to this project, please reach out!
English
0
0
4
5K
Malwrologist
Malwrologist@DissectMalware·
Short-term goal: Consolidate the frontend and backend projects. Long-term goal: Transition to a frontend-only application by eliminating the backend.
English
1
1
3
5.1K
Malwrologist
Malwrologist@DissectMalware·
Remember maldocs with XOR encryption back in 2020? I crafted a decryptor and integrated it with my msoffcrypto-tool fork 3 years back! Guess what? it is now merged with github.com/nolze/msoffcry… main branch! Tnx @nolze : ) Context: twitter.com/JohnLaTwC/stat… by @JohnLaTwC
John Lambert@JohnLaTwC

ICYMI, looks like a campaign with XOR encrypted XLS with the VelvetSweatshop password. 0 AV detects. cc/ @BouncyHat 📎virustotal.com/gui/file/0f69a… 📎virustotal.com/gui/file/f402c… 📎virustotal.com/gui/file/0034b… 📎virustotal.com/gui/file/6fd94… 👉twitter.com/BouncyHat/stat… 📄docs.microsoft.com/en-us/openspec…

English
0
2
4
6.2K
Malwrologist
Malwrologist@DissectMalware·
@decalage2 Great to hear that! if you need a hand, let me know; I would love to contribute...
English
1
0
1
123
Philippe Lagadec
Philippe Lagadec@decalage2·
I am resuming the work on this project, so new features might be added soon!
English
1
0
6
375
Malwrologist
Malwrologist@DissectMalware·
Thrilled to announce my move to @Amazon as a senior security engineer! Leaving the amazing team at @Microsoft was a tough call—they're truly incredible people. However, I'm buzzing with excitement for this new chapter and the opportunities it holds.
English
3
0
34
9.6K
Malwrologist
Malwrologist@DissectMalware·
@nolze Awesome! I created a pull request (github.com/nolze/msoffcry…) Encountered a few merge conflicts with master. If you have time, plz go ahead and resolve them. Otherwise, I will try to do it. It may take some time for me to get back to it though. Context: twitter.com/JohnLaTwC/stat…
John Lambert@JohnLaTwC

ICYMI, looks like a campaign with XOR encrypted XLS with the VelvetSweatshop password. 0 AV detects. cc/ @BouncyHat 📎virustotal.com/gui/file/0f69a… 📎virustotal.com/gui/file/f402c… 📎virustotal.com/gui/file/0034b… 📎virustotal.com/gui/file/6fd94… 👉twitter.com/BouncyHat/stat… 📄docs.microsoft.com/en-us/openspec…

English
1
0
1
1K
nolze
nolze@nolze·
I'm really impressed with what you've done and I would love to continue its development with you and future contributors. If you're open to it, would you consider creating a Pull Request for us? Thank you in advance for your consideration.
English
1
0
1
203
Malwrologist
Malwrologist@DissectMalware·
@Mao_Ware I thought # of interviews is equal to number of companies; still impressive though
English
0
0
0
334
Brian Bartholomew
Brian Bartholomew@Mao_Ware·
Extremely excited to join the herd at Rapid7. That said, for those that are navigating this job market, here's some numbers to help put things in perspective: - 22+ years experience - Unemployed May 4 - 38 applications submitted - 35 interviews conducted - 2 offers received
English
36
9
187
43.8K