Today I've launched malapi.io. I've been analyzing malware source code that utilizes WinAPIs and have been categorizing them. Please feel free to contribute as I know the current list is not exhaustive.
Our preprint is available here: phanivadrevu.com/files/papers/p…
Please reach out with any questions. Also, do attend our presentation which is scheduled for Track-1 on August 13th (Friday) at 11:15 PDT.
IDAPython script deobfuscating ADVobfuscator strings, applied to a TrickBoot sample github.com/TakahiroHaruya… We may not be able to reuse it for a different sample that was compiled with a different compiler or with different flags but I think the same approach can be applied.
I've updated the #YARA performance guidelines with input from Arnim Rupp
Guidelines
github.com/Neo23x0/YARA-P…
We've been working on Panopticon, a YARA performance measurement tool & Arnim improved the guide according to new findings
github.com/Neo23x0/panopt…
Bye-bye botnets👋 Huge global operation brings down the world's most dangerous malware.
Investigators have taken control of the Emotet botnet, the most resilient malware in the wild.
Get the full story: europol.europa.eu/newsroom/news/…
8K Followers 2K FollowingJust another OffSec geek. Speaker at Black Hat, IEEE, BSides & RE:HACK. Organizer of BSidesABQ & OWASPCairo. Building @CyberDose_
12K Followers 1K FollowingConsole hacker, former Kaspersky Team Lead of Exploits & Network Threat Detection, security researcher. For tips (thx!): https://t.co/VxJMiawFpP
547 Followers 809 FollowingResearcher at Talos. No infosec drama, no opinions, no politics, Tech and Tools only. Author of Dyn. Data Resolver (Winner of Hex-Rays Plugin Contest 2020).
5K Followers 375 FollowingCurrently Senior Windows Core OS Engineer, Windows Internals Enthusiast and Book author, tennis lover, currently working for MS. Opinions and tweets are my own.
35K Followers 255 FollowingWe help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
40K Followers 326 FollowingI built a C library that lets you compile 12kb static binaries that run natively on Linux, Mac, Windows, FreeBSD, OpenBSD, NetBSD and BIOS using just GCC/Clang.
19K Followers 2K Following🔬Founder & CEO @Binarly_io, #codeXplorer, #efiXplorer, @REhints and "Rootkits and Bootkits" book. Previously worked at Nvidia, Cylance, Intel, ESET, Yandex.
21K Followers 1 FollowingRME-DisCo research group from University of Zaragoza. Special interest on software and systems security. Link to our Telegram channel: https://t.co/UmkcXVG8MU
9K Followers 20 FollowingA Singapore company that discovers vulnerabilities to help customers mitigate the risks of cyber attacks. Organisers of @offbyoneconf
10K Followers 462 FollowingThreat Researcher at Check Point @_CPResearch_ #DFIR #Reversing - All opinions expressed here are mine only.
https://t.co/iWvwWF1AnN