Posts

Showing posts with the label Malware Detection

Vba2graph - Generate Telephone Telephone Graphs From Vba Code, For Easier Analysis Of Malicious Documents

Image
H5N1 tool for safety researchers, who waste product their fourth dimension analyzing malicious Office macros. Generates a VBA telephone yell upward graph, alongside potential malicious keywords highlighted. Allows for quick analysis of malicous macros, in addition to slowly agreement of the execution flow. @MalwareCantFly Features Keyword highlighting VBA Properties support External business office declarion support Tricky macros alongside "_Change" execution triggers Fancy color schemes! Pros Pretty fast Works good on nearly malicious macros observed inwards the wild Cons Static (dynamicaly resolved calls would non survive recognized) Examples Example 1: Trickbot downloader - utilizes object Resize number every bit initial trigger, followed yesteryear TextBox_Change triggers. Example 2: Check out the Examples folder for to a greater extent than cases. Installation Install oletools: https://github.com/decalage2/oletools/wiki/...

Stoq - An Opened Upwards Origin Framework For Corporation Degree Automated Analysis

Image
stoQ is a automation framework that helps to simplify the to a greater extent than mundane in addition to repetitive tasks an analyst is required to do. It allows analysts in addition to DevSecOps teams the mightiness to chop-chop transition from dissimilar information sources, databases, decoders/encoders, in addition to numerous other tasks. stoQ was designed to move company produce in addition to scalable, spell likewise beingness thin plenty for private safety researchers. Want to acquire more? Read but about of the blog posts we've written to acquire more. Introduction to stoQ stoQ in addition to Enterprise e-mail Operationalizing Indicators stoQ amongst Suricata Plugins stoQ currently has over twoscore publicly available plugins. These plugins are available separately inwards the plugin repository Installation in addition to Documenation Want to boot the bucket started quickly? Check out the docker image . stoQ requires a minimum of python 3.4. Instal...

Flerken - Obfuscated Ascendency Detection Tool

Image
Command business obfuscation has been proved to endure a non-negligible cistron inwards fileless malware or malicious actors that are "living off the land". To bypass signature-based detection, dedicated obfuscation techniques are shown to endure used past times red-team penetrations as well as fifty-fifty APT activities. Meanwhile, numerous obfuscators (namely tools perform syntax transformation) are opened upwards sourced, hence making obfuscating given commands increasingly effortless. However, the position out of suitable defenses remains to endure few. For Linux command line obfuscation, nosotros tin barely divulge whatever detection tools. Concerning defenses against Windows ascendance obfuscation, existing schemes plough out to either lack of toolization, or alone partially resolve the entire problem, sometimes fifty-fifty inaccurately. To amend facilitate obfuscation detection, we accept proposed Flerken, a toolized platform that tin endure used to hono...