Recognize STL code easily
Recognizing STL code with ease 😐 During reverse engineering, we often encounter STL code whose analysis at first glance seems difficult. An inexperienced eye ma…
Recognizing STL code with ease 😐 During reverse engineering, we often encounter STL code whose analysis at first glance seems difficult. An inexperienced eye ma…
CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…
Click trap: not only for users, but also for link analyzers 🐭 When manually analyzing links, we typically ask ourselves only one question — “is it safe?” ✔️❌ Tr…
Cyber Threat Library: Basic Minimum or Luxurious Maximum? 🔍 In the world of information security, the term "cyber threat library" periodically appears in variou…
Sold a phone with my personal data ☹️ When purchasing donor devices on platforms for selling personal items, a negative trend is emerging: many people rarely wo…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️ Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll ta…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
Searching for Phishing Infrastructure at the Preparation Stage 🧱 In protecting an organization from phishing threats, it is useful not to limit yourself to simp…
In addition to the previous post we are looking at additional tools for decrypting network traffic. Let's look at an alternative to PolarProxy that is no…
MITM attack is a fairly popular feature of various sandboxes and application analysis systems. Typically, tools that enable MITM attacks are a proxy serv…
In the first part, we examined the decryption of TLS connections, which are often used on the internet. But if we move inside a corporate environment, other pro…
🦈 Looking Under the Hood of Secure Connections in Wireshark. Part 1: TLS Our network experts often need to decrypt TLS connection traffic and analyze protected…