Willi Ballenthin
Willi Ballenthin
many sandboxes provide a summary of the indicators extracted during runtime analysis, such as files written, registry keys opened, network connections created, etc. it might be nice to provide a...
### Details There's a nice list of actively maintained IDA plugins here: https://vmallet.github.io/ida-plugins/ We should use this list as inspiration for IDA plugins to add to FLARE-VM.
We should consider installing a top level exception handler that logs basic environmental details, such as OS, python version, ghidra version, when displaying an exception and stack trace. This will...
GoReSym is pretty slow and this makes it difficult to deploy at a large scale. Despite being written in Go and compiled to native code, it may take seconds or...
background: https://twitter.com/a_tweeter_user/status/1339927755299958784
- fix syntax error with missing `]`. - add new variant of ror13AddHash32 that includes the trailing null, as seen in sample in the wild
ref: https://github.com/vivisect/vivtestfiles