Decaf binary analysis platform
VDF: Targeted Evolutionary Fuzz Testing of Virtual Devices. Doctoral thesis, Syracuse University, 2016. Birmingham, UK: Packt Publishing. During my time as a PhD student in the SycureLab at Syracuse University, I developed a number of tools and techniques that are used to perform malware reverse engineering via dynamic analysis. Code Patrol: Fighting malware with static and dynamic code analysis. Dean Krusienski still acts as the PI for the grant. Syracuse University, January 2014. The project has since moved from UNF to the ASPEN Lab at Old Dominion University. On soundness and precision of dynamic taint analysis. This allows us to add more instrumentation per emulated instruction, which leads to more complex analyses and studies.
San Jose, CA, July 2014. Android for the BeagleBone Black. BeagleBone Black: Capes verwalten. Much of my PhD thesis is based upon DECAF and its design. JSForce: A Forced Execution Engine for Malicious JavaScript Detection. Not everything that I write is intended for an academic audience. DECAF is often much, much faster. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, April 2017. Bred in the Bone: BeagleBone capes.
One of the demonstrations based upon our research work. Beagle Music: HDMI and the BeagleBone Black multimedia environment. This is also the home of the DroidScope dynamic Android malware analysis platform. DroidScope is now an extension to DECAF. DECAF builds upon TEMU. BitBlaze project headed up by Dawn Song. We appreciate all that worked with us on that project. Thus, the taint status for each CPU register and memory location is processed and updated synchronously during the code execution of the virtual machine. To reduce runtime overhead, the instrumentation code is inserted into the translated code only when necessary.
DECAF for help documents. Lok Kwong Yan, Andrew Henderson, Xunchao Hu, Heng Yin, and Stephen McCamant? DECAF can provide support for both multiple architectures and multiple operating systems. CPU registers and memory, and inlining precise tainting rules in the translated code blocks. To ease the development of plugins, the management of dynamic code instrumentation is completely taken care of in the framework, and thus invisible to the plugins. The analysis plugins only need to register for interested events and implement corresponding event handling functions. Fig 1 illustrates the overall architecture of DECAF. It requires that the analysis framework hide the architecture and operating system specific details from the analysis plugins.
When the plugin unregisters this function hook, the instrumentation code will also be removed from the translated code accordingly. It provides the following key features. The details of code instrumentation are taken care of by the framework. Dynamic binary analysis is a prevalent and indispensable technique in program analysis. DECAF using CPU2006 SPEC benchmarks and show average overhead of 605 percent for system wide tainting and 12 percent for VMI. Free automated vulnerability test. Is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android applications. Cs, phone numbers etc. This tool is designed to look for several security related Android application vulnerabilities, either in source code or packaged APKs.
No need to install on Windows. The FindBugs plugin for security audits of Java web applications. Adds some instructions to the classes. For copyright information see the COPYING_DECAF file. Cannot retrieve the latest commit at this time. The laptop still showed a locked Windows login screen. The man mumbled an apology in English about his keycard working on the wrong room, brushed past Delpy, and was out the door before Delpy could even react. Delpy long to guess why his laptop had been the target of a literal black bag job. Delpy refused, and went back to wait in the room instead.
Like being in a spy film. BeagleBoard and BeagleBone platforms. Linux desktop and embedded Linux and Android systems. Free Website Malware and Security Scanner. Community based IP blacklist service. Live memory inspection and kernel debugging for Windows systems. Linux malwares and capturing IOCs. Free online dig and other network tools.
AV scanners, and malware sandboxes for automated analysis. Active collection of malware samples. Sample information and downloads. Registry compare utility that compares snapshots. Aggregates security threats from a number of sources, including some of those listed below in other resources. Volatility, and create a readable report. Python library for parsing Windows Event Logs. Web interface for the Volatility Memory Forensics Framework.
Sublime Malware Research Tool, a plugin for Sublime 3 to aid with malware analyis. Python library for parsing registry files. Aggregates IOCs from various lists. Xiang Fu, a great resource for learning practical malware analysis. Domain name permutation engine for detecting typo squatting, phishing and corporate espionage. Source for the Zeus trojan leaked in 2011. Open Source Malware Analysis Pipeline System.
NET assembly editor, decompiler and debugger. Dynamic analysis for Linux executables. Automatic and complete Android application analysis system. Free API Services for detecting possible phishing domains, blacklisted ip addresses and breached accounts. Gather information about an IP or domain by searching online resources. NET assembly browser and decompiler. Perform static analysis of Windows executables. QEMU with embedded WinDbg server for stealth debugging.
Scan for malicious traces in MS Office documents. Custom Google search engine from Corey Harrell. OSINT tool for gathering information about URLs, IPs, or hashes. Didier Stevens for finding XORed data. An Automated Malware Analysis Tool for Linux ELF Files. Be careful with malware.
Malware Information Sharing Platform curated by The MISP Project. DomainTools free online whois search. Large repository of malware actively scrapped from malicious sites. Reverse engineering framework, with debugger support. Research, connect, tag and share IPs and domains. Web based code browser using clang to provide basic code analysis.
IP based spam block list. Local Linux rootkit detection. An open source, serverless AWS pipeline that scans and alerts on uploaded files based on a set of YARA rules. Modular, recursive file scanning solution. Deobfuscate simple Javascript that use eval or document. Free online tools for researching malicious websites, compiled by Lenny Zeltser. Disassembly framework for binary analysis and reversing, with support for many architectures and bindings in several languages.
Realtime database of malware and malicious domains. Pattern matching tool for analysts. Reverse engineering tool for virtualization wrappers. One click tool to retrieve as much metadata as possible for a website and to assess its good standing. WScript support and ActiveX emulation. Disassembler for analyzing malicious shellcode.
IP and UDP ports in a live system and maps them to the owning application. Reverse engineering subreddit, not limited to just malware. Malware database that detected by many anti malware programs except ClamAV. This package contains most of the software referenced in the Practical Malware Analysis book. Python tool for exploring possibly malicious PDFs. Catalog and compare malware at a function level. Modified version of Cuckoo Sandbox released under the GPL.
GUI for Pyew and Radare. Analyse suspicious PDF files. Read, write and edit file metadata. PE executables including imports, exports, and debug symbols. Guess XOR key length, as well as the key itself. The Pharos binary analysis framework can be used to perform automated static analysis of binaries. Curated by the CSIRT Gadgets Foundation. Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail. Binary analysis IDE for reverse engineering based on graph visualization.
Python script to monitor and generate alerts based on IOCs indexed by a set of Google Custom Search Engines. Sandbox for Analyzing Linux Malware. Malware samples collected for analysis. Data visualization and statistical analysis of Threat Intelligence feeds. Python library for working with OpenIOC objects, from Mandiant. Tools for dissecting malware in memory images or running systems. Live malware samples for analysts. Python tool for malware analysis.
Identifies and extracts information from bots and other malware. Open source, self hosted sandbox and automated analysis system. QuickSand is a compact C framework to analyze suspected malware documents to identify exploits in streams of different encodings and to locate and extract embedded executables. Part of GNU binutils, for static analysis of Linux binaries. Debugger for malware analysis and more, with a Python API. Honeypot tools, papers, and other resources. Block list based on domains and IPs.
Lenny Zeltser and other contributors for developing REMnux. Run Volatility on memory images before and after malware execution, and report changes. The macOS and Linux Disassembler. Multiplatform, open source Binary Analysis and Reverse engineering Framework. Extract, decode and display online the configuration settings from common malwares. Dynamic malware analysis system.
Python alternative to PEiD. Analyze suspicious office documents. Python script for not difficult searching of the TotalHash. Online static analysis of malware. Malware blog and resources by Lenny Zeltser. Free automated sandboxes and services, compiled by Lenny Zeltser. Windows disassembler and debugger, with a free evaluation version. Differential Analysis of Malware in Memory, built on Volatility. Free online analysis of APKs against multiple mobile antivirus apps.
This introductory malware dynamic analysis class is dedicated to people who are starting to work on malware analysis or who want to know what kinds of artifacts left by malware can be detected via various tools. National Software Reference Library database. Unpacks, scans and analyzes almost any firmware package. ELF, PE and MachO formats. JavaScript unpacking and deobfuscation. Tool to gather Threat Intelligence indicators from publicly available sources. Advanced task manager for Windows. Exploit and shellcode samples. An active community devoted to malware analysis and kernel development.
Tool that monitors system resources. OLE and OpenXML documents and extracting useful information. Malware repository, registration required. Inspect domains and IP addresses. Pull intelligence per host. Zulu URL Risk Analyzer. The FireEye Labs Obfuscated String Solver uses advanced static analysis techniques to automatically deobfuscate strings from malware binaries. Python RESTful API framework for online malware and URL analysis services.
Open source visualization library and command line tools for logs. Tool for exploration and tracing of the Windows kernel. IP research, and searching for file hashes and scan reports. See also the browser malware section. Multiple DNS blacklist and forward confirmed reverse DNS lookup over more than 300 RBLs. Disassembler library and tool for x86 and x86_64. Deconstruct malicious PDFs into a JSON representation. Library and tools for x86 shellcode emulation. Harvest and analyze IOCs.
Open source antivirus engine. JavaScript engine, for debugging malicious JS. Store, tag, and search malware. NET supports all Windows x64, includes code integrity and write support. Python Exploit Development Assistance for GDB, an enhanced display with added commands. Advanced monitoring tool for Windows programs. Not merged upstream due to legal concerns by the author. Suricata configured with EmergingThreats Pro.
Compute digest hashes with a variety of algorithms. Search for IP, domain or network owner. Agregator for malware corpus tracker and malicious download sites. CERTs for processing incident data using a message queue. Maltego transform for the VirusTotal API. NET deobfuscator and unpacker. This blog focuses on network traffic related to malware infections.
IN this List we could see the tools for Disassemblers, debuggers, and other static and dynamic analysis tools. GDB Enhanced Features, for exploiters and reverse engineers. Advanced memory forensics framework. Pull intelligence per file hash. Free analysis with an online Cuckoo Sandbox instance. An asynchronous and customizable analysis platform for suspicious files.
Automated malware unpacker for Windows malware based on WinAppDbg. Web Interface for Volatility Memory Analysis framework. Host based scanner for IOCs. Python scriptable reverse engineering sandbox by the Talos team at Cisco. Generate yara rules based on a set of malware samples. Reverse XOR and other code obfuscation methods. Java, JavaScript, Perl, PHP, Python, Ruby.
These are the course materials used in the Malware Analysis course at at Rensselaer Polytechnic Institute during Fall 2015. The Malware Analysis Tutorials by Dr. Analyze malicious JS and shellcode from PDFs and Office documents. This list is Created with helping of following Awesome Peoples. Guess a 256 byte XOR key using frequency analysis. Windows registry file format specification. Share and collaborate in developing Threat Intelligence. MacOS forensics client supporting hiberfil, pagefile, raw memory analysis.
Distributed content analysis framework with extensive plugin support, from input to output, and everything in between. Automatic sandboxed analysis of malware behavior. PDFs and attempting to determine whether they are malicious. Memory analysis framework, forked from Volatility in 2013. Online malware analysis tool, powered by VxSandbox. Wrapper for a variety of tools for reporting on Windows PE files.
Deep malware analysis with Joe Sandbox. Find AES encryption keys in memory. Uses Sysinternals Procmon to collect information about malware in a sandboxed environment. Script based on Volatility for automating various malware analysis tasks. Collaborative Research Into Threats, a malware and threat repository.
Comments
Post a Comment