Detect-It-Easy
flare-vm
Our great sponsors
Detect-It-Easy | flare-vm | |
---|---|---|
18 | 23 | |
6,567 | 5,856 | |
- | 3.8% | |
9.4 | 8.0 | |
6 days ago | 5 days ago | |
JavaScript | PowerShell | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Detect-It-Easy
-
E-book piracy - a weird ZIP file
If it was me, I'd first run something like DIE on it (I have a few such programs installed)- https://github.com/horsicq/Detect-It-Easy
- How do I debug software that detaches as soon as I attach the debugger
- Detect It Easy 3.07 Program for determining types of files for Windows, Linux and MacOS.
-
An error occurred while unpacking a game (ISDONE.DLL). How do I get rid of this in wine emulator?
You could try to run https://github.com/horsicq/Detect-It-Easy to maybe find out how it got packed... Would help narrow it down.
- Detect It Easy 3.06 Program for determining types of files for Windows, Linux and MacOS.
- Detect It Easy 3.05 Program for determining types of files for Windows, Linux and MacOS.
-
Decompiling MPRESS packed Autohotkey scripts!
First to confirm suspicions we will download and launch Detect it easy and click THIS button and select your executable and it should say "MPRESS 2.19" right HERE, that's how you know it's an MPRESS packed executable
- How do I decompile Windows' setup.exe?
- Detect It Easy 3.04 Program for determining types of files for Windows, Linux and MacOS.
- What language/Technology used by anydesk ? The application seems to be small and is able to run on all platforms natively. my closest guess is delphi suites.. but unsure.
flare-vm
-
Looking for x86 Assembly learning material
Follow the instructions here to setup a FLARE vm which will have all the tools you need for the labs in the book flare vm
-
Small company, small analysis Platform
FLARE VM: this is a boxstarter from Mandiant to add a bunch of tools to Windows for malware analysis
-
Home lab for cybersecurity
build it as a proxmox host and have a malware analysis VM (flare-vm for example - https://github.com/mandiant/flare-vm) you can then interact with it via Console or host another VM as an SSH jump box and ssh tunnel to port 3389 on the malware vm
- Ma poate ajuta cineva ? Am descărcat ceva de pe filelist si după am întâmpinat asta.
- Any sandbox app (Windows or Linux) that supports network routing?
-
OS Recommendations for DFIR
FLARE VM: a Windows toolkit for malware analysis from Mandiant: https://github.com/mandiant/flare-vm
-
L1 analysts, do you do malware analysis? If so how often?
I usually run it in virtualbox without guest additions, get one of those free windows 10 isos from microsoft and install the mandiant flare vm on it ( https://github.com/mandiant/flare-vm ), after everything is installed i keep a snapshot of the windows machine with everything set up so i dont have to do it all again and once its done i set the network to internal and set set up inetsim on remnux as well if im going to do dynamic analysis so that i have an internet simulator that the malware can talk to.
-
How do you setup a malware analysis sandbox?
I use https://any.run for quick stuff or just fire my FlareVM up.
- Any distro for forensic blue team?
- How to set up a laptop as a dedicated mal-lab that has access to my home network for malware to send and receive traffic but cannot propagate to the rest of my devices?
What are some alternatives?
drakvuf-sandbox - DRAKVUF Sandbox - automated hypervisor-level malware analysis system
commando-vm - Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. [email protected]
radare2 - UNIX-like reverse engineering framework and command-line toolset
x64dbg - An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Nauz-File-Detector - Linker/Compiler/Tool detector for Windows, Linux and MacOS.
flare-fakenet-ng - FakeNet-NG - Next Generation Dynamic Network Analysis Tool
youtube-dl-gui - A cross platform front-end GUI of the popular youtube-dl written in wxPython.
Binance-APK-Analysis - Revealing secrets behind Binance Crypto Exchange platform through Android APK Analysis
PEpper - An open source script to perform malware static analysis on Portable Executable
pwndbg - Exploit Development and Reverse Engineering with GDB Made Easy