CyberChef Tutorials
Advanced Cyberchef Techniques - Defeating Nanocore Obfuscation With Math and Flow Control
Applying Flow Control and Mathematical operators to deobfuscate a .vbs loader for Nanocore malware.
CyberChef Tutorials
Applying Flow Control and Mathematical operators to deobfuscate a .vbs loader for Nanocore malware.
How To Use CyberChef
Decoding a Cobalt Strike script with CyberChef and VsCode.
Malware Analysis Guides
Identifying and Removing Obfuscation in a Self-Referencing Latrodectus Loader
Malware Analysis Guides
Advanced CyberChef techniques using Registers, Regex and Flow Control
Malware Analysis Guides
Manual analysis of Cobalt Strike Shellcode with Ghidra. Identifying function calls and resolving API hashing.
Malware Analysis Guides
Manual identification, decryption and fixing of encrypted strings using Ghidra and x32dbg.
Malware Analysis Guides
Leveraging Ghidra to establish context and intent behind imported functions.
Malware Analysis Guides
Leveraging Ghidra to establish context and intent behind suspicious strings.
Malware Analysis Guides
Manually Reversing a decryption function using Ghidra, ChatGPT and CyberChef.
Malware Analysis Guides
Extracting C2 configuration using the Garbageman .NET analysis tool
Ghidra Tutorials
Unpacking a simple Cobalt Strike loader using Debuggers and Hardware breakpoints.
Malware Analysis Guides
Demonstrating three additional methods for obtaining unpacked malware samples. Using Process Hacker, Pe-sieve, Hxd and Pe-bear.