Showing posts with label analysis. Show all posts
Showing posts with label analysis. Show all posts
Sunday, April 16, 2017
DAMM Differential Analysis of Malware in Memory
DAMM Differential Analysis of Malware in Memory
An open source memory analysis tool built on top of Volatility. It is meant as a proving ground for interesting new techniques to be made available to the community. These techniques are an attempt to speed up the investigation process through data reduction and codifying some expert knowledge.
Features
- ~30 Volatility plugins combined into ~20 DAMM plugins (e.g., pslist, psxview and other elements are combined into a processes plugin)
- Can run multiple plugins in one invocation
- The option to store plugin results in SQLite databases for preservation or for "cached" analysis
- A filtering/type system that allows easily filtering on attributes like pids to see all information related to some process and exact or partial matching for strings, etc.
- The ability to show the differences between two databases of results for the same or similar machines and manipulate from the cmdline how the differencing operates
- The ability to warn on certain types of suspicious behavior
- Output for terminal, tsv or grepable
NOTE: Most DAMM output looks better piped through less -S (upper S) as in:
#python damm.py <some DAMM functionality> | less -S (for default output format)
python damm.py -h
usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG]
[--db DB] [--profile PROFILE] [--debug] [--info] [--tsv]
[--grepable] [--filter FILTER] [--filtertype FILTERTYPE]
[--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]
DAMM v1.0 Beta
optional arguments:
-h, --help show this help message and exit
-d DIR Path to additional plugin directory
-p PLUGIN [PLUGIN ...]
Plugin(s) to run. For a list of options use --info
-f FILE Memory image file to run plugin on
-k KDBG KDBG address for the images (in hex)
--db DB SQLite db file, for efficient input/output
--profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86)
--debug Print debugging statements
--info Print available volatility profiles, plugins
--tsv Print screen formatted output.
--grepable Print in grepable text format
--filter FILTER Filter results on name:value pair, e.g., pid:42
--filtertype FILTERTYPE
Filter match type; either "exact" or "partial",
defaults to partial
--diff BASELINE Diff the imageFile|db with this db file as a baseline
-u FIELD [FIELD ...] Use the specified fields to determine uniqueness of
memobjs when diffing
--warnings Look for suspicious objects.
-q Query the supplied db (via --db).
Supported plugins
See #python damm.py --info
apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers
Download DAMM
Go to link download
Sunday, March 12, 2017
Viper A binary management and analysis framework dedicated to malware and exploit researchers
Viper A binary management and analysis framework dedicated to malware and exploit researchers


Viper is a binary analysis and management framework. Its fundamental objective is to provide a solution to easily organize your collection of malware and exploit samples as well as your collection of scripts you created or found over the time to facilitate your daily research. Think of it as a Metasploit for malware researchers: it provides a terminal interface that you can use to store, search and analyze arbitraty files with and a framework to easily create plugins of any sort.
Download Viper
Go to link download
Friday, March 10, 2017
WiFi software Acrylic WiFi Free v2 0 Real time WLAN information and network analysis
WiFi software Acrylic WiFi Free v2 0 Real time WLAN information and network analysis

New Acrylic WiFi software update. WiFi software for network analysis has gone through many changes since the first free version and finally reaches version v2.0 with more power than ever and long awaited features for network and channel analysis under Windows and with any wireless card.
Acrylic WiFi Free and Professional WiFi software news:
The main improvements of the new Acrylic WiFi software release are as follows:
- Acrylic Free WiFi program incorporates information about the maximum speeds supported by the WiFi access point.
- Fixed install and uninstall issues with NDIS capture driver under x64
- Enhanced NDIS driver to avoid packet loss under heavy network capture with monitor mode.
- Enhanced Wireshark integration for better performance and fixed radiotap header issues
- Fixed compatibility with Windows Vista.
- Added additional Visual studio dependencies.
- Fixed issues when requesting trial licenses for Acrylic WiFi professional.
- New exception handler module to detect Acrylic bugs.
- Execute Acrylic as user: Acrylic can be installed and executed as user, without administrator rights. Note that without admin privileges monitor mode wont be available
- Added additional software tooltips.
- Added social network buttons to share information about Acrylic WiFi software with all your friends and followers :).
- Improved graphical interface and usability.
- Acrylic WiFi Free starts with data capture automatically once the program is executed.
Download WiFi software Acrylic WiFi Free v2.0
Go to link download
Tuesday, March 7, 2017
OWASP iOSForensic Tool to help in forensics analysis on iOS
OWASP iOSForensic Tool to help in forensics analysis on iOS

OWASP iOSForensic is a python tool to help in forensics analysis on iOS.
It get files, logs, extract sqlite3 databases and uncompress .plist files in xml.
OWASP iOSForensic provides:
- Applications files
- Conversion of .plist files in XML
- Extract all databases
- Conversion of binary cookies
- Applications logs
- A List of all packages
- Extraction multiple packages
Options
- -h --help : show help message
- -a --about : show informations
- -v --verbose : verbose mode
- -i --ip : local ip address of the iOS terminal
- -p --port : ssh port of the iOS terminal (default 22)
- -P --password : root password of the iOS terminal (default alpine)
Examples:
./iOSForensic.py -i 192.168.1.10 [OPTIONS] APP_NAME.app INCOMPLETE_APP_NAME APP_NAME2_WITHOUT_DOT_APP
./iOSForensic.py -i 192.168.1.10 -p 1337 -P pwd MyApp.app angry MyApp2Download OWASP iOSForensic
Go to link download
Sunday, March 5, 2017
ParanoiDF PDF Analysis Suite Password cracking redaction recovery DRM removal malicious JavaScript extraction and more
ParanoiDF PDF Analysis Suite Password cracking redaction recovery DRM removal malicious JavaScript extraction and more

The swiss army knife of PDF Analysis Tools. Based on peepdf - http://peepdf.eternal-todo.com.
Features
Interactive Console: Type "help" to get a list of commands. Type "help [command]" to get a description/usage on specific command.
- crackpw This executes Nacho Barrientos Ariass PDFCrack tool by performing an OS call. The command allows the user to input a custom dictionary, perform a benchmark or continue from a saved state file. If no custom dictionary is input, this command will attempt to brute force a password using a modifiable charset text file in directory "ParanoiDF/pdfcrack". (http://pdfcrack.sourceforge.net/)
- decrypt This uses an OS call to Jay Berkenbilts "QPDF" which decrypts the PDF document and outputs the decrypted file. This requires the user-password. (http://qpdf.sourceforge.net/)
- encrypt Encrypts an input PDF document with any password you specify. Uses 128-bit RC4 encryption.
- embedf Create a blank PDF document with an embedded file. This is for research purposes to show how files can be embedded in PDFs. This command imports Didier Stevens Make-pdf-embedded.py script as a module. (http://blog.didierstevens.com/programs/pdf-tools/)
- embedjs Similiar to "embedf", but embeds custom JavaScript file inside a new blank PDF document. If no custom JavaScript file is input, a default app.alert messagebox is embedded (http://blog.didierstevens.com/programs/pdf-tools/)
- extractJS This attempts to extract any embedded JavaScript in a PDF document. It does this by importing Blake Hartsteins Jsunpackns "pdf.py" JavaScript tool as a module, then executing it on the file. (https://code.google.com/p/jsunpack-n/)
- redact Generate a list of words that will fit inside a redaction box in a PDF document. The words (with a custom sentence) can then be parsed in a grammar parser and a custom amount can be displayed depending on their score. This command requires a tutorial to use. Please read "redactTutorial.pdf" in directory "ParanoiDF/docs".
- removeDRM Remove DRM (editing, copying etc.) restrictions from PDF document and output to a new file. This does not need the owner-password and there is a possibility the document will lose some formatting. This command works by calling Kovid Goyals Calibres "ebook-convert" tool. (http://calibre-ebook.com/)
Download ParanoiDF
Go to link download
Webfwlog 1 01 Web Based Firewall Log Analysis and Reporting
Webfwlog 1 01 Web Based Firewall Log Analysis and Reporting

Webfwlog is a flexible web-based firewall log analyzer and reporting tool. It supports standard system logs for linux, FreeBSD, OpenBSD, NetBSD, Solaris, Irix, OS X, etc. as well as Windows XP®. Supported log file formats are netfilter, ipfilter, ipfw, ipchains and Windows XP®. Webfwlog also supports logs saved in a database using the ULOG or NFLOG targets of the linux netfilter project, or any other database logs mapped with a view to the ulogd schema. Versions 1 and 2 of ulogd database schemas are supported.
Webfwlog fully supports IPv6 for database logs, and netfilter and ipfilter system logs.
With Webfwlog you can design reports to use on your logged data in whatever configuration you desire. Included are example reports as a starting point. You can sort a report with a single click, "drill-down" on the reports all the way to the packet level, and save your reports for later use. You can also create a link directly to any saved report.
PREREQUISITES
- A web server with PHP >= 4.1
- Log files in standard netfilter, ipfilter, ipfw, ipchains or Windows XP® format
or database logs populated with the ULOG or NFLOG target of netfilter,
or other database logs mapped with a view to ulogd version 1 or 2 schemas
- A MySQL or PostgreSQL database server:
- MySQL >= 3.23.52 or any production release of 4.x or 5.x
- MySQL >= 5 required for IPv6
- PostgreSQL >= 7.1
- PostgreSQL >= 7.4 required for IPv6
- Your favorite web browser.
Windows XP® support provided via Cygwin.
Download Webfwlog 1.01
Go to link download
Subscribe to:
Posts (Atom)