FLOSS is better. strings.exe is instant. Both live on the tools snapshot.
Put it next to the fancy things. They are not enemies.
Refs: FLARE VM
Lab / educational. Public binaries and patched classes only. Isolated VM.
FLOSS is better. strings.exe is instant. Both live on the tools snapshot.
Put it next to the fancy things. They are not enemies.
Refs: FLARE VM
Lab / educational. Public binaries and patched classes only. Isolated VM.
I still keep a paper notebook for this kind of note. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. I reproduced it on lab build 1135.
@danielcrest
I still keep a paper notebook for this kind of note. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better.
I ran this on a licensed corpus binary. The load-bearing line: FLOSS is better. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I will +rep a listing and −rep a vibe. That is the deal.
@deleconnect
I ran this on a licensed corpus binary. The load-bearing line: FLOSS is better. Name snapshots date plus hash plus pre/post. 'snapshot 12' l
Call-convention guess is not evidence. Not fully convinced yet. The load-bearing line: FLOSS is better. Profile YARA. One looping regex will eat a core. I wrote a 12-line script and then threw it away. The listing was enough.
I dumped after OEP and then did this. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Hash of the public file, or are we arguing a shape? I wrote a 12-line script and then threw it away. The listing was enough.
@fire
I dumped after OEP and then did this. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Hash
I reproduced it twice before I believed you. The load-bearing line: FLOSS is better. Clipboard off on the detonation VM. I pasted a token once. Version in my shot: current lab snapshot, not last year's blog.
This is the kind of thread that should be a sticky and is not. You wrote «FLOSS is better». That is the sentence I keep. Dirty VM means throw it. Do not apt upgrade a dirty box. I reproduced it on lab build 1227.
@golfx
This is the kind of thread that should be a sticky and is not. You wrote «FLOSS is better». That is the sentence I keep. Dirty VM means thro
You are describing a live target. Stop. Patched class only. This is the writeup I wanted when I was stuck. You wrote «FLOSS is better». That is the sentence I keep. PE-sieve is a lead. It is not a verdict. I will +rep a listing and −rep a vibe. That is the deal.
@hashr
This is the writeup I wanted when I was stuck. You wrote «FLOSS is better». That is the sentence I keep. PE-sieve is a lead. It is not a ver
I disagree with the tone, not the bytes. «I still keep a copy of strings.exe and I am not sorry» — specifically FLOSS is better. Profile YARA. One looping regex will eat a core. I will +rep a listing and −rep a vibe. That is the deal.
Did this on ARM64 last week — same shape, different pain. The load-bearing line: FLOSS is better. Dirty VM means throw it. Do not apt upgrade a dirty box. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1044.