capa first for the boring capabilities. Then I look. If you skip capa you will miss the boring ones and write about the exciting ones.
Boring is the job.
Refs: FLARE VM
Lab / educational. Public binaries and patched classes only. Isolated VM.
capa first for the boring capabilities. Then I look. If you skip capa you will miss the boring ones and write about the exciting ones.
Boring is the job.
Refs: FLARE VM
Lab / educational. Public binaries and patched classes only. Isolated VM.
Quietly the best note on this board this month. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Dirty VM means throw it. Do not apt upgrade a dirty box. I wrote a 12-line script and then threw it away. The listing was enough.
If you only have the decompiler, you do not have the bug. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. Version in my shot: current lab snapshot, not last year's blog.
Also: Caps on the drop folder saved the box. The 4GB 'txt' was a dump.
@dump_the_core
If you only have the decompiler, you do not have the bug. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring
Came back to this after a coffee. Still hold. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. What did you key the join on ā PID or process GUID? I reproduced it on lab build 1261.
@analyst
Came back to this after a coffee. Still hold. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilitie
Do not call people skids because they use Ghidra. Bookmarking this for the lab wiki. The load-bearing line: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. My note id for this: 10c-14.
I want the listing, not the decompiler story. The load-bearing line: capa first for the boring capabilities. Transfer samples as a hashed read-only ISO. Not drag-drop. Pinned a comment at 0x140006adf in the listing.
@bitwse
I want the listing, not the decompiler story. The load-bearing line: capa first for the boring capabilities. Transfer samples as a hashed re
I disagree with the tone, not the bytes. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. My note id for this: 10c-16.
I failed this exact class in January. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. PE-sieve is a lead. It is not a verdict. I wrote a 12-line script and then threw it away. The listing was enough.
@chain
I failed this exact class in January. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. PE-si
Take the telegram pitch to the bin. Market listing or nothing. Please keep the hashes and drop the mystery zips. You wrote «capa first for the boring capabilities». That is the sentence I keep. PE-sieve is a lead. It is not a verdict. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1342.
@cldsec
Please keep the hashes and drop the mystery zips. You wrote «capa first for the boring capabilities». That is the sentence I keep. PE-sieve
Bookmarking this for the lab wiki. You wrote «capa first for the boring capabilities». That is the sentence I keep. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. My note id for this: 10c-19.
This is the kind of thread that should be a sticky and is not. The load-bearing line: capa first for the boring capabilities. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. I will +rep a listing and ārep a vibe. That is the deal.
Also: Clipboard off on the detonation VM. I pasted a token once.
Good. Dated shot, version in the post. You wrote «capa first for the boring capabilities». That is the sentence I keep. FakeNet that can reach the internet is not a simulator. If anyone DMs me a zip I will not open it. Hash in-thread.
@deltafx
Good. Dated shot, version in the post. You wrote «capa first for the boring capabilities». That is the sentence I keep. FakeNet that can rea
You are treating a checksum as a signature again. I still keep a paper notebook for this kind of note. The load-bearing line: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. My note id for this: 10c-22.
Good. Dated shot, version in the post. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. Did you force-create the function or did auto-analysis luck into it? I wrote a 12-line script and then threw it away. The listing was enough.
Came back to this after a coffee. Still hold. The load-bearing line: capa first for the boring capabilities. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. Same class as the October thread, different binary.
@freq
Came back to this after a coffee. Still hold. The load-bearing line: capa first for the boring capabilities. Do not detonate in Docker. Shar
Good. Dated shot, version in the post. The load-bearing line: capa first for the boring capabilities. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. If anyone DMs me a zip I will not open it. Hash in-thread.
@grayx
Good. Dated shot, version in the post. The load-bearing line: capa first for the boring capabilities. Caps on the drop folder saved the box.
I am not moving this to DMs so you can yell. Stay on the class. Good. Dated shot, version in the post. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I wrote a 12-line script and then threw it away. The listing was enough.
Please keep the hashes and drop the mystery zips. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. Same class as the January thread, different binary.
@iamflex
Please keep the hashes and drop the mystery zips. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the bor
Came back to this after a coffee. Still hold. You wrote «capa first for the boring capabilities». That is the sentence I keep. Transfer samples as a hashed read-only ISO. Not drag-drop. Can you quote the offset instead of the graph screenshot? My note id for this: 10c-28.
I would have written the opposite conclusion a year ago. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. Profile YARA. One looping regex will eat a core. I reproduced it on lab build 1076.
@kabirjay
I would have written the opposite conclusion a year ago. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring
I read the patch. You read a tweet. Those are not the same source. Not fully convinced yet. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Tools snapshot in 8 minutes or you will not restore it. Same class as the June thread, different binary.
@l0gic
Not fully convinced yet. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Tools s
I reproduced it twice before I believed you. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. I still have the snapshot named tool-268-pre.
Quietly the best note on this board this month. You wrote «capa first for the boring capabilities». That is the sentence I keep. Profile YARA. One looping regex will eat a core. I still have the snapshot named tool-268-pre.
I would have written the opposite conclusion a year ago. The load-bearing line: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. Did you force-create the function or did auto-analysis luck into it? Pinned a comment at 0x1400027da in the listing.
@netrix
I would have written the opposite conclusion a year ago. The load-bearing line: capa first for the boring capabilities. FakeNet that can rea
Do not call people skids because they use Ghidra. Did this on ARM64 last week ā same shape, different pain. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. PE-sieve is a lead. It is not a verdict. I will +rep a listing and ārep a vibe. That is the deal.
@netmap
Quietly the best note on this board this month. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the borin
Bookmarking this for the lab wiki. The load-bearing line: capa first for the boring capabilities. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I will +rep a listing and ārep a vibe. That is the deal.
@ohmx
Bookmarking this for the lab wiki. The load-bearing line: capa first for the boring capabilities. Name snapshots date plus hash plus pre/pos
You are treating a checksum as a signature again. I dumped after OEP and then did this. You wrote «capa first for the boring capabilities». That is the sentence I keep. FakeNet that can reach the internet is not a simulator. Version in my shot: current lab snapshot, not last year's blog.
I ran this on a licensed corpus binary. The load-bearing line: capa first for the boring capabilities. PE-sieve is a lead. It is not a verdict. I reproduced it on lab build 1142.
Came back to this after a coffee. Still hold. You wrote «capa first for the boring capabilities». That is the sentence I keep. Tools snapshot in 8 minutes or you will not restore it. Did you force-create the function or did auto-analysis luck into it? Same class as the March thread, different binary.
I want the listing, not the decompiler story. The load-bearing line: capa first for the boring capabilities. Do not detonate in Docker. Shared kernel. VMs for samples, containers for tools. Version in my shot: current lab snapshot, not last year's blog.
Also: Transfer samples as a hashed read-only ISO. Not drag-drop.
@primez
Came back to this after a coffee. Still hold. You wrote «capa first for the boring capabilities». That is the sentence I keep. Tools snapsho
Did this on ARM64 last week ā same shape, different pain. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. I wrote a 12-line script and then threw it away. The listing was enough.
@prosmart
I want the listing, not the decompiler story. The load-bearing line: capa first for the boring capabilities. Do not detonate in Docker. Shar
I want the listing, not the decompiler story. The load-bearing line: capa first for the boring capabilities. Tools snapshot in 8 minutes or you will not restore it. I will +rep a listing and ārep a vibe. That is the deal.
This is the writeup I wanted when I was stuck. The load-bearing line: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. My note id for this: 10c-05.
@scrpt
This is the writeup I wanted when I was stuck. The load-bearing line: capa first for the boring capabilities. FakeNet that can reach the int
I am not moving this to DMs so you can yell. Stay on the class. Quietly the best note on this board this month. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Caps on the drop folder saved the box. The 4GB 'txt' was a dump. I wrote a 12-line script and then threw it away. The listing was enough.
@sigx
Quietly the best note on this board this month. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the borin
I would have written the opposite conclusion a year ago. Ā«capa vs 'I know this packer' ā both, in that orderĀ» ā specifically capa first for the boring capabilities. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. I reproduced it on lab build 1172.
I want the listing, not the decompiler story. You wrote Ā«capa first for the boring capabilitiesĀ». That is the sentence I keep. Name snapshots date plus hash plus pre/post. 'snapshot 12' loses a week. What did you key the join on ā PID or process GUID? My note id for this: 10c-08.
I tried the naive path first and wasted a morning. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. FakeNet that can reach the internet is not a simulator. I still have the snapshot named tool-268-pre.
@vectx
I tried the naive path first and wasted a morning. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabi
I read the patch. You read a tweet. Those are not the same source. Agreed on the class, not on the tool. On Ā«capa vs 'I know this packer' ā both, in that orderĀ»: capa first for the boring capabilities. Transfer samples as a hashed read-only ISO. Not drag-drop. Pinned a comment at 0x140002ac3 in the listing.
I would have written the opposite conclusion a year ago. You wrote «capa first for the boring capabilities». That is the sentence I keep. Profile YARA. One looping regex will eat a core. I still have the snapshot named tool-268-pre.