Content Paint

Dnspy

Malware Unpacking With Memory Dumps - Intermediate Methods (Pe-Sieve, Process Hacker, Hxd and Pe-bear)

Demonstrating three additional methods for obtaining unpacked malware samples. Using Process Hacker, Pe-sieve, Hxd and Pe-bear.

How to Use Process Hacker and DnSpy to Unpack .NET Malware

Unpacking an Asyncrat loader using Process Hacker and Dnspy

How to Write Yara Rules For DotNet Malware

How to develop Yara rules for .NET Malware. Utilising IL instructions and associated bytecodes.

How To Write a Simple Configuration Extractor For .NET Malware - RevengeRAT

Introduction to dotnet configuration extraction. Leveraging RevengeRat and Python.

How To Track Quasar Rat C2 Infrastructure Using TLS Certificates

Extraction of Quasar C2 configuration via Dnspy, and using this information to pivot to additional servers utilising Shodan and Censys.

Manual analysis and deobfuscation of a .NET based Dcrat. Touching on Custom Python Scripts, Cyberchef and .NET analysis with Dnspy.

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.