Deobfuscation

Examine Static Properties

CyberChef

Decode and otherwise analyze data using this browser app.

Website: https://github.com/gchq/CyberChef/arrow-up-right Author: GCHQ License: Apache License 2.0: https://github.com/gchq/CyberChef/blob/master/LICENSEarrow-up-right Notes: cyberchef State File: remnux.tools.cyberchefarrow-up-right

Malchive

Perform static analysis of various aspects of malicious code.

Website: https://github.com/MITRECND/malchivearrow-up-right Author: The MITRE Corporation, https://github.com/MITRECND/malchive/graphs/contributorsarrow-up-right License: License 2.0: https://github.com/MITRECND/malchive/blob/main/LICENSEarrow-up-right Notes: Malchive command-line tools start with the prefix malutil-. See utilities documentationarrow-up-right for details. State File: remnux.python3-packages.malchivearrow-up-right

1768.py

Analyze Cobalt Strike beacons.

Website: https://blog.didierstevens.com/2021/05/22/update-1768-py-version-0-0-6/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain Notes: For an overview of this tool, see the Quick Tiparrow-up-right article. State File: remnux.scripts.1768arrow-up-right

cs-decrypt-metadata.py

Decrypt Cobalt Strike metadata.

Website: https://blog.didierstevens.com/2021/11/12/update-cs-decrypt-metadata-py-version-0-0-2/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.cs-decrypt-metadataarrow-up-right

Cobalt Strike Configuration Extractor (CSCE) and Parser

Analyze Cobalt Strike beacons.

Website: https://github.com/strozfriedberg/cobaltstrike-config-extractorarrow-up-right Author: Aon / Stroz Friedberg License: Apache License 2.0: https://github.com/strozfriedberg/cobaltstrike-config-extractor/blob/master/LICENSEarrow-up-right Notes: csce, list-cs-settings State File: remnux.python3-packages.cscearrow-up-right

sets.py

Perform set operations on lines or bytes in text files.

Website: https://blog.didierstevens.com/2021/05/22/update-1768-py-version-0-0-6/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.setsarrow-up-right

xortool

Analyze XOR-encoded data.

Website: https://github.com/hellman/xortoolarrow-up-right Author: Aleksei Hellman License: MIT License: https://github.com/hellman/xortool/blob/master/LICENSEarrow-up-right State File: remnux.python3-packages.xortoolarrow-up-right

RATDecoders

Python3 Decoders for Remote Access Trojans.

Website: https://github.com/kevthehermit/RATDecodersarrow-up-right Author: Kevin Breen: https://twitter.com/KevTheHermitarrow-up-right License: MIT License: https://github.com/kevthehermit/RATDecoders/blob/master/LICENSEarrow-up-right Notes: Only available on older version of REMnux based on Ubuntu 20.04 (Focal). malconf State File: remnux.python3-packages.ratdecodersarrow-up-right

DC3-MWCP

Parsing configuration information from malware.

Website: https://github.com/Defense-Cyber-Crime-Center/DC3-mwcparrow-up-right Author: Defense Cyber Crime Center - United States Government License: Some parts Public Domain, some MIT License: https://github.com/Defense-Cyber-Crime-Center/DC3-mwcp/blob/master/LICENSE.txtarrow-up-right Notes: mwcp State File: remnux.python3-packages.dc3-mwcparrow-up-right

unicode

Display Unicode character properties.

Website: https://github.com/garabik/unicodearrow-up-right Author: Radovan Garabik License: GNU General Public License (GPL) v3: https://github.com/garabik/unicode/blob/master/COPYINGarrow-up-right State File: remnux.python3-packages.unicodearrow-up-right

Chepy

Decode and otherwise analyze data using this command-line tool and Python library.

Website: https://github.com/securisec/chepyarrow-up-right Author: securisec: https://twitter.com/securisecarrow-up-right License: GNU General Public License (GPL) v3: https://github.com/securisec/chepy/blob/master/LICENSEarrow-up-right Notes: chepy State File: remnux.python3-packages.chepyarrow-up-right

Balbuzard

Extract and deobfuscate patterns from suspicious files.

Website: https://github.com/digitalsleuth/balbuzardarrow-up-right Author: Philippe Lagadec / Corey Forman (digitalsleuth) License: Free, custom license: https://github.com/digitalsleuth/balbuzardarrow-up-right Notes: balbuzard, bbcrack, bbharvest, bbtrans State File: remnux.python3-packages.balbuzardarrow-up-right

base64dump

Locate and decode strings encoded in Base64 and other common encodings.

Website: https://blog.didierstevens.com/2020/07/03/update-base64dump-py-version-0-0-12/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain Notes: base64dump.py State File: remnux.scripts.base64dumparrow-up-right

xor-kpa.py

Implement a XOR known plaintext attack.

Website: https://blog.didierstevens.com/2017/06/06/update-xor-kpa-py-version-0-0-5/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.xor-kpaarrow-up-right

NoMoreXOR.py

Help guess a file's 256-byte XOR by using frequency analysis.

Website: https://github.com/digitalsleuth/NoMoreXORarrow-up-right Author: Glenn P. Edwards Jr. License: Free, unknown license State File: remnux.scripts.nomorexorarrow-up-right

unXOR

Deobfuscate XOR'ed files.

Website: https://github.com/tomchop/unxor/arrow-up-right Author: Thomas Chopitea License: Apache License 2.0: https://github.com/tomchop/unxor/blob/master/LICENSEarrow-up-right State File: remnux.scripts.unxorarrow-up-right

brxor.py

Bruteforce XOR'ed strings to find those that are English words.

Website: https://github.com/REMnux/distro/blob/master/files/brxor.pyarrow-up-right Author: Alexander Hanel, Trenton Tait License: Free, unknown license State File: remnux.scripts.brxorarrow-up-right

xorBruteForcer.py

Bruteforce an XOR-encoded file.

Website: https://eternal-todo.com/category/bruteforcerarrow-up-right Author: Jose Miguel Esparza License: Free, unknown license State File: remnux.scripts.xorbruteforcerarrow-up-right

strdeob.pl

Locate and decode stack strings in executable files.

Website: https://github.com/REMnux/distro/blob/master/files/strdeob.plarrow-up-right Author: TotalHash License: Free, unknown license State File: remnux.scripts.strdeobarrow-up-right

cut-bytes.py

Cut out a part of a data stream.

Website: https://blog.didierstevens.com/2015/10/14/cut-bytes-py/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.cut-bytesarrow-up-right

format-bytes.py

Decompose structured binary data with format strings.

Website: https://blog.didierstevens.com/2020/02/17/update-format-bytes-py-version-0-0-13/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.format-bytesarrow-up-right

translate.py

Translate bytes according to a Python expression.

Website: https://blog.didierstevens.com/programs/translate/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.translatearrow-up-right

XORStrings

Search for XOR encoded strings in a file.

Website: https://blog.didierstevens.com/2013/04/15/new-tool-xorstrings/arrow-up-right Author: Didier Stevens License: Free, unknown license State File: remnux.packages.xorstringsarrow-up-right

XORSearch

Locate and decode strings obfuscated using common techniques.

Website: https://blog.didierstevens.com/programs/xorsearch/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain Notes: xorsearch State File: remnux.packages.xorsearcharrow-up-right

FLOSS

Extract and deobfuscate strings from PE executables.

Website: https://github.com/mandiant/flare-flossarrow-up-right Author: FireEye Inc, Willi Ballenthin: https://twitter.com/williballenthinarrow-up-right, Moritz Raabe License: Apache License 2.0: https://github.com/mandiant/flare-floss/blob/master/LICENSE.txtarrow-up-right Notes: floss State File: remnux.packages.flare-flossarrow-up-right

ex_pe_xor.py

Search an XOR'ed file for indications of executable binaries.

Website: http://hooked-on-mnemonics.blogspot.com/2014/04/expexorpy.htmlarrow-up-right Author: Alexander Hanel License: Free, unknown license State File: remnux.scripts.ex-pe-xorarrow-up-right

Didier Stevens Scripts

A collection of Python scripts for analyzing suspicious files and data from Didier Stevens.

Website: https://blog.didierstevens.comarrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.didier-stevens-scriptsarrow-up-right

Last updated