Search the Community
Showing results for tags 'v0.2.0'.
-
Motivation During the forensic analysis of a Windows machine, you may find the name of a deleted prefetch file. While its content may not be recoverable, the filename itself is often enough to find the full path of the executable for which the prefetch file was created. [hide][Hidden Content]]
-
- 4
-
- prefetch-hash-cracker
- v0.2.0
-
(and 5 more)
Tagged with:
-
Prefetch Hash Cracker During the forensic analysis of a Windows machine, you may find the name of a deleted prefetch file. While its content may not be recoverable, the filename itself is often enough to find the full path of the executable for which the prefetch file was created. How does it work? The provided bodyfile is used to get the path of every folder on the volume. The tool appends the provided executable name to each of those paths to create a list of possible full paths for the executable. Each possible full path is then hashed using the provided hash function. If there’s a possible full path for which the result matches the provided hash, that path is outputted. [Hidden Content]
-
Deep ghidra decompiler and sleigh disassembler integration for rizin This is an integration of the Ghidra decompiler and Sleigh Disassembler for rizin. It is solely based on the decompiler part of Ghidra, which is written entirely in C++, so Ghidra itself is not required at all and the plugin can be built self-contained. This project was presented, initially for radare2, at r2con 2019 as part of the Cutter talk: [Hidden Content] [hide][Hidden Content]]
-
What is this? As the name implies, this is a hex editor. It aims to be a good general-purpose hex editor and to have a wide selection of features for analysing and annotating binary file formats. It is still in early development and should be considered in beta state at the moment. Current features include: Large* file support Decoding of integer/floating point value types Disassembly of machine code Highlighting and annotation of ranges of bytes Side by side comparision of selections 0.2.0 Allow copying comments from a document and pasting them elsewhere in the same document or into another one. Fixed bounds check when clicking on nested comments in a document. Added context menu when right clicking on a comment in a document. Optionally highlight byte sequences which match the current selection. ("Highlight data matching selection" or "PatternMatchHighlight"). Allow copying cursor offset from document context menu. Correctly display offsets over 4GiB in the status bar. Display offsets as XXXX:XXXX rather than XXXXXXXX:XXXXXXXX when the file size is under 4GiB. Add per-document option for dec/hex offset display. When first byte after a comment is deleted, show that the comment was deleted rather than leaving phantom comment on screen until regions are repopulated. Add side-by-side comparison of chunks of data from files. Select data and choose "Compare..." from context menu to open diff window. Clean up search threads when a tab is closed while a search is running. Display bytes which have been modified since the file was saved in red. [hide][Hidden Content]]
-
- 2
-
- reverse
- engineer's
-
(and 3 more)
Tagged with: