Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Looking to learn about system exploitation, but don't know where to start? This (very) detailed guide covers all the basics. Contains 21 detailed CTF solutions, plenty of theory, and zero times the phrase "exercise left to the reader".
πŸ—£ynvb

> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then β€œgo practice, like you would with CTF exercises.”
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the β€œflag”) as a proof of having cracked the problem.

This is always my answer to this question.
πŸ‘€MaliciouSSymbol

Thank you!!!
πŸ‘€redimusu76

This is a great read. I hope more of this pops up.
πŸ‘€snake_case_believer


πŸŽ–@malwr
Fitz Roy: a free solo climbing to sanitize virtual machines
πŸ—£vilethan3773
Fitz Roy monitorizes Linux guests filesystems (raw, qcow2, vmdk , vdi, vpc, vhd) relying on libguestfs and Virustotal's API. Libguestfs mounts virtual machine filesystem and uploads suspicious files to Virustotal's API which are then analyzed.


πŸŽ–@malwr
When Mac has gone to hibernate/safe sleep can memory still be gathered?
If a MacBook Pro goes into hibernation mode can the ram still be acquired? The laptop is encrypted FV2 APFS...I’m guessing the ram would be written to disk and only FileVault password could cause the data to be written back to them ram...
πŸ—£Lackluster123

Are you asking "can it be recovered after it wakes up?"

Or "can it be recovered while it's in that state?"

The answer to the first one is yes, and the second one is "not with any tool I've ever heard of."
πŸ‘€Cypher_Blue


πŸŽ–@malwr
PCode Disasm - VB6 For Loops
πŸ—£dz3212

Wow. This is so cool!!! When do you plan to release this? I tried to find the WKTVB Debugger source code and use it, however, I don't have any idea how VB6 Pcode debugger works.
πŸ‘€ismael_akez


πŸŽ–@malwr