base64_substring Logo

base64_substring

0
Free
Visit Website

The base64_substring tool helps malware analysts search through base64-encoded samples by enumerating all possible base64 encodings for a given search term and generating a yara rule that checks those possibilities. To run an example, generate a yara rule that matches a base64-encoded file containing the term 'Application' by using the provided script. Further reading: 'Searching for Content in Base-64 Strings' by Lee Holmes.

FEATURES

ALTERNATIVES

A native Python cross-version decompiler and fragment decompiler.

Compact C framework for analyzing suspected malware documents and detecting exploits and embedded executables.

Tplmap is a tool for detecting and exploiting server-side template injection vulnerabilities.

A tool to help exploit XXE vulnerabilities by sending a crafted XML file to the server and parsing it to extract the data.

RABCDAsm is a collection of utilities for ActionScript 3 assembly/disassembly and SWF file manipulation.

Detect capabilities in executable files and identify potential behaviors.

A write-up of the reverse engineering challenge from the 2019 BambooFox CTF competition

A tool to find XSS vulnerabilities in web applications

PINNED