2024-08-23 |
C++ Unwind Exception Metadata: A Hidden Reverse Engineering Bonanza |
Rolf Rolles |
|
2022-01-26 |
An Exhaustively Analyzed IDB for ComLook |
Rolf Rolles |
|
2021-09-22 |
Automation in Reverse Engineering C++ STL/Template Code |
Rolf Rolles |
|
2021-06-02 |
Hex-Rays, GetProcAddress, and Malware Analysis |
Rolf Rolles |
|
2021-03-04 |
What is a while(2) loop in Hex-Rays? |
Rolf Rolles |
|
2021-03-03 |
An Exhaustively-Analyzed IDB for FlawedGrace |
Rolf Rolles |
|
2020-09-02 |
An Exhaustively-Analyzed IDB for ComRAT v4 |
Rolf Rolles |
|
2020-05-08 |
A Compiler Optimization involving Speculative Execution of Function Pointers |
Rolf Rolles |
|
2019-08-06 |
Automation Techniques in C++ Reverse Engineering |
Rolf Rolles |
|
2019-05-08 |
An Abstract Interpretation-Based Deobfuscation Plugin for Ghidra |
Rolf Rolles |
|
2019-05-08 |
Removing an Annoying Compiler Optimization with a Hex-Rays Microcode Plugin |
Rolf Rolles |
|
2019-05-08 |
A Quick Solution to an Ugly Reverse Engineering Problem |
Rolf Rolles |
|
2019-05-08 |
Hex-Rays CTREE API Scripting: Automated Contextual Function Renaming |
Rolf Rolles |
|
2019-05-08 |
Hex-Rays Microcode API vs. Obfuscating Compiler |
Rolf Rolles |
|
2019-05-08 |
Weekend Project: A Custom IDA Loader Module for the Hidden Bee Malware Family |
Rolf Rolles |
|
2019-05-08 |
The Atredis BlackHat 2018 CTF Challenge |
Rolf Rolles |
|
2019-05-08 |
Concrete and Abstract Interpretation, Explained through Chess |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Unpacking Tutorial Part 3: Devirtualization. Phase #4: Second Attempt at Devirtualization |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Unpacking Tutorial Part 3: Devirtualization. Phase #3: Fixing the Function-Related Issues |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Unpacking Tutorial Part 3: Devirtualization. Phase #2: First Attempt at Devirtualization |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Unpacking Tutorial Part 3: Devirtualization. Phase #1: Deobfuscating FinSpy VM Bytecode Programs |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Unpacking Tutorial Part 3: Devirtualization |
Rolf Rolles |
|
2019-05-08 |
FinSpy VM Part 2: VM Analysis and Bytecode Disassembly |
Rolf Rolles |
|
2019-05-08 |
A Walk-Through Tutorial, with Code, on Statically Unpacking the FinSpy VM: Part One, x86 Deobfuscation |
Rolf Rolles |
|
2019-05-08 |
The Synesthesia Shellcode Generator: Code Release and Future Directions |
Rolf Rolles |
|
2019-05-08 |
Synesthesia: Modern Shellcode Synthesis (Ekoparty 2016 Talk) |
Rolf Rolles |
|
2019-05-08 |
SMT-Based Binary Program Analysis Course Sample: X86 Assembly/Disassembly |
Rolf Rolles |
|
2019-05-08 |
Memory Lane: Hacking Renovo |
Rolf Rolles |
|
2019-05-08 |
Transparent Deobfuscation with IDA Processor Module Extensions |
|
|