Have You Ever Heard of the Fernet Encryption Algorithm?, (Tue, Aug 22nd)

In cryptography, there is a gold rule that states to not develop your own algorithm because… it will be probably weak and broken! They are strong algorithms (like AES) that do a great job so why reinvent the wheel? However, there are projects that try to develop new algorithms. One of them is Fernet[1], described like this:

Continue reading Have You Ever Heard of the Fernet Encryption Algorithm?, (Tue, Aug 22nd)→

Posted in Uncategorized

Quick Malware Triage With Inotify Tools, (Mon, Aug 21st)

When you handle a lot of malicious files, you must have a process and tools in place to speedup the analysis. It&#;x26;#;39;s impossible to investigate all files and a key point is to find interesting files that deserve more attention. In my malware analysis lab, I use a repository called my “Malware Zoo” where I put all the files. This repository is shared across different hosts (my computer, REMnux and Windows virtual machines). This helps me to keep all the “dangerous files” in a central location and avoid spreading dangerous stuff everywhere. When you analyze a malware, you&#;x26;#;39;ll quickly generate more files: You extract shellcodes, configurations, DLLs, more executables and those files should also be analyzed. To perform a quick triage with basic operations, I rely on the Inotify[1] suite.

Continue reading Quick Malware Triage With Inotify Tools, (Mon, Aug 21st)→

Posted in Uncategorized