Here is an overview of content I published in November:
Blog posts:
- Maldoc With Process Hollowing Shellcode
- Quickpost: Zone.Identifier
- Update: shellcode2vba.py Version 0.5
- Update: byte_stats.py Version 0.0.4
- Update: zipdump.py Version 0.0.4
- Update: base64dump.py Version 0.0.5
- Simple Ciphers: cipher-tool.py
- Update: xor-kpa.py Version 0.0.4
- Update: pdf-parser Version 0.6.6
YouTube videos:
- VBA Shellcode To Test EMET
- EMET vs Hancitor Maldoc
- Hancitor maldoc: Extracting URLs
- Hancitor Maldoc: Shellcode Dynamic Analysis
Videoblog posts:
- VBA Shellcode To Test EMET
- EMET vs Hancitor Maldoc
- Hancitor maldoc: Extracting URLs
- Hancitor Maldoc: Shellcode Dynamic Analysis
SANS ISC Diary entries:
- Hancitor Maldoc Bypasses Application Whitelisting
- VBA Shellcode and EMET
- VBA Shellcode and Windows 10
- ZIP With Comment
- Update:ZIP With Comment
- Extracting Shellcode From JavaScript
NVISO Labs blog posts: