Here is an overview of content I published in December:
Blog posts:
- Update: oledump.py Version 0.0.56
- Update: pecheck.py Version 0.7.12
- Quickpost: finger.exe
- Update: numbers-to-string.py Version 0.0.11
- Update: oledump.py version 0.0.57
- Decrypting TLS Streams With Wireshark: Part 1
- Update: strings.py Version 0.0.6
- Update: translate.py Version 2.5.11
- Update: cut-bytes.py Version 0.0.13
- Update: byte-stats.py Version 0.0.8
- Video: Using numbers-to-string.py To Analyze FireEye Maldocs
- Update: zipdump.py Version 0.0.21
- Update: base64dump.py Version 0.0.13
- Update: 1768.py Version 0.0.4
- Decrypting TLS Streams With Wireshark: Part 2
- Update: rtfdump.py Version 0.0.10
YouTube videos:
- Analyzing FireEye Maldocs
- Inspecting Process Explorer Traffic With Fiddler
- Hobo Knife
- Process Explorer & VirusTotal: Fixed!
- December 2020: Jupiter & Saturn
Videoblog posts:
- Analyzing FireEye Maldocs
- Inspecting Process Explorer Traffic With Fiddler
- Hobo Knife
- Process Explorer & VirusTotal: Fixed!
- December 2020: Jupiter & Saturn
SANS ISC Diary entries:
- oledump’s Indicators (video)
- Corrupt BASE64 Strings: Detection and Decoding
- Office 95 Excel 4 Macros
- Wireshark 3.4.1 Released
- KringleCon 2020
- Analyzing FireEye Maldocs
- Wireshark 3.4.2 Released
- Heads-up: VirusTotal Functionality in Sysinternals Tools Not Working
- Quickie: String Analysis & Maldocs
- base64dump.py Supported Encodings
- Quickie: Bit Shifting With translate.py