Didier Stevens

Saturday 26 August 2023

Overview of Content Published in July

Filed under: Announcement — Didier Stevens @ 8:41
Here is an overview of content I published in July:

Blog posts: SANS ISC Diary entries:

Sunday 16 July 2023

Overview of Content Published in June

Filed under: Announcement — Didier Stevens @ 7:50
Here is an overview of content I published in June:

Blog posts: SANS ISC Diary entries:

Thursday 15 June 2023

Overview of Content Published in May

Filed under: Announcement — Didier Stevens @ 7:56
Here is an overview of content I published in May:

Blog posts: SANS ISC Diary entries:

Monday 1 May 2023

Overview of Content Published in April

Filed under: Announcement — Didier Stevens @ 22:43
Here is an overview of content I published in April:

Blog posts: SANS ISC Diary entries:

Monday 10 April 2023

New Tool: myjson-transform.py

Filed under: Announcement,My Software,Uncategorized — Didier Stevens @ 8:05

This tool takes JSON output from tools like oledump, zipdump, base64dump, … via stdin and transforms the data produced by these tools.
The transformation function (name Transform) has to be defined in a Python script provided via option -s.

This Transform function has 2 arguments: items and options.
items is a list of dictionaries produced by the “feeding” tool , e.g., the tool whose JSON output is piped into this tool (oledump, …).
Each dictionary has 3 keys: id, name and content.

The transformation function reads content from the items, and transforms it. The transformed data is the return value of the Transform function, and it can also be stored in the items list (modifying the values of the dictionaries, like the content value for example).

By default, this tool will output the transformed data (return value of Transform function) as binary data.
With options -a, -A, -x, -X, -b, -B this output can be presented as ASCII dump, hex dump and base64 dump. Option -d is also present to explicitly request a binary dump.

If option –jsonoutput is used, then the return value of the Transform function is ignored, and in stead, the transformed items are output as JSON data.
The –jsonouput option can not be combined with the above output format options.

Option -p (–parameter) is a string option that is passed on to the Transform function (via options argument). It is designed to be used by the developer of the Transform function as they see fit.
For example, it can be used to tell the Transform function which item to select for transformation, in case there are several items.

Take a look at my SANS ISC diary entry “Another Malicious HTA File Analysis – Part 2” for an example on how to decrypt an AES encrypted payload.

myjson-transform_V0_0_1.zip (http)
MD5: 01669E77D9706317A92112E2918A73B9
SHA256: 5DD1DB80D18480196C5EEF415AA7D22C1EB54B985B4D6ACF56E739B58052D34C

Saturday 1 April 2023

Overview of Content Published in March

Filed under: Announcement — Didier Stevens @ 7:25
Here is an overview of content I published in March:

Blog posts: SANS ISC Diary entries:

Thursday 23 March 2023

Overview of Content Published in February

Filed under: Announcement — Didier Stevens @ 19:19
Content: Here is an overview of content I published in February:

Blog posts: SANS ISC Diary entries:

Saturday 4 February 2023

Overview of Content Published in January

Filed under: Announcement — Didier Stevens @ 18:22
Here is an overview of content I published in January:

Blog posts: SANS ISC Diary entries:

Monday 2 January 2023

Overview of Content Published in 2022

Filed under: Announcement — Didier Stevens @ 0:00
Here is an overview of content I published in 2022:

Blog posts: YouTube videos: Videoblog posts: SANS ISC Diary entries: NVISO blog posts: NVISO Videos:

Sunday 1 January 2023

Overview of Content Published in December

Filed under: Announcement — Didier Stevens @ 9:44
Here is an overview of content I published in December:

Blog posts: SANS ISC Diary entries:
« Previous PageNext Page »

Blog at WordPress.com.