I added option –verbose to visualize generated YARA rules.
xorsearch_v0_0_3.zip (http)MD5: 394557EDD88EF9862ACC97D15A2308A3
SHA256: D8FE6914F25FEC4E589A3F3EF7C30F8281C0B918D9254B8AEB2322D2BB8DAE36
I added option –verbose to visualize generated YARA rules.
xorsearch_v0_0_3.zip (http)This is a rewrite of xorsearch.py, an implementation of XORsearch.exe in Python.
xorsearch_v0_0_2.zip (http)This is a bug fix version.
zipdump_v0_0_31.zip (http)This is a bugfix version.
xmldump_V0_0_10.zip (http)This is a bugfix version.
pdf-parser_V0_7_11.zip (http)This is a bugfix version.
pdfid_v0_2_10.zip (http)This is an update with new stats.
1768_v0_0_23.zip (http)This is a bug fix version.
oledump_V0_0_79.zip (http)zoneidentifier.exe, my tool to manage MoTW (ADS Zone.Identifier) data received a small update.
A new option, -show, can be used to display the Zone.Identifier data.
zoneidentifier_V0_0_2.zip (http)This is a bugfix version.
cs-decrypt-metadata_V0_0_5.zip (http)