Malwrologist (@dissectmalware) 's Twitter Profile
Malwrologist

@dissectmalware

Senior Security Engineer @Amazon. Ex Assistant Professor. Opinions are mine; not my employer's. DM is open.
Author of xlmdeobfuscator and yaradbg.dev

ID: 967487209535361025

linkhttps://github.com/DissectMalware/XLMMacroDeobfuscator calendar_today24-02-2018 19:51:40

2,2K Tweet

15,15K Followers

160 Following

Malwrologist (@dissectmalware) 's Twitter Profile Photo

One of my former colleagues/friends and his wife are killed by a stalker. Milad was a gifted software engineer and also a super nice person. Such a huge loss Life is too short... cbsnews.com/amp/news/podca…

Malwrologist (@dissectmalware) 's Twitter Profile Photo

#yaradbg v0.0.3 is out 1⃣ New yara editor: syntax highlighting, showing evaluation res inline, autocomplete, ... 2⃣ You can upload pass-protected zip containing malware directly (pass must be" infected") Not sure who uses it but ping if you do, enjoy :) yaradbg.dev

#yaradbg v0.0.3 is out

1⃣ New yara editor: syntax highlighting, showing evaluation res inline, autocomplete, ...
2⃣ You can upload pass-protected zip containing malware directly (pass must be" infected")

Not sure who uses it but ping if you do, enjoy :)

yaradbg.dev
Malwrologist (@dissectmalware) 's Twitter Profile Photo

The #yaradbg editor offers advanced features such as autocomplete (keywords, rulenames, strings) and reference display (shift + F12), which can greatly enhance the coding experience for analysts. Here is a short demo yaradbg.dev

Malwrologist (@dissectmalware) 's Twitter Profile Photo

Fixed a few bugs in interpreting rules in #yaradbg over the weekend. Added support for "in" keyword: $str in (0..100) $str in (filesize-100..filesize)

Malwrologist (@dissectmalware) 's Twitter Profile Photo

.VirusTotal added a new #yara editor with syntax highlighting, autocomplete, rule templates, ... :) blog.virustotal.com/2023/07/action…… #YaraDbg is not done, will definitely continue to extend it more yaradbg.dev

Malwrologist (@dissectmalware) 's Twitter Profile Photo

Thrilled to announce my move to @Amazon as a senior security engineer! Leaving the amazing team at Microsoft was a tough call—they're truly incredible people. However, I'm buzzing with excitement for this new chapter and the opportunities it holds.

Malwrologist (@dissectmalware) 's Twitter Profile Photo

Remember maldocs with XOR encryption back in 2020? I crafted a decryptor and integrated it with my msoffcrypto-tool fork 3 years back! Guess what? it is now merged with github.com/nolze/msoffcry… main branch! Tnx nolze : ) Context: x.com/JohnLaTwC/stat… by John Lambert

Malwrologist (@dissectmalware) 's Twitter Profile Photo

Loved the idea! So, I've donated the entire amount collected since activating the feature to St. Jude Children's Research Hospital, although it wasn't that much. Thank you all who donated : ) stjude.org/donate/donate-…

Malwrologist (@dissectmalware) 's Twitter Profile Photo

Lesser known feature of #YaraDbg: you can drag/drop a pass-protected zip file to analyze the file inside. The pass must be "infected" The decompressed file will be in the memory not on the local filesystem github.com/DissectMalware… live: yaradbg.dev #100DaysOfYara