-
Top Categories
-
Category Cloud
-
Tag Cloud
-
Latest links
-
Bookmark Me
|
PR: 5
| Rasta Ring0 Debugger http://rr0d.droids-corp.org/ RR0D is a ring 0 debugger. It offers the possibility to debug any kind of code (kernel/user/rasta land). Its philosophy is to be OS independent. That's why RR0D can today be installed on Linux, *BSD, Wind0ws. |
|
PR: 5
| Immunity Debugger http://www.immunitysec.com/products-immdbg.shtml Immunity Debugger is a powerful new way to write exploits, analyze malware, and reverse engineer binary files. It builds on a solid user interface with function graphing, the industry's first heap analysis tool built specifically for heap creation, and a large and well supported Python API for easy extensibility. |
|
PR: 0
| Microsoft Portable Executable and Common Object File Format Specification http://www.microsoft.com/whdc/system/platform/firmware/PECOFF.mspx This document specifies the structure of executable (image) files and object files under the Microsoft Windows family of operating systems. These files are referred to as Portable Executable (PE) and Common Object File Format (COFF) files respectively. |
|
PR: 0
| WiteG's Homepage http://h1.ripway.com/witeg/ Assembler implementations of cryptographic algorithms, crypto tools and also crypto crackmes. |
|
PR: 5
| Alex Ionescu’s Blog http://www.alex-ionescu.com Alex is a kernel developer, reverse engineer, and Microsoft Student Ambassador. This blog shares Alex’s views and news on Technology, OS Development and Reverse Engineering. |
|
PR: 2
| Peering Inside the PE http://msdn2.microsoft.com/en-us/library/ms809762.aspx A Tour of the Win32 Portable Executable File Format by Matt Pietrek. |
|
PR: 4
| Jason Geffner http://malwareanalysis.com/communityserver/blogs/geffner/default.aspx A Reverse Engineer's Blog. |
|
PR: 4
| Syser Debugger http://www.sysersoft.com/ Syser Debugger is designed for Windows NT Family based on X86 platform. It is a core-level debugger with full-graphical interfaces and supports assembly debugging and source code debugging. |
|
PR: 1
| Ring3 Circus http://www.ring3circus.com Diary of a programmer, journal of a hacker. |
|
PR: 5
| OllyDbg http://www.ollydbg.de/ OllyDbg is a 32-bit assembler level analysing debugger for Microsoft® Windows®. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable. OllyDbg is a shareware, but you can download and use it for free. |
|
PR: 4
| Reconstructer http://www.reconstructer.org/ This site primary mirrors my interests on low level stuff like reverse engineering, malware and rootkit research, debugging and troubleshooting applications, as well as software protections and its concepts. |
|
PR: 3
| ReFox http://www.refox.net ReFox is a multi-purpose and easy-to-use utility for viewing and restoring source code from Visual FoxPro 9.0, VFP 8.0, VFP 7.0, VFP 6.0, VFP 5.0, VFP 3.0, FoxPro 2.x, FoxPro 1 and FoxBASE+ compiled modules and executables. The ReFox decompiler is able to decompile standard and encrypted Fox compiled modules for the purpose of source code recovery. |
|
PR: 4
| REC - Reverse Engineering Compiler http://www.backerstreet.com/rec/rec.htm REC is a portable reverse engineering compiler, or decompiler. It reads an executable file, and attempts to produce a C-like representation of the code and data used to build the executable file. |
|
PR: 5
| Uninformed http://www.uninformed.org Uninformed is a technical outlet for research in areas pertaining to security technologies, reverse engineering, and lowlevel programming. The goal, as the name implies, is to act as a medium for informing the uninformed. The research presented here is simply an example of the evolutionary thought that affects all academic and professional disciplines. |
|
PR: 5
| OpenRCE http://www.openrce.org OpenRCE aims to serve as a centralized resource for reverse engineers (currently heavily win32/security/malcode biased) by hosting files, blogs, forums articles and more. |
|
PR: 5
| Nynaeve http://www.nynaeve.net Adventures in Windows debugging and reverse engineering. |
|
PR: 5
| WinDbg http://www.microsoft.com/whdc/devtools/debugging/default.mspx You can use Debugging Tools for Windows to debug drivers, applications, and services on systems running Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 as well as for debugging the operating system itself. Versions of the Debugging Tools for Windows package are available for 32-bit x86, native Intel Itanium, and native x64 platforms. |
|
PR: 5
| Executable and Linkable Format (ELF) http://www.skyfree.org/linux/references/ELF_Format.pdf The Executable and Linking Format was originally developed and published by UNIX System Laboratories (USL) as part of the Application Binary Interface (ABI). The Tool Interface Standards committee (TIS) has selected the evolving ELF standard as a portable object file format that works on 32-bit Intel Architecture environments for a variety of operating systems. |
|
PR: 2
| Zeta Debugger http://www.fyzor.com/debugger/index.htm At this moment the debugger supports a several number of debugging formats used by compilers of two most known companies - Borland and Microsoft. |
|
PR: 6
| Joanna Rutkowska http://theinvisiblethings.blogspot.com/ The official blog of Joanna Rutkowska, new rootkit technologies. |
|
PR: 5
| Dancho Danchev's Blog http://ddanchev.blogspot.com/ In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude. |
|
PR: 3
| Linice http://www.linice.com/ Linice is an Intel x86-based, Linux source-level kernel debugger with the look and feel of SoftIce for MS Windows. Linice is designed to be used by the people who have SoftIce experience. Linice provides a major subset of SoftIce commands, and adds a few new ones. |
|
PR: 7
| Microsoft Anti-Malware Engineering Team http://blogs.technet.com/antimalware/default.aspx This blog provides information about what's happening in the anti-malware technology team at Microsoft. We're the team that builds the core antivirus, antispyware, anti-rootkit, and related technology, which is then used across a number of Microsoft products and technologies. |
|
PR: 7
| Breaking Eggs And Making Omelettes http://multimedia.cx/eggs/ Mike Melanson's blog on multimedia technology and reverse engineering. |
|
PR: 5
| ESET Threat Blog http://www.eset.com/threat-center/blog/ ESET's blog about new threats in malware world. |
|
PR: 6
| TrendLabs Malware Blog http://blog.trendmicro.com/ http://blog.trendmicro.com/ |
|
PR: 5
| Hex blog http://www.hexblog.com About IDA Pro, decompilation, programming, binary program anylasis, information security. |
|
PR: 6
| DVLabs Blog http://dvlabs.tippingpoint.com/blog/ DVLabs blog. |
|
PR: 7
| Kaspersky Analyst's Diary http://www.viruslist.com/en/weblog The Analyst's Diary is a weblog maintained by virus analysts from Kaspersky Lab headed by Eugene Kaspersky. Find out more about the authors of this weblog. |
|
PR: 5
| Offensive Computing http://www.offensivecomputing.net/ Offensive Computing, LLC was formed by Valsmith and Danny Quist as a resource for the computer security community. The primary emphasis here is on malware collections and analysis for the purpose of improving people's abilities to defend their networks. |
|
PR: 7
| F-Secure Weblog http://www.f-secure.com/weblog/ Most Recent News from the F-Secure Lab. |
|
PR: 5
| Boomerang http://boomerang.sourceforge.net/ This project is an attempt to develop a real decompiler for machine code programs through the open source community. A decompiler takes as input an executable file, and attempts to create a high level, compilable, possibly even maintainable source file that does the same thing. |
|
PR: 4
| diStorm64 http://www.ragestorm.net/distorm/ diStorm is a binary stream disassembler. It's capable of disassembling 80x86 instructions in 64 bits (AMD64, x86-64) and both in 16 and 32 bits. In addition, it disassembles FPU, MMX, SSE, SSE2, SSE3 and 3DNow! (w/ extensions) and new x86-64 instruction sets. |
|
PR: 4
| Anti Rootkit Blog http://www.antirootkit.com/blog/ Antirootkit Software, News, Articles and Forums. |
|
PR: 3
| My infected computer http://zairon.wordpress.com/ Various information about malware analysis and reverse engineering. |
|
PR: 5
| Peter Ferrie http://pferrie.tripod.com/ Virtual machines detection, articles with malware analysis for Virus Bulletin. |
|
PR: 0
| TatraDAS http://tatradas.sourceforge.net TatraDAS is disassembler of x86 executables which supports PE, NE, MZ, COM, ELF and binary file formats. It includes disassembler, text viewer with syntax highlighting. |
|
PR: 3
| VB Decompiler http://www.vb-decompiler.org/ VB Decompiler is decompiler for programs (EXE, DLL or OCX) written in Visual Basic 5.0/6.0. As you know, programs in Visual Basic can be compiled into interpreted p-code or into native code. |
|
PR: 7
| McAfee Avert Labs Blog http://www.avertlabs.com/research/blog/ McAfee's antivirus labs blog. |
|
PR: 5
| ThreatFire Research Blog http://blog.threatfire.com Blog from the threat research team at ThreatFire. |
|
PR: 6
| Symantec Security Response Weblog http://www.symantec.com/enterprise/security_response/weblog/ The Symantec Security Response Weblog has been created to provide a forum for the team to share ideas and commentary on emerging issues and trends. |
|
PR: 6
| Sunbelt Blog http://sunbeltblog.blogspot.com A blog about activities, products and ideas at Sunbelt Software, one of the leading developers of security software to protect against spyware, spam and other threats. |
|
PR: 0
| KPNC reversing lab http://nezumi-lab.org/blog/ Reverse engineering articles, anti-debugging tricks, many unpublished tips&tricks. |
|
PR: 6
| IDA Pro http://www.hex-rays.com/idapro/ IDA Pro is a Windows or Linux hosted multi-processor disassembler and debugger that offers so many features it is hard to describe them all. |
|
PR: 3
| VB RezQ http://www.vbrezq.com VB RezQ can recover source from all types of 32-bit Visual Basic executables i.e .exe, .ocx and .dll files created by VB4(32), VB5 and VB6. |
|
PR: 4
| MASM32 http://www.masm32.com MASM32 version 9 is a working development for programmers who are interested in either learning or writing 32 bit Microsoft assembler (MASM). |
|
PR: 0
| AniProtect http://www.antiprotect.com All AntiRootkit,Rootkit,Virus And AntiVirus. |
|
PR: 4
| Resource Builder http://www.resource-builder.com/ Resource Builder is the complete solution for Windows resource editing. |
|
N/A
| corkami http://corkami.blogspot.com/ Packers and protectors, antidebugging tricks, assembler. |
|
PR: 4
| ReversingLabs http://blog.reversinglabs.com ReversingLabs has been founded with the goal to provide the best file analysis tools and the best software protection tools. Our expertise in building superior software reversing tools, gives ReversingLabs a unique background for creating superior software protection tools. Reverse Engineering is an Art where the most complex protection schemas are the least publicly available. Our tools enable the security industry, governments and research institutions to rapidly and effectively reduce the spread of malware. |
|
PR: 2
| bannedit's reverse engineering blog http://binaryfun.blogspot.com/ I am a professional security researcher who enjoys working with vulnerabilities. I am fascinated by what causes vulnerable code and the methods used to exploit these flaws. |
|
PR: 5
| Hex-Rays http://www.hex-rays.com Hex-Rays is a decompiler that transforms binary applications into a high level C-like pseudo code. Unlike disassemblers, which perform the same task at a lower level, the decompiler output is concise and closer to the way most programmers write applications. This alone can save hours of work because analysts easily map the disassembly output to high-level concepts. |
|
PR: 4
| eXeScope http://hp.vector.co.jp/authors/VA003525/emysoft.htm eXeScope can analyze, display various information, and rewrite resources of executable files, that is, EXE, DLL, OCX, etc. without source files. |
|
PR: 4
| ThreatExpert Blog http://blog.threatexpert.com/ ThreatExpert is an advanced automated threat analysis system designed to analyze and report the behavior of computer viruses, worms, trojans, adware, spyware, and other security-related risks in a fully automated mode. |
|
PR: 3
| DFM Editor http://www.mitec.cz/dfm.html DFM Editor allows edit and create Borland Delphi VCL Forms in text and binary format. It is compatible with all Borland Delphi versions (including BDS). DFM Editor can extracts forms from compiled executables and DLLs (or others Portable Executable files) by its extraction tool. Syntax highlihting editor, object inspector and object tree view are tools that make work easier. |
|
PR: 3
| PEBrowse Professional Interactive http://www.smidgeonsoft.prohosting.com/pebrowse-pro-interactive-debugger.html PEBrowse Professional Interactive builds upon the framework presented by PEBrowse Professional to create a very powerful, versatile, and customizable Win32 user mode debugger/disassembler. PEBrowse Interactive is not a source code debugger, but operates at the Intel x86 instruction level and therefore at the lowest level where your program executes. The debugger fully supports Microsoft .NET managed processes and seamlessly allows interop or mixed-mode debugging. |
|
PR: 5
| Restorator http://www.bome.com/Restorator/ Restorator is an utility to edit windows resources in applications and their components, e.g. files with .exe, .dll, .res, .rc, .dcr, extension (see PE files and RES files). |
|
PR: 2
| File Info http://www.softpedia.com/get/Programming/Other-Programming-Files/File-Info-v.shtml File scanner/analyzer. |
|
PR: 4
| Indefinite Studies http://indefinitestudies.org Daniel Reynaud is currently a PhD student in France, in the computer security team of the Loria lab in the mostly harmless city of Nancy. His research focuses on computer viruses and more generally the reverse engineering of malware. |
|
PR: 5
| FASM http://flatassembler.net FASM is an open source assembly language compiler for x86 and x86-64 processors (this includes the AMD64 and Intel EM64T architectures). |
|
PR: 6
| Reverse Mode http://www.reversemode.com/ Ruben Santamarta is an european security researcher. |
|
PR: 0
| Didier Stevens http://blog.didierstevens.com/ |
|
PR: 5
| PE Explorer http://www.heaventools.com/overview.htm Designed for inspection and editing of Windows executable files, PE Explorer offers powerful static analysis and editing tools for working with EXE, DLL, ActiveX controls, and other executable file formats that run on MS Windows 32-bit platforms. |
|
PR: 3
| Rohitab API Monitor http://www.rohitab.com/apimonitor/ API Monitor is a software that monitors and displays API calls made by applications. Its a powerful tool for seeing how Windows and other applications work or tracking down problems that you have in your own applications. The current version include Filters to monitor the following API Categories. |
|
PR: 3
| KaKeeware Application Monitor http://www.kakeeware.com KaKeeware Application Monitor is a very small API monitor that allows the user to monitor the APIs called by the given application. KAM supports 5577 different APIs as for now. KAM works as an API spy that may help the developers and localization engineers to find the bugs in the release versions of the software. It can be also used by malware analysts to check which APIs are used by the sample they analyse. |
|
PR: 4
| TracePlus http://www.sstinc.com A wide range of tools to monitor system and network activity. |
|
PR: 6
| .NET Resourcer http://www.aisto.com/roeder/dotnet/ Resourcer is an editor for .resources binaries and .resX XML file formats used with the .NET platform. Resourcer allows editing of name/string pairs, import of bitmaps/icons and and merging of resources from different sources. |
|
PR: 5
| Resource Hacker http://www.angusj.com/resourcehacker/ Resource Hacker is a freeware utility to view, modify, rename, add, delete and extract resources in 32bit Windows executables and resource files (*.res). It incorporates an internal resource script compiler and decompiler and works on Win95, Win98, WinME, WinNT, Win2000 and WinXP operating systems. |
|
PR: 5
| VBReFormer http://www.decompiler-vb.net/ VBReFormer is a solution for recovering the design of each form and control, with all properties, values, all reference to external controls (ActiveX™ libraries), and all pictures. Then with VBReFormer you can obtain the necessary information to re-write the graphical design of your application without executable Visual Basic code... |
|
PR: 5
| Sandboxie http://www.sandboxie.com/ Sandboxie runs your applications in an isolated abstraction area called a sandbox. Under the supervision of Sandboxie, an application operates normally and at full speed, but can't effect permanent changes to your computer. Instead, the changes are effected only in the sandbox. |
|
PR: 4
| j00ru//vx tech blog http://j00ru.vexillium.org/ As far as I recall, subjects related to programming (C, C++, x86 assembler, Python and so on), reverse engineering, malware analysis (just like the one before), Bughunting (again!), NT OS internals research etc. are the things I spend most of my life on. When it comes to real life things, I prefer reading horror books (Kings rulz), taking |
|
PR: 0
| Microsoft Malware Protection Center http://blogs.technet.com/mmpc/ Threat Research & Response Blog |
|
N/A
| gynvael.coldwind//vx.log http://gynvael.coldwind.pl/?lang=en Reverse engineering, exploits, programming, game development and many more. |
|
PR: 2
| Piotr Bania Chronicles http://blog.piotrbania.com/ Computer security, reverse engineering, antivirus development, game programming, gsm telephony, martial arts, life and everything. |
|
PR: 6
| NASM http://nasm.sourceforge.net The Netwide Assembler, NASM, is an 80x86 and x86-64 assembler designed for portability and modularity. It supports a range of object file formats, including Linux and *BSD a.out, ELF, COFF, Mach-O, Microsoft 16-bit OBJ, Win32 and Win64. It will also output plain binary files. It supports from the upto and including Pentium, P6, MMX, 3DNow!, SSE, SSE2, SSE3 and x64 opcodes. |
|
PR: 3
| Protection ID http://pid.gamecopyworld.com/ Application which can detect most protection systems. Mainly detects CD/DVD protection systems like SecuRom, StarForce, SafeDisc, Tages. Also it can detect many different protectors, packers for PE file format |
|
PR: 5
| WinAsm Studio http://www.winasm.net WinAsm Studio is a free Integrated Development Environment IDE for developing 32-bit Windows and 16-bit DOS programs using the Assembler. The Microsoft Macro Assembler (MASM) is supported inherently, while the FASM Add-In adds support for FASM and other assemblers. |
|
PR: 0
| Anolis Resourcer http://anolis.codeplex.com Resourcer is a powerful and flexible resource editor for Microsoft Windows that features full x64 and Vista/Win7 support, in addition to PNG icons and is also free and open-source (GPL). |
|
N/A
| Valkyrie http://www.grafxsoft.com/2valkyrie.htm A Decompiler for Clipper S87 & CA-Clipper 5. Supports CA-Clipper 5.0 through 5.2 |
|
PR: 4
| HT Editor http://hte.sourceforge.net HT is a file editor / viewer / analyzer for executables. The goal is to combine the low-level functionality of a debugger and the usability of IDEs. |
|
PR: 5
| Microsoft Detours http://research.microsoft.com/sn/detours/ Detours is a library for instrumenting arbitrary Win32 functions on x86, x64, and IA64 machines. Detours intercepts Win32 functions by re-writing the in-memory code for target functions. The Detours package also contains utilities to attach arbitrary DLLs and data segments (called payloads) to any Win32 binary. |
|
PR: 1
| MiscellaneouZ http://0x5a4d.blogspot.com/ Code, hacks, security, RE, misc... |
|
PR: 0
| Fast Horizon http://fasthorizon.blogspot.com/ Greg Hoglund's blog about rootkit technologies, information security and reverse engineering. |
|
N/A
| fist of god http://maximumcrack.wordpress.com/ This is my humble attempt at sharing questions, ideas, interesting topics and filthy pictures I stumble upon while doing what I do best (and most) – all sorts of geek stuff. I like programming, reverse engineering and playing games (no particular order). |
|
PR: 0
| Visual DuxDebugger http://www.duxcore.com/ Visual DuxDebugger is a debugger disassembler for Windows 64 bits, it is the first version so it is still very simple, but it has some features that others debuggers doesn’t have, it debugs multiple processes and debugs multiple child processes, but may be the most interesting feature is the “Detour System”. The current disadvantage is that only debugs 64 bits software, but it is a long term project and surely in a close future 64 bits software will be more common. |
|
PR: 1
| RDG Packer Detector http://www.rdgsoft.8k.com/ RDG Packer Detector is a file detector for exe packers, cryptors, scrabmlers, linkers, file joiners and installers. |
|
PR: 4
| PEiD http://peid.has.it/ PEiD detects most common packers, cryptors and compilers for PE files. It can currently detect more than 600 different signatures in PE files. |
|
PR: 4
| HxD - Freeware Hex Editor and Disk Editor http://mh-nexus.de HxD is a carefully designed and fast hex editor including raw disk editing, modifying foreign RAM and handling files of any size. |
|
PR: 5
| JWasm http://www.japheth.de/JWasm.html JWasm is a MASM v6 compatible assembler. It's a fork of Open Watcom's WASM and released under the Sybase Open Watcom Public License, which allows free commercial and non-commercial use. JWasm is written in C, source code is open. |
|
PR: 1
| The Customiser http://www.wanga.com/cu.php The Customiser allows you to set the position and size of any window, button or other control and set the text of these controls. These changes can be permanently saved for any application and readily undone when desired. You can also set The Customiser to automatically press those annoying extra buttons you have to press when you go through a certain procedure, like OK buttons that you always press and wish you could automate. |
|
PR: 4
| Resource Tuner http://www.heaventools.com/resource-tuner-scrshots.htm Resource Tuner is a PE Explorer spin-off product that is used solely to edit resources in Windows programs. It has a broader audience than just software developers: translators, tweakers and those wanting a different look and feel. Resource Tuner is an important productivity tool for those who are engaged in editing of resources in Windows executables. |
|
PR: 0
| Hackman Suite http://www.technologismiki.com/prod.php?id=31 Hackman Suite is a multi-module all purpose debugging tool. It includes a hex editor, a disassembler, a template editor, a hex calculator and other everyday useful tools to assist programmers and code testers with the most common tasks. |
|
PR: 5
| Yasm http://www.tortall.net/projects/yasm/ Yasm currently supports the x86 and AMD64 instruction sets, accepts NASM and GAS assembler syntaxes, outputs binary, ELF32, ELF64, 32 and 64-bit Mach-O, RDOFF2, COFF, Win32, and Win64 object formats, and generates source debugging information in STABS, DWARF 2, and CodeView 8 formats. |
|
PR: 5
| FrameworkPascal and TMT Pascal http://www.frameworkpascal.com The TMT Pascal compiler is a fast compiler for the Pascal language. The compiler emits 32-bit code and supports many language extensions from Borland Pascal (BP), as well as more powerful new extensions. |
|
PR: 6
| C++ Tutorials & Reference http://www.cplusplus.com/doc/tutorial/ C++ Reference, Tutorials, Examples. |
|
PR: 4
| KOrUPt http://korupt.co.uk/ Generally we prefer to focus on Binary Analysis and Reverse Engineering, however I'm sure there's something everyone can enjoy! |
|
PR: 4
| RCE Cafe http://rcecafe.net/ Reverse engineering blog by HexRay's employee - Daniel Pistelli, .net reversing, CFF Explorer notes and more. |
|
PR: 3
| SysEye http://sourceforge.net/projects/jkd-syseye/ Utility to control all objects that you see in Windows screen (text, combo boxes, buttons, pictures...). You will be able to enable disabled objects, to hide buttons, to modify menus... Useful utility for programmers who need object's handle. |
|
PR: 6
| .NET Reflector http://www.reflector.net/ Reflector is the class browser, explorer, analyzer and documentation viewer for .NET. Reflector allows to easily view, navigate, search, decompile and analyze .NET assemblies in C#, Visual Basic and IL. |
|
PR: 4
| Hook Explorer http://labs.idefense.com/files/labs/releases/previews/HookExplorer/ This is a small application designed to scan a process looking for IAT or detours style hooks. |