marc ochsenmeier · @ochsenmeier
190 followers · 32 posts · Server infosec.exchange

analyses an Executable and provides an overview of the @mitreattack techniques detected. Medusa

#pestudio #malware #ransomware

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
188 followers · 31 posts · Server infosec.exchange

When handling .NET Executable file, enumerates references to managed & unmanaged libraries.

#pestudio #malware #dfir #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
183 followers · 30 posts · Server infosec.exchange

Update of in a few days, to ease Initial Assessment.

#pestudio #malware #ransomware #infosecurity

Last updated 2 years ago

MAL: Malware Introductory - I have just completed this room! Check it out: tryhackme.com/room/malmalintro # beginner # introductory freeware analysis via @RealTryHackMe

#tryhackme #peid #ida #windows #pestudio #malware #malmalintroductory

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
183 followers · 29 posts · Server infosec.exchange

Update of soon, to add Libraries groups in order to accelerate Initial Assessment.

#pestudio #malware #ransomware #infosec #dfir

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
183 followers · 29 posts · Server infosec.exchange

Next update of to fix an issue with the query of @virustotal scores

#pestudio #malware #ransomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
183 followers · 29 posts · Server infosec.exchange

Starting today, purchase professional to a discount price winitor.com/download

#pestudio #malware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
180 followers · 25 posts · Server infosec.exchange

A deeper look at large strings can often lead to interesting indicators | RedLine

#pestudio #stealer #malware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
177 followers · 23 posts · Server infosec.exchange

Thank you very much for your trust in 2022. You can count on more updates of in 2023, to ease Initial Assessment.

#pestudio #malware #ransomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
172 followers · 22 posts · Server infosec.exchange

detects some well-known .NET Executable Obfuscators | Medusa

#pestudio #rasomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
172 followers · 22 posts · Server infosec.exchange

When analyzing a .NET Executable, shows an overview of referenced Namespaces in order to accelerate Initial Assessment

#pestudio #malware #rat #ransomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
164 followers · 20 posts · Server infosec.exchange

Next with more features to accelerate Initial Assessment

#pestudio #malware #ransomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
151 followers · 18 posts · Server infosec.exchange

enumerates imports and namespaces of .NET Executable in order to accelerate Initial Assessment

#pestudio #malware #dfir #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
135 followers · 16 posts · Server infosec.exchange

Next update of to add a "group" of libraries to accelerate Initial Assessment

#pestudio #malware #warzone #rat #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
129 followers · 13 posts · Server infosec.exchange

Next www.winitor.com with more indicators to accelerate

#pestudio #malwareanalysis

Last updated 2 years ago

CPU ⬜ Carré Petit Utile · @cpu
475 followers · 6607 posts · Server mastodon.tetaneutral.net

RT @ochsenmeier@twitter.com

shows @MITREattack@twitter.com indicators to accelerate Initial Assessment

🐦🔗: twitter.com/ochsenmeier/status

#infosec #ransomware #malware #pestudio

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
129 followers · 12 posts · Server infosec.exchange

shows @mitreattack indicators to accelerate Initial Assessment

#pestudio #malware #ransomware #infosec

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
129 followers · 12 posts · Server infosec.exchange

Next to indicate .NET Executable files using unmanaged libraries/functions (aka. P/Invoke)

#pestudio #malware #infosec #dfir

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
129 followers · 12 posts · Server infosec.exchange

detects .NET Executable files referencing unmanaged functions (aka. P/Invoke)

#pestudio #malware #doublezero #wiper #dfir

Last updated 2 years ago

marc ochsenmeier · @ochsenmeier
129 followers · 12 posts · Server infosec.exchange

detects MS-Compress streams hidden in the Resources of Executable

#pestudio #wiper #malware #dfir #infosec

Last updated 2 years ago