Giter VIP home page Giter VIP logo

ma-notebook's Introduction

ma-resources

Youtube channels:

Books:

RSS feeds:

Sites/blogs:

Datasets:

Emulation:

Cheat-sheets:

Anti RE:

Xor:

RE CTFs:

Training:

Free Training:

Mobile:

ELK:

Others:

Reports/ Research Papers:

Firmware:

Others:

Awesome list:

Programming Language Specifications/helpers:

Topic Subject Resource
Assembler - General PC Assembly Language Paul A. Carter
The Art of Assembly Language
Intel Assembler 80186 and higher
Windows Assembly Language & Systems Programming
Javascript - Specification ECMAScript® 2020 Language Specification

Assembly Knowledge Resources:

Topic Subject Resource
Introduction - How a processor works
- Introduction to Assembly
- Arquitecture
- Convertion (Binary, Decimal, Hexadecimal)
- Characters
01 - Introduction to Assembly
Registers - Registers
- Flags
- Virtual Memory
- Paging
- Interrupts
02 - Registers and Components of the CPU
Skull security - Registers
Mnemonics - Assembly Mnemonics
- Operands
- Instructions
- Deirectives, define, data directives and Identifiers
- Exercises
04 - Assembly Mnemonics
Paul A Carter - PC Assembly Language
Paul A Carter Github
Registers Sizes - Positive number
- Negative number
- Zero Extend
- Sign Extend
08 - Sign Extension
Control Structure - Compare
- Branching
10 - Conditionals

File Formats:

Topic Subject Resource
Portable Executable - PE Portable Executable File Format – A Reverse Engineer View
PE 101
PE101 - Light
Malware Theory - Basic Structure of PE Files
Malware Theory - Memory Mapping of PE Files
Malware Theory - Portable Executable Resources
Malware Theory - PE Malformations and Anomalies
corkami pocs

Exploits:

Topic Subject Resource
Shellcode - Shellcode
- Buffer overflow
Shellcoding - Modern Binary Exploitation CSCI 4968 - Spring 2015 Sophia D’Antoine
Lab: ARM Assembly ShellcodeFrom Zero to ARM Assembly Bind Shellcode
Buffer Overflow Attack - Computerphile
Shellcoding in Linux
From a C project, through assembly, to shellcode
DLL Injection - Reflective DLL Injection Reflective DLL Injection By Stephen Fewer
Race conditions - Exploit race conditions Secure Coding in C and C++ Race Conditions

Threat Hunting:

Open Source Intelligence:

Subject Resource
Network Robtex
CentralOps
Devices Shodan
White/Black lists Spamhaus
URLhaus
General Malpedia
MalwareWorld
ThreatMiner
Sandbox Hybrid Analysis
AlienVault - Open Threat Exchange

Virtual Machines:

Hardening VM:

Tools (Windows Analysis machine):

Name URL
7zip https://www.7-zip.org/download.html
BareTail https://baremetalsoft.com/baretail/
CyberChef https://github.com/gchq/CyberChef/releases
x64dbg https://sourceforge.net/projects/x64dbg/files/latest/download
- Plugin OllyDumpEx: https://low-priority.appspot.com/ollydumpex/#download
- Plugin xAnalyzer x86x64: https://github.com/ThunderCls/xAnalyzer/releases/
- Plugin ScyllaHide: https://github.com/x64dbg/ScyllaHide/releases
de4dot https://github.com/de4dot/de4dot
Detect It Easy (die) https://github.com/horsicq/DIE-engine/releases
DLL_to_EXE https://github.com/hasherezade/dll_to_exe/releases
dnSpy https://github.com/dnSpy/dnSpy/releases
Ghidra (64 Bits) https://github.com/NationalSecurityAgency/ghidra/releases
- BinDiff: https://www.zynamics.com/software.html
- Setup BinDiff with Ghidra: https://github.com/ubfx/BinDiffHelper & https://github.com/google/binexport
- Create Ghidra scripts: https://nuculabs.dev/2019/10/13/ghidra-scripting-annotating-linux-system-calls/
- Community https://gist.github.com/adulau/a3a0eefb7828d52747a9d247a82eeeef
HxD https://mh-nexus.de/en/downloads.php?product=HxD20
hollows_hunter https://github.com/hasherezade/hollows_hunter/releases
Video: https://www.youtube.com/watch?v=rH4XzNwgVoo
https://www.youtube.com/watch?v=-QgMDtVRAzM
IDA Freeware (64 Bits) https://www.hex-rays.com/products/ida/support/download_freeware/
- IDA 7 Freeware Linux fix: https://github.com/WqyJh/qwingraph_qt5
NetworkMiner https://www.netresec.com/?download=NetworkMiner
Notepad++ https://notepad-plus-plus.org/downloads/
PEBear https://github.com/hasherezade/pe-bear-releases/releases
Quassel https://quassel-irc.org/downloads
Resource Hacker http://angusj.com/resourcehacker/#download
UniExtract2 https://github.com/Bioruebe/UniExtract2/releases
WinMerge https://winmerge.org/downloads/?lang=en
AlternateStreamView https://www.nirsoft.net/utils/alternate_data_streams.html
AutoRuns https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns
Burp Suite https://portswigger.net/burp/communitydownload
bytecode-viewer https://github.com/Konloch/bytecode-viewer/releases
capa https://github.com/fireeye/capa/releases
CSVFileView https://www.nirsoft.net/utils/csv_file_view.html
DLL Export Viewer https://www.nirsoft.net/utils/dll_export_viewer.html
DriverView https://www.nirsoft.net/utils/driverview.html
Exeinfo PE http://exeinfo.xn.pl/
Floss https://github.com/fireeye/flare-floss/releases
HashMyFiles https://www.nirsoft.net/utils/hash_my_files.html
iText RUPS https://github.com/itext/i7j-rups/releases
jpexs-decompiler https://github.com/jindrapetrik/jpexs-decompiler/releases
- Flash utilities: https://www.adobe.com/support/flashplayer/debug_downloads.html (Download Flash Player projector content debugger, Flash Player projector and PlayerGlobal.swc)
MegaDumper https://github.com/CodeCracker-Tools/MegaDumper
Netcat (Windows version) https://eternallybored.org/misc/netcat/
pe_to_shellcode https://github.com/hasherezade/pe_to_shellcode/releases
Process Monitor https://docs.microsoft.com/en-us/sysinternals/downloads/procmon
Process Dump http://split-code.com/processdump.html
PortEx https://github.com/katjahahn/PortEx/releases
Process Explorer https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer
- Windows Processes: https://securitybytes.io/blue-team-fundamentals-part-two-windows-processes-759fe15965e2
RawCap https://www.netresec.com/?page=RawCap
RegShot https://sourceforge.net/projects/regshot/files/latest/download
SearchMyFiles https://www.nirsoft.net/utils/search_my_files.html
SSView https://www.mitec.cz/ssv.html
Windows Strings https://docs.microsoft.com/en-us/sysinternals/downloads/strings
Sysmon https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
TaskSchedulerView https://www.nirsoft.net/utils/task_scheduler_view.html
tiny_tracer https://github.com/hasherezade/tiny_tracer/releases
(TAG usage with PEBear @ 7:44) https://www.youtube.com/watch?v=pZW_BAO8EJ8
(Usage) https://www.youtube.com/watch?v=-YVrU4-507A
WMI Code Creator https://www.microsoft.com/en-us/download/details.aspx?id=8572
Yara https://github.com/VirusTotal/yara/releases

Extra Tools (Analysis machine):

Name URL
PAFish https://github.com/a0rtega/pafish/releases
NPCap https://nmap.org/npcap/
Wireshark https://www.wireshark.org/download.html
DevManView https://www.nirsoft.net/utils/device_manager_view.html
VolumeID https://docs.microsoft.com/en-us/sysinternals/downloads/volumeid

Tools (Linux Gateway machine):

Name URL
Avalonia ILSpy https://github.com/icsharpcode/AvaloniaILSpy
Volatility git clone https://github.com/volatilityfoundation/volatility3.git
Volatility 3: https://github.com/volatilityfoundation/volatility3/
Volatility 2: https://www.volatilityfoundation.org/
Volatility docs
Symbols for Windows
Symbols for Mac
Symbols for Linux
Volatility Cheat Sheet
Wireshark Ubuntu PPA: https://launchpad.net/~wireshark-dev/+archive/ubuntu/stable
Wireshark Wiki
MaxMind GeoIP DB setup
Yara sudo apt install yara
Yara Rules
Yara documentation (ReadTheDocs)
Didier Stevens's rules
Neo23x0 YARA Performance Guidelines
[David Bernal Detecting malicious files with YARA rules as they traverse the network](https://i.blackhat.com/USA-19/Wednesday/

Honeypots:

Name URL
Installing T-Pot Honeypot Framework in the Cloud https://www.stratosphereips.org/blog/2020/10/10/installing-t-pot-honeypot-framework-in-the-cloud
https://github.com/telekom-security/tpotce
https://github.com/armedpot/honeytrap/

Unpacking:

Name URL
Unpacking ISFB (including the custom 'PX' format) https://www.youtube.com/watch?v=KvOpNznu_3w
Unpackers

Boilerplate (up for investigation):

ma-notebook's People

Contributors

qwertzy-antonio-godinho avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.