Unpack Sodin, no IDAPython required

Intro I see there is quite some interest around Sodin on OSINT pages, some have problems with unpacking the sample, others reverse and create complex IDAPython scripts to recreate the IAT. In this post, I'll demonstrate a quick and easy way to unpack this malware without losing time with scripting. IDAPython has it's benefits, but … Continue reading Unpack Sodin, no IDAPython required

Windows event logging and Fileless attacks

Intro: Welcome back. I've been asked lately if I know any techniques to investigate fileless attacks using free tools and I shamefully replied with a "No". I wasn't aware of any free and good tools that can accomplish this task of logging PowerShell scripts, WMI commands, process creation , parent processes and command lines. Lately … Continue reading Windows event logging and Fileless attacks