SLIDE 1
A static analyzer for PE executables RMLL 2016 – Security Track
Ivan Kwiatkowski, AMIR Consulting
A static analyzer for PE executables RMLL 2016 Security Track Ivan - - PowerPoint PPT Presentation
A static analyzer for PE executables RMLL 2016 Security Track Ivan Kwiatkowski, AMIR Consulting Project origins Started in Feb. 2014 Annoyance at AV softwares opaque decisions Needed to automate repetitive tasks Overview: A
Ivan Kwiatkowski, AMIR Consulting
Input Files PE Parser Plugin A Plugin B Plugin C Data Data Data Report
YARA Engine
(3.4.0)
Output Formatter
(text, json)
File hashes
(incl. imphash)