Author Commit Message Labels Comments Date
Daniel Plohmann avatarDaniel Plohmann
removed debug output
Daniel Plohmann avatarDaniel Plohmann
added own yara path for IDAscope and EICAR example rule
Daniel Plohmann avatarDaniel Plohmann
convenience fix: auto sorting YARA result table
Daniel Plohmann avatarDaniel Plohmann
updated documentation
Daniel Plohmann avatarDaniel Plohmann
Merged YaraScanner into master
Daniel Plohmann avatarDaniel Plohmann
release commit, dialog for showing the selected rule's source and minor improvements
Daniel Plohmann avatarDaniel Plohmann
added custom rule loader to display non-matched strings, progress on visualization
Daniel Plohmann avatarDaniel Plohmann
working progress, added YaraScannerWidget and made it functional.
Daniel Plohmann avatarDaniel Plohmann
First attempts of idascope core-part for the yara fun
Daniel Plohmann avatarDaniel Plohmann
Created new branch YaraScanner
Daniel Plohmann avatarDaniel Plohmann
this was also part of that I guess
Daniel Plohmann avatarDaniel Plohmann
Supposedly I enabled better matching of APIs for WinApiWidget. Just can't remember, lol.
Daniel Plohmann avatarDaniel Plohmann
added RC5/RC6 magic to recognized crypto patterns
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #15: Now resolving real API names, by doing import enumeration to obtain addresses/names of imports as recognized by IDA. This increases the coverage for function inspection in case a PDB is loaded
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #19: Added annotation button for crypto signature hits
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #18: seperate icons for the two crypto scan modes.
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #20: Now converting data with function prologue to code and function, helpful for inspecting data assumed to be code.
Daniel Plohmann avatarDaniel Plohmann
Merge branch 'master' of bitbucket.org:daniel_plohmann/simplifire.idascope
Daniel Plohmann avatarDaniel Plohmann
fixed issue #21 (out of bounds error in crypto id
Daniel Plohmann avatarDaniel Plohmann
Merge branch 'master' of bitbucket.org:daniel_plohmann/simplifire.idascope
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #17 by including scanning for dword padded signatures
Daniel Plohmann avatarDaniel Plohmann
cleaning suffixes now reaches all code.
Daniel Plohmann avatarDaniel Plohmann
refactored wrapper renaming a little (new suffix: _w%d). WinApi now also truncating both _%d and _w%d.
Daniel Plohmann avatarDaniel Plohmann
fixed Issue #16 by initializing variable properly.
Daniel Plohmann avatarDaniel Plohmann
WinApi shortcut now truncates trailing suffixes of the form _%d before lookup
Daniel Plohmann avatarDaniel Plohmann
easier variant of posix demo
Daniel Plohmann avatarDaniel Plohmann
added support for runtime chosing of semantic definition files (+ template for POSIX)
Daniel Plohmann avatarDaniel Plohmann
Added filter functionality to Function Inspection
Daniel Plohmann avatarDaniel Plohmann
Preparation of a filter option for FunctionInspection
Daniel Plohmann avatarDaniel Plohmann
changed format of semantics file to directly indicate groups over tags
  1. Prev
  2. Next
Tip: Filter by directory path e.g. /media app.js to search for public/media/app.js.
Tip: Use camelCasing e.g. ProjME to search for ProjectModifiedEvent.java.
Tip: Filter by extension type e.g. /repo .js to search for all .js files in the /repo directory.
Tip: Separate your search with spaces e.g. /ssh pom.xml to search for src/ssh/pom.xml.
Tip: Use ↑ and ↓ arrow keys to navigate and return to view the file.
Tip: You can also navigate files with Ctrl+j (next) and Ctrl+k (previous) and view the file with Ctrl+o.
Tip: You can also navigate files with Alt+j (next) and Alt+k (previous) and view the file with Alt+o.