CTF-All-In-One/doc/9.2_wintools.md
2018-08-05 17:43:10 +08:00

55 lines
1.2 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 9.2 更多 Windows 工具
- [010 Editor](#010-editor)
- [DIE](#die)
- [PEiD](#peid)
- [PE Studio](pe-studio)
- [PEview](#peview)
- [PortEx Analyzer](#portex-analyzer)
- [Resource Hacker](#resource-hacker)
- [wxHexEditor](#wxhexeditor)
- [PDF Stream Dumper](#pdf-stream-dumper)
- [EMET](#emet)
## 010 Editor
<https://www.sweetscape.com/010editor/>
## DIE
<http://ntinfo.biz/>
## PEiD
<http://www.softpedia.com/get/Programming/Packers-Crypters-Protectors/PEiD-updated.shtml>
PEiD 是一个用于检测常用壳加密压缩的小程序。恶意软件编写者通常会进行加壳和混淆让恶意软件不容易被检测和分析。PEiD 可以检查超过 600 种不同的 PE 文件签名,这些数据存放在 `userdb.txt` 文件中。
## PE Studio
<https://www.winitor.com/>
## PEview
<http://wjradburn.com/software/>
## PortEx Analyzer
<https://github.com/katjahahn/PortEx>
## Resource Hacker
<http://www.angusj.com/resourcehacker/>
## wxHexEditor
<http://www.wxhexeditor.org/>
## PDF Stream Dumper
<http://sandsprite.com/blogs/index.php?uid=7&pid=57>
## EMET
<https://support.microsoft.com/en-us/help/2458544/the-enhanced-mitigation-experience-toolkit>