From 309a09663f2975071bfe7095daf1bd22725c3ae5 Mon Sep 17 00:00:00 2001 From: mether049 Date: Wed, 15 Jul 2020 22:38:50 +0900 Subject: [PATCH] Update malware-analysis_ref_and_memo.md --- malware-analysis_ref_and_memo.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/malware-analysis_ref_and_memo.md b/malware-analysis_ref_and_memo.md index ed72836..68dac8c 100644 --- a/malware-analysis_ref_and_memo.md +++ b/malware-analysis_ref_and_memo.md @@ -268,7 +268,9 @@ DFIR,マルウェア解析,OSINTに特化したUbuntuベースのディスト - [010 Editorに組み込むことも可能](https://www.sweetscape.com/010editor/repository/scripts/file_info.php?file=RateStrings.1sc&type=1&sort=) - ref: - [Learning to Rank Strings Output for Speedier Malware Analysis](https://www.fireeye.com/blog/threat-research/2019/05/learning-to-rank-strings-output-for-speedier-malware-analysis.html) -- **exiftool** +- **exiftool** +- **[Detect It Easy](https://github.com/horsicq/Detect-It-Easy)** + - library, linker, packer, compilerなどを判別 - **wql** - wqlで子プロセスの検索 ```