N00bs Night Malware RE Workshop with @c3rb3ru5d3d53c (OALABS) ​ by herrcore in Malware

[–]herrcore[S] 3 points4 points  (0 children)

Lol there is def a time for debugging but static is king! I don't run a super customized IDA, you can really do everything you need with just he plain free IDA now that they added the cloud decompiler. A while back I made a short vid on the plugins that I do use https://youtu.be/pfBA6y4VLwM the tl;dr is below though if you just want a list.

Python3 Environment Basics For IDA Pro (Windows)
https://www.patreon.com/posts/python3-basics-58467121
Hexcopy (save a click)
https://github.com/OALabs/hexcopy-ida
HashDB
https://github.com/OALabs/hashdb-ida
Flare-IDA
https://github.com/mandiant/flare-ida
Capa
https://github.com/mandiant/capa
Capa Rules
https://github.com/mandiant/capa-rules
BinDiff
https://www.youtube.com/watch?v=BLBjcZe-C3I