Author Archives: Daniel Pistelli

Torrent Support

Following our recent introduction to Scan Providers, here’s a first implementation example. In this post we’ll see how to add support for Torrent files in Profiler. Of course, the implementation shown in this post will be available in the upcoming … Continue reading

Posted in Forensics, Profiler | Tagged , , | Comments Off on Torrent Support

Scan Providers

Version 2.5.0 is close to being released and comes with the last type of extension exposed to Python: scan providers. Scan providers extensions are not only the most complex type of extensions, but also the most powerful ones as they … Continue reading

Posted in Profiler, Python, SDK | Comments Off on Scan Providers

Profiler 2.4

Profiler 2.4 is out with the following news: – added initial support for PDB files (including export of types) – added support for Windows Encoded Scripts (VBE, JSE) – introduced fixed xml structures – added automatic string decoding in struct … Continue reading

Posted in Profiler | Tagged , | Comments Off on Profiler 2.4

PDB support (including export of types)

The main feature of the upcoming 2.4 version of Profiler is the initial support for the PDB format. Our code doesn’t rely on the Microsoft DIA SDK and thus works also on OS X and Linux. Since the PDB format … Continue reading

Posted in PDB, Profiler, Python | Tagged , , , | Comments Off on PDB support (including export of types)

Profiler 2.3

Profiler 2.3 is out with the following news: – introduced YARA 3.2 support – added groups for logic providers – added Python action to encode/decode text – added Python action to strip XML down to text – added the possibility … Continue reading

Posted in Profiler | Tagged | Comments Off on Profiler 2.3

YARA 3.2.0 support

The upcoming 2.3 version of Profiler includes support for the latest YARA engine. This new release is scheduled for the first week of January and it will include YARA on all supported platforms. One inherent technical advantage of having YARA … Continue reading

Posted in Action, Hooks, Profiler, Python, SDK | Tagged , | Comments Off on YARA 3.2.0 support

Profiler 2.2 (Linux support)

The new version of Profiler is out and it includes support for Linux x64! Some time ago we did a poll to ask our users if they preferred an x86 or x64 edition for Linux. The participants voted unanimously for … Continue reading

Posted in Profiler | Tagged , | Comments Off on Profiler 2.2 (Linux support)

Stripping symbols from an ELF

Just as the previous post about stripping symbols from a Mach-O binary, here’s one about stripping them from an ELF binary. The syntax to execute the script is the same as in the previous post, only the called function changes: … Continue reading

Posted in ELF, Profiler, Python, SDK | Tagged , , , | Comments Off on Stripping symbols from an ELF

Stripping symbols from a Mach-O

A common mistake many developers do is to leave names of local symbols inside applications built on OS X. Using the strip utility combined with the compiler visibility flags is, unfortunately, not enough. So I wrote a small script for … Continue reading

Posted in MachO, Profiler, Python, SDK | Tagged , , , | Comments Off on Stripping symbols from a Mach-O

Profiler 2.1 (Mac OS X support)

The new version of Profiler is out and it includes support for Mac OS X! Here’s the change-list for the current version: – ported Cerbero Profiler to MacOSX – added command-line scripting support – updated Header Manager to Clang 3.5 … Continue reading

Posted in Profiler | Tagged , | Comments Off on Profiler 2.1 (Mac OS X support)