horsicq / Detect-It-Easy

Program for determining types of files for Windows, Linux and MacOS.
http://ntinfo.biz
MIT License
6.9k stars 688 forks source link

Find and check (extract) encoded data (code). #18

Open MariasStory opened 8 years ago

MariasStory commented 8 years ago

Hi,

It would be nice to have a possibility to check for encoded strings, data or code.

Just a quick look gives me: https://github.com/hwhw/base64finder https://digital-forensics.sans.org/blog/2013/05/14/tools-for-examining-xor-obfuscation-for-malware-analysis

This one is really cool: http://www.kahusecurity.com/2014/exploring-xor-decryption-methods/

Just need to look in this direction.

Greetings

horsicq commented 8 years ago

Ok. I'll take a look!