mandiant / flare-ida

IDA Pro utilities from FLARE team
Apache License 2.0
2.24k stars 465 forks source link

sc_hashes.db: add process name database + filename database #96

Open rakovskij-stanislav opened 4 years ago

rakovskij-stanislav commented 4 years ago

Sometimes malware uses for example ror-13 to check process and file names. I suggest to eiter include popular process/file names to existing database with decoy library names "processes" "filesystem" or make a new database located at the same folder.