Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement peframe in r2 #13421

Closed
radare opened this issue Mar 18, 2019 · 5 comments
Closed

Implement peframe in r2 #13421

radare opened this issue Mar 18, 2019 · 5 comments
Labels
FEEDBACK WANTED PE Portable Executable file format handling

Comments

@radare
Copy link
Collaborator

radare commented Mar 18, 2019

Evaluate the list of checks from this tool and determine if we want/can have them in core or if they make more sense to be distributed in a separate script

https://github.com/guelfoweb/peframe

@Maijin
Copy link
Contributor

Maijin commented Mar 18, 2019

We already have those features in r2core or r2-extras (yara). The behavior stuff shouldn't be in core imho. It's way too specialized for malware analysis and is very likely a matter of some yara rules.

@Maijin Maijin added FEEDBACK WANTED PE Portable Executable file format handling labels Mar 18, 2019
@radare
Copy link
Collaborator Author

radare commented Mar 18, 2019 via email

@Maijin
Copy link
Contributor

Maijin commented Mar 18, 2019

All the idea are already on #921 there is nothing new that what is already on our tracker :(

@Maijin
Copy link
Contributor

Maijin commented Mar 18, 2019

Or that we already have.

@Maijin
Copy link
Contributor

Maijin commented Mar 22, 2019

So I took some time today to evaluate and check what are the features of this tool.

After review there is nothing that we don't have already, already supported by Yara/Radare2 or already in the issue tracker.

The part related for the Macro analysis is irrelevant to radare2 or at least irrelevant for radare2 core for now.

I'm closing here

@Maijin Maijin closed this as completed Mar 22, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
FEEDBACK WANTED PE Portable Executable file format handling
Projects
None yet
Development

No branches or pull requests

2 participants