Skip to content
Malwagon
Sign up

Latest posts

5 posts, newest first.
Title Description Date
Extracting Cobalt Strike beacon configs at scale How the static engine recovers XOR-obfuscated beacon TLV records locally, and what the extracted C2 profile tells you. Research
Release: OneShot Run across the full OS matrix Detonate a sample across every sandbox image back to back and capture screenshots, with a single interactive VM screen. Release
Hunting vulnerable drivers with the LOLDrivers feed Pairing the LOLDrivers corpus with static signing checks to flag BYOVD attempts before detonation. Threat intel
Guide: isolating guests while keeping hypervisor-level capture Locking guest-to-host and guest-to-LAN traffic without losing the HTTP/S and connection telemetry the platform records. Guide
Detecting VBA stomping and DDE in weaponized documents Deep maldoc analysis: reconciling compiled p-code against source VBA to catch stomped macros, plus RTF/OneNote object tricks. Research

See also

The documentation describes how a scan runs from submission to report, the glossary defines the terms these posts and the reports use, public scans lists the analyses submitters chose to share, and the platform overview covers the analysis modules the write-ups refer to.

Sign in

Sign in

The analyst console and your scan history. Private scans and the API come with a paid plan.

or
Continue with Google

New team? Create a free account

Sign up

Create your account

Free tier: 20 scans a month, three sandbox images, reports public. No card required.

12 characters minimum

or
Continue with Google

By creating an account you accept the terms and privacy policy.

Already provisioned? Sign in