We have released the IFPS Format package for all licenses of Cerbero Suite. IFPS (RemObjects PascalScript) bytecode files are utilized by InnoSetup, a popular script-driven Windows installation system, to enhance the installer’s functionality through custom scripts and can potentially be used by malware to execute malicious code.
Category: Package
File Miner Package
We are thrilled to announce the launch of the File Miner package, a sophisticated file carving tool now available for all Cerbero Suite licenses. Designed to aid malware and forensic analysts in their daily tasks, this package stands out as a top-tier utility in its category, and we plan to enhance it further by supporting additional file formats.
.NET Decompiler Package
We’re excited to release the DotNET Decompiler package for all licenses of Cerbero Suite: this package is capable of decompiling .NET assemblies from their bytecode back to C#.
Once you have installed the package, you can access the decompiler from the bytecode view.
DEX Decompiler Package
We’re excited to release the DEX Decompiler package for all licenses of Cerbero Suite: this package is capable of decompiling Android DEX files from their bytecode back to Java.
Once you have installed the package, you can access the decompiler from the bytecode view.
Java Decompiler Package
We’re excited to release the Java Decompiler package for all licenses of Cerbero Suite: this package is capable of decompiling Java Class files from their bytecode back to Java.
Once you have installed the package, you can access the decompiler from the bytecode view.
The bytecode view and the decompiler are accessible not only within Java Class files but also within JAR files.
YARA Rules Package
We are proud to announce the release of the YARA Rules package for all licenses of Cerbero Suite!
This package is designed to be the ultimate toolkit for downloading, scanning with, creating, editing, and testing YARA rules.
YARA, an essential tool in the fight against malware, allows for the creation of descriptions to match patterns across various file types. Recognizing the importance of YARA in digital forensics and malware analysis, we have developed a comprehensive suite of tools designed to enhance the YARA rule management process.
The YARA Rules package for Cerbero Suite includes an array of features aimed at streamlining the workflow associated with YARA rules. Whether you’re downloading rules from public repositories, scanning files for matches, creating rules tailored to the latest malware threats, editing existing rules to improve accuracy, or rigorously testing rules to ensure effectiveness, this package has everything you need.
Our goal is to provide Cerbero Suite users with a powerful, efficient, and user-friendly set of tools that empowers them to use YARA rules more effectively than ever before. Whether you are a seasoned malware analyst or just starting out in the field of cybersecurity, the YARA Rules package is designed to enhance your analysis capabilities and streamline your workflows.
We invite you in this blog post to explore the full potential of the YARA Rules package and discover how it can enhance your malware analysis and forensic investigations.
DotNET ManifestResources Format Package
We have released the DotNET ManifestResources Format package for all licenses of Cerbero Suite.
.NET manifest resources are embedded elements within .NET assemblies, used to store additional data such as files, icons, and strings that an application requires for execution. These resources are directly compiled into the executable, becoming a part of the application’s core assets. In the realm of malware, attackers frequently exploit .NET manifest resources to hide malicious payloads. Cerbero Suite lets you inspect the format of .NET manifest resources and automatically detects embedded files.
FLIR Format Package
We released the FLIR Format package for all licenses of Cerbero Suite.
FLIR (Forward-Looking InfraRed) refers to thermal imaging data that is embedded within the JPEG file format. Unlike standard visual imagery, FLIR data represents heat emissions from objects, providing a thermal spectrum view that is invaluable for various applications, from surveillance and security to energy audits and search and rescue operations. When FLIR data is embedded in JPEG images, it allows the combination of visible light information with thermal imaging in a single file.
OneNote Format 2.0 Package
We have released version 2 of the OneNote Format package. This latest version introduces numerous enhancements and expands the scope of information extraction capabilities.
In this update, we’ve focused particularly on improving the utility for forensic analysis, ensuring that you can extract more detailed information from OneNote documents.
MediaInfo Package
We’re very happy to announce the release of the MediaInfo package for all licenses of Cerbero Suite!
The MediaInfo package supports a vast array of media file types, providing essential metadata information. This is particularly important for covering file types that do not yet have official support.