killchain-compendium/stego/docs/remnux.md

25 lines
683 B
Markdown

# ReMnux
* [Documentation](https://docs.remnux.org/)
## Tools
### Peepdf
* Extracting JS from PDF using config file into `js_from_pdf.js`
```sh
echo 'extract js > js_from_pdf.js' > extract_js.conf
peepdf -s extract_js.conf <file.pdf>
```
### vmonkey
* Detects malicious VBasic code in documents.
```sh
vmonkey <file.doc>
```
### Packaged Binaries
* Can be identified via entropy or loaded libs
* The count of libs loaded by a packaged bin is very low. A packaged PE could load `GetProcAddress` or `LoadLibrary`.
* [PEiD](https://www.aldeid.com/wiki/PEiD) detects most packers.
* File [Entropy](https://fsec404.github.io/blog/Shanon-entropy/) of a packaged is high.