MASTIFF
MASTIFF is an static analyzer framework. It works on Linux and Mac. As a framework, the static analysis is based on plugins from the MASTIFF author and from the community.
These plugins include the following:
trid : This is used for identifying file types. ssdeep : ssdeep is a fuzzy hash calculator. A fuzzy hash, or context triggered piecewise hashes (CTPH), can be used to identify nearly identical files. This is useful for identifying variants of a malware family. pdftools : A plugin by Didier Stevens. This extracts information about PDF files. exiftool : This shows info, from image files. pefile : This shows information about PE files. disitool : This is another Python script from Didier Stevens. This is used to extract digital ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access