Carnegie Mellon University
Browse

Introducing CERT Kaiju: Malware Analysis Tools for Ghidra

Download (127.45 kB)
Version 2 2023-01-12, 21:30
Version 1 2021-09-15, 16:46
online resource
posted on 2023-01-12, 21:30 authored by Garret WassermannGarret Wassermann, Jeffrey GennariJeffrey Gennari
Since the National Security Agency publicly released the software reverse engineering (SRE) tool suite, we have been working to integrate Ghidra into our Pharos malware analysis tool. Ghidra provides many useful reverse engineering services including disassembly, function partitioning, decompilation, and various other types of program analyses. As this post details, we have been developing a new suite of tools, known as Kaiju, for malware analysis and reverse engineering to take advantage of Ghidra’s capabilities and interface. Ghidra provides a compelling environment for reverse engineering tools that are relatively easy to use during malware analysis. The tools included with Kaiju give malware analysts many advantages as they are faced with increasingly diverse and complex malware threats.

History

Date

2021-09-13

Copyright Statement

© 2021 Carnegie Mellon University https://www.sei.cmu.edu/legal/index.cfm

Usage metrics

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC