[Misc Series #1] pydotNetCLI dotNet Header Parse and Resource Extractor

Hey guys! Just released a tool named ✨ pydotNetCLI ✨ that make my life easier when extract the resource file from dotNet malware samples as we know dotNet resource file stored inside dotNet CLI header which is not from the .rsrc section of the PE file. In this initial version, I will just focusing on the resource extraction and hopefully will add more header information or functions if time allows.

The initial intention of this tool just to improve my understanding on the dotNet CLI header structure, but it ends up as a resource extractor 🤣.

Screenshot

Output from pydotNetCLI 😉

Will make a explanation on how I parse it in the next blog post!

Next blog post over HERE!!

Link to the GitHub

https://github.com/ghoulgy/pydotNetCLI

--

--

--

Typical memes addict🐒 GitHub: https://github.com/ghoulgy 🍕Support my work: https://www.buymeacoffee.com/GhoulSec

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

Dear $WSPP & $GWSPP holders on Binance Smart Chain, today we are super happy to be able to offer a…

Dear Internet User

The ARBY airdrop can now be claimed!

Most MSMEs Are ‘Pick Mes’ Online: A look at how a Secure Website can increase your chances!

The Current State of Cybersecurity Performance

Kerberos — the magic behind authentication

{UPDATE} 4 Immagini 1 Calciatore Hack Free Resources Generator

TryHackMe walkthrough — Wordpress: CVE-2021–29447

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
GhouLSec

GhouLSec

Typical memes addict🐒 GitHub: https://github.com/ghoulgy 🍕Support my work: https://www.buymeacoffee.com/GhoulSec

More from Medium

How To Control a GoPro Camera via BlueTooth Using Python?

Secure Python socket with ngrok.

10 Minutes of Killer Python Inspiration With Influencer Mike Driscoll

Deploying Python and PostgreSQL in Docker