[Misc Series #1] pydotNetCLI dotNet Header Parse and Resource Extractor

Hey guys! Just released a tool named ✨ pydotNetCLI ✨ that make my life easier when extract the resource file from dotNet malware samples as we know dotNet resource file stored inside dotNet CLI header which is not from the .rsrc section of the PE file. In this initial version, I will just focusing on the resource extraction and hopefully will add more header information or functions if time allows.

The initial intention of this tool just to improve my understanding on the dotNet CLI header structure, but it ends up as a resource extractor 🤣.

Screenshot

Output from pydotNetCLI 😉

Will make a explanation on how I parse it in the next blog post!

Next blog post over HERE!!

Link to the GitHub

https://github.com/ghoulgy/pydotNetCLI

--

--

--

Typical memes addict🐒 GitHub: https://github.com/ghoulgy 🍕Support my work: https://www.buymeacoffee.com/GhoulSec

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

{UPDATE} 天上天下 Hack Free Resources Generator

article 4 https://t.co/L2GHcvq6Qn

Fraudsters Exploiting the Pandemic: Evolving Fraud and Money Laundering Patterns

Combating Identity Theft: Stopping Fraudsters in Their Tracks

Guide to Participating in Nabox Launch on Pacific

Improving SOC Operations in the Covid World

6 Steps to a Great Channel Business in Cybersecurity

Web3 and Metaverse: do they go together?

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
GhouLSec

GhouLSec

Typical memes addict🐒 GitHub: https://github.com/ghoulgy 🍕Support my work: https://www.buymeacoffee.com/GhoulSec

More from Medium

“Static” and runtime type checking for python dict at same time

RaspberryPi with DHT22 Sensor for Humidity and Temperature Data with InfluxDB

WFH Work-Life Balance Tracker using Raspberry PI

Beginner’s Guide to ROS — Part 3 “Topics In-Depth”