The Anatomy of a Modern Packer
A structured walkthrough of how runtime packers stage decompression and how analysts reason about them defensively.

SPIRITX
In-depth articles on the internals of reverse engineering and malware analysis — packers, obfuscation, binary formats, and the techniques that cut through them.
A structured walkthrough of how runtime packers stage decompression and how analysts reason about them defensively.
Techniques for recovering intent from obfuscated control flow without executing untrusted code.
A structured walkthrough of how runtime packers stage decompression and how analysts reason about them defensively.
Techniques for recovering intent from obfuscated control flow without executing untrusted code.
Everything a researcher needs to know about how the loader wires up an ELF binary at runtime.
A field guide to the encoding tricks you will meet and how to decode them methodically.