Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   Detect It Easy 0.73 (https://forum.exetools.com/showthread.php?t=15028)

Dreamer 05-27-2013 00:09

Detect It Easy 0.73
 
5 Attachment(s)
Not sure if this is a carry on from the old DiE by hellspawn but seems interesting and the version number seems to take off from 0.64/5 DiE version that was last released (as far as I know) Haven't had a proper chance to test it out a lot yet due to being at work but seems promising and may have a better play tonight.

Attachment 6916

Attachment 6917

Attachment 6918

Attachment 6919

Attachment 6921


Ps: i am search here but not found thread if exist move this there also credit for this go to "StreamLine" hi post this on tuts4you

here is web site

wilson bibe 05-27-2013 09:18

Thanks BRO

Dreamer 07-13-2013 02:28

Detect It Easy 0.74

Code:

http://ntinfo.biz/files/DIE074.rar

sendersu 07-13-2013 18:51

as for my short exploration and discovery the tools looks damn good, gentlemen!

benney 07-22-2013 11:26

thanks for your share...this tool is a very good one.

Dreamer 07-22-2013 13:05

Detect It Easy ver. 0.75
 
Code:

http://ntinfo.biz/files/DIE075.rar

Dreamer 08-23-2013 18:26

Detect It Easy ver.0.76.1 is out

Code:

http://ntinfo.biz/index.php/detect-it-easy
:D

CRoot 08-25-2013 18:00

Sorry, at first glance to Detect as the Delete, I thought it was a tool to Delete files.
This tool compared with PE Exeinfo?

wilson bibe 10-03-2013 09:54

Update to version 0.77

Quote:

http://ntinfo.biz/index.php/detect-it-easy

Newbie_Cracker 10-03-2013 17:29

no changelog?

BAHEK 11-02-2013 22:04

Update to version 0.78

Сhangelog:
[+] Added a IMAGE_DIRECTORY_ENTRY_DEBUG (void)
[+] Added definition PCGuard (NikolayD)
[+] Added definition Safengine (NikolayD)
[+] Added definition NoobyProt (NikolayD)
[+] Improved the registry under Win8 x64 (4kusNick)
[ +] Improved opening a file, if one copy of the program is already running (4kusNick)
[+] Improved the appearance tab "Thanks" window "About" (4kusNick)
[+] added to the SDK function changes the order of bytes in a double word (GPcH)
[+] The SDK function added transforming the file offset of the virtual address (GPcH)
[+] added to the SDK function searches the string in the # heap. NET files (GPcH)
[+] Added label change in HEX-viewer in accordance with the fact that it shows . (BOROV)
[+] Improved definition Enigma Protector (DimitarSerg)
[+] Added definition FoxPro (DimitarSerg)
[+] Improved definition ASProtect 1.32Beta, 1.23rc1-SDK, 2.5 SKE build 03.31, 2.56 SKE build 0317 (4kusNick)
[+ ] Improved definition ASDPack 2.0 (4kusNick)
[+] Added definition Break-Into-Pattern (BIP!) v0.1 (4kusNick)
[+] Added detection of DOC (4kusNick)
[+] Fixed bug with saving the registry (changed "\ "on" / ") (redblkjck)
[+] Added detection for UPX PE + (Fix sent AJAX)
[+] Improved detection of new versions ExeCryptor (DimitarSerg)
[+] Improved detection of new versions VMProtect (DimitarSerg)

Download:
http://ntinfo.biz/index.php/detect-it-easy

giv 11-03-2013 01:50

Quote:

Added definition FoxPro (DimitarSerg)
It detects if the file is VFP compiled or detects one of the VFP protections like Refox, Defox etc....?

sendersu 11-03-2013 20:11

Very promising project!
dynamic and feature rich! Definitely Peid killer

BAHEK 11-28-2013 04:55

Update to version 0.79

Сhangelog:
[+] Fixed some bugs.
[+] Improved definition ACProtect 1.41 and ACProtect 2.1.0 (4kusNick)
[+] Improved definition ANDpakk2 (apk2) v0.18 (4kusNick)
[+] Improved definition ASPack 1.05b (4kusNick)
[+] Improved definition ASPack 1.061b ( as Detective ASPack1.07b) (4kusNick)
[+] Improved definition ASPack 1.08.02 ( as Detective 1.08.01) (4kusNick)
[+] Improved definition ASPack 2.000, 2.001, 2.1, 2.11c, 2.11d (4kusNick)
[+] Improved definition DYAMAR Protector 1.3.5 (4kusNick)
[+] Improved detection of some versions ASPack (== DJ == [ZLO])
[+] Fixed bug with incorrect processing keys in the console version (exet0l)
[+] Improved definition of MSI (== DJ == [ZLO])
[+] Improved detection of new versions of Delphi (Mick Grove)
[+] Added detection of Excelsior JET (signature sent sendersu)

Download:
http://ntinfo.biz/index.php/detect-it-easy

giv 11-29-2013 02:11

Is important that the developement continue.

sope2001 11-30-2013 13:18

Nice to see the detecting tools getting updates. Kudos to all of you!

kjms 01-14-2014 22:29

Download DIE ver. 0.80 (Windows)

Plugin for HIEW (author exet0l)

Plugin for CFF Explorer (author exet0l)

nikkapedd 01-15-2014 00:17

kjms, do you know how to make working the plugin under CFF Explorer..???
Thanks in advance...

kjms 01-15-2014 01:19

Copy the DIE_Plugin.dll & die folder,place the files here
C:\Program Files\NTCore\Explorer Suite\Extensions\CFF Explorer

alfares 01-15-2014 02:12

Quote:

Originally Posted by giv (Post 88376)
Is important that the developement continue.

yes i think new Versions will be soon :)

kjms 02-05-2014 19:51

Detect It Easy 0.81
Download: http://ntinfo.biz/index.php/detect-it-easy
Source: http://n10info.blogspot.nl/

[+] Fixed some bugs
[+] Improved definition VMprotect for dll (DenCoder)
[+] Fixed a bug with processing export some files (deniskore)
[+] Improved definition Safengine Shielden (DimitarSerg)
[+] Improved definition Starforce (Slinger)
[+] Improved detection of new versions of Armadillo (Dazz)
[+] Improved definition. ANDpakk2 (4kusNick)

LostandFound 02-10-2014 04:30

This is a very useful tool indeed.

an0rma1 02-10-2014 16:56

very nice idea and very good implemented, i am thinking about adding all dos exes protectors as ids, old stuff is still interesting for some of us :D

sendersu 02-11-2014 05:05

Quote:

Originally Posted by an0rma1 (Post 89891)
very nice idea and very good implemented, i am thinking about adding all dos exes protectors as ids, old stuff is still interesting for some of us :D

Are you sure it'll read DOS MZ?

an0rma1 02-23-2014 18:01

Quote:

Originally Posted by sendersu (Post 89908)
Are you sure it'll read DOS MZ?

hi,
yes, look here http://ntinfo.biz/files/How%20to%20create%20signatures.pdf

Code:

Currently the program defines the following types:
• MSDOS executable files MS-DOS
• PE executable files Windows
• ELF executable files Linux
• Binary all other files


wilson bibe 03-06-2014 03:20

DIE V.0.82

Quote:

Download:
http://ntinfo.biz/index.php/detect-it-easy
Quote:

Changelog:
[+] Fixed some bugs
[+] Optimized library for working with signatures
[+] Add information on the armadillo (Dazz)
[+] DotFix NiceProtect detection 2.5 (Dazz)
[+] Added .NET protectors (ajax)
[+] Improved determination Y0da's Cryptor (DICI BF)
[+] Fixed bug with IA-64 detektom files (A.S.L)
[+] Made an active link "Bugreport (A.S.L)
[+] Fixed bug editing in HEX-Editor (hypn0)

kjms 03-24-2014 15:08

DIE V.0.83
Code:

http://ntinfo.biz/index.php/detect-it-easy
Change log:
[+] Fixed some bugs
[+] Added new MACH-O (executable Mac OS)
[+] Improved displaying graphics entropy (void)
[+] Fixed bug with incorrect output time when scanning folders (hypn0)
[+] Fixed bug with incorrect output when scanning a folder path (hypn0)
[+] Added a configuration file for the console version (hypn0)
[+] Fixed bug with incorrect display of TLS callback in PE + (deniscore)


val2032 03-30-2014 03:46

This is a MUST HAVE tool...

giv 03-30-2014 19:50

Quote:

Originally Posted by val2032 (Post 90605)
This is a MUST HAVE tool...

Not quite.
Every "tool" of this kind have his own good/bad stuff compared to the "concurrence".
:)

Carbon 03-31-2014 00:26

Let's hope the author will make it open source or it will DIE like PEiD ;)

chicknsoup 04-01-2014 00:52

Quote:

Originally Posted by Carbon (Post 90625)
Let's hope the author will make it open source or it will DIE like PEiD ;)

It shouldn't be dead anytime soon :D

peMan!a 04-01-2014 22:09

IMO this better than PEiD coz it is still active and detection engine can still be improved.

Dreamer 04-08-2014 20:26

DIE_083_win

Code:

http://rghost.net/53681044
reason for this link to post is cannot be downloaded from main site.

Ps: link i post is from tuts4you posted there by horse credit to him.

sendersu 04-08-2014 20:38

short question - does it detect .net protectors?

kjms 04-18-2014 10:13

DIE V.0.84
http://ntinfo.biz/index.php/detect-it-easy
Change log:
Code:

[+] Fixed some bugs
[+] Added support for native plugins (BoRoV)
[+] Improved definition BeRo DLL Linker Compressor v1.0 byBeRo (4kusNick)
[+] Improved definition. Net Reactor (BoRoV)
[+] Improved window view "Thanks" (BoRoV)
[+] Added detection Spoon Studio (GMAP)


Dreamer 04-18-2014 13:16

kjms mate your link no good

Code:

http://ntinfo.biz/index.php/detect-it-easy

RedBlkJck 04-22-2014 20:58

1 Attachment(s)
Here is a build of the DIE CFF plugin to support running the 64 bit version of CFF.

leetone 04-23-2014 13:53

Windows 0.8.4 - http://ntinfo.biz/files/DIE_084_win.zip
Linux x64 0.8.4 - http://ntinfo.biz/files/DIE_084_lin64.tar.gz
Linux x86 0.8.4 - http://ntinfo.biz/files/DIE_084_lin32.tar.gz
Mac OSX 0.8.4 - http://ntinfo.biz/files/DIE_084_mac.dmg

HIEW Plugin - http://ntinfo.biz/files/Detect%20It%20Easy%20Hem%20for%20Hiew.zip
(info: http://n10info.blogspot.ru/2014/01/dies-plugin-for-hiew.html)

CFF Explorer Plugin - http://ntinfo.biz/files/Detect%20It%20Easy%20Plugin%20for%20CFF%20Explorer.zip
(info: http://n10info.blogspot.ru/2014/01/dies-plugin-for-cff-explorer.html)

kjms 05-24-2014 11:54

DIE V.0.85

detect-it-easy

Code:

[+] Added detection of known files (ajax)
[+] Added ability to copy signatures (hypn0)
[+] Added detection EXE32pack (== DJ == [ZLO])
[+] Added a new type of "Text" (Jason Hood)
[+] Added a few new signatures (Levis)
[+] Added new features and the console version (Jason Hood)


kjms 06-18-2014 12:05

DIE V.0.86
http://ntinfo.biz/index.php/detect-it-easy
Code:

[+] Fixed some bugs
[+] For the entropy made ​​fixed-width table sections (void)
[+] Revision of all signatures (Jason Hood)
[+] Fixed error when scanning some non-standard files (deniskore)
[+] Added ability to search kriptosignatur [Search-> Crypto]
[+] Open repository for signatures https://github.com/horsicq/Detect-It-Easy
[+] Scan Engine as a separate dll http://ntinfo.biz/files/diedll.zip



All times are GMT +8. The time now is 07:07.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX