forked from mandiant/flare-vm
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathprofile.json
172 lines (138 loc) · 5.16 KB
/
profile.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
{
"env": {
"TOOL_LIST_DIR": "%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\FLARE",
"TOOL_LIST_SHORTCUT": "%UserProfile%\\Desktop\\FLARE.lnk",
"RAW_TOOLS_DIR": "%SystemDrive%\\Tools",
"TEMPLATE_DIR": "flarevm.installer.flare"
},
"packages": [
{"name": "dotnetfx"},
{"name": "powershell"},
{"name": "vcbuildtools.fireeye"},
{"name": "cmder.fireeye"},
{"name": "vcpython27"},
{
"name": "python2.x86.nopath.flare",
"x64Only": true,
"args": "--package-parameters \'/InstallDir:C:\\Python27.x86\'"
},
{"name": "libraries.python2.fireeye"},
{"name": "libraries.python3.fireeye"},
{"name": "ollydbg.flare"},
{"name": "ollydbg.ollydump.flare"},
{"name": "ollydbg.ollydumpex.flare"},
{"name": "ollydbg2.flare"},
{"name": "ollydbg2.ollydumpex.flare"},
{"name": "x64dbg.flare"},
{"name": "x64dbg.py.flare"},
{"name": "x64dbg.ollydumpex.fireeye"},
{"name": "windbg.flare"},
{"name": "windbg.kenstheme.flare"},
{"name": "windbg.ollydumpex.flare"},
{"name": "windbg.pykd.flare"},
{"name": "scdbg.flare"},
{"name": "idafree70.flare", "x64Only": true},
{"name": "idafree.flare"},
{"name": "binaryninja.flare"},
{"name": "radare2.flare"},
{"name": "cutter.flare"},
{"name": "ghidra.fireeye"},
{"name": "ilspy.flare"},
{"name": "dnspy.flare"},
{"name": "dotpeek.flare"},
{"name": "de4dot.flare"},
{"name": "dnsd.flare"},
{"name": "rundotnetdll.flare"},
{"name": "javaruntime"},
{"name": "jd-gui.flare"},
{"name": "java-deobfuscator-gui.fireeye"},
{"name": "bytecode-viewer.flare"},
{"name": "dex2jar.flare"},
{"name": "vbdecompiler.flare"},
{"name": "idr.small.flare"},
{"name": "ffdec.flare"},
{"name": "kali_windowsbinaries.flare"},
{"name": "volatility.flare", "x64Only": true},
{"name": "Autospy.fireeye"},
{"name": "fileinsight.flare"},
{"name": "hxd.flare"},
{"name": "010editor.flare"},
{"name": "peid.flare"},
{"name": "explorersuite.flare"},
{"name": "peview.flare"},
{"name": "die.flare"},
{"name": "pestudio.flare"},
{"name": "pebear.flare"},
{"name": "hollowshunter.fireeye"},
{"name": "pesieve.fireeye"},
{"name": "resourcehacker.flare"},
{"name": "processdump.fireeye"},
{"name": "sublimetext3"},
{"name": "notepadplusplus.flare"},
{"name": "SilkETW.fireeye"},
{"name": "unxutils"},
{"name": "farmanager.flare"},
{"name": "checksum"},
{"name": "7zip.flare"},
{"name": "lessmsi.fireeye"},
{"name": "putty"},
{"name": "wireshark.flare"},
{"name": "nmap.flare"},
{"name": "winpcap"},
{"name": "rawcap"},
{"name": "wget"},
{"name": "bytehist.fireeye"},
{"name": "upx"},
{"name": "processhacker.flare"},
{"name": "sysinternals.flare"},
{"name": "apimonitor.flare"},
{"name": "spystudio.flare"},
{"name": "hashcalc.flare"},
{"name": "hashmyfiles.flare"},
{"name": "regshot.flare"},
{"name": "exeinfope.flare"},
{"name": "ncat.flare"},
{"name": "shellcode_launcher.flare"},
{"name": "xorsearch.flare"},
{"name": "xorstrings.flare"},
{"name": "yara.flare"},
{"name": "kmdloader.flare"},
{"name": "lordpe.flare"},
{"name": "googlechrome.flare"},
{"name": "cyberchef.flare"},
{"name": "py2exedecompiler.flare"},
{"name": "pyinstxtractor.fireeye"},
{"name": "uniextract2.fireeye"},
{"name": "innounp.fireeye"},
{"name": "innoextract.fireeye"},
{"name": "ppee.fireeye"},
{"name": "exe2aut.fireeye"},
{"name": "ImpRec.fireeye"},
{"name": "procdot.fireeye"},
{"name": "offvis.flare"},
{"name": "officemalscanner.flare"},
{"name": "oledump.fireeye"},
{"name": "rtfdump.fireeye"},
{"name": "msoffcrypto-crack.fireeye"},
{"name": "oletools.fireeye"},
{"name": "pdfid.flare"},
{"name": "pdfparser.flare"},
{"name": "pdfstreamdumper.flare"},
{"name": "nasm.fireeye"},
{"name": "vim.flare"},
{"name": "cygwin.flare"},
{"name": "retdec.flare"},
{"name": "MAP.flare"},
{"name": "SysAnalyzer.flare"},
{"name": "pmalabs.flare"},
{"name": "PSDecode.fireeye"},
{"name": "burp.free.fireeye"},
{"name": "fiddler.fireeye"},
{"name": "HTTrack.fireeye"},
{"name": "malware-jail.fireeye"},
{"name": "apktool.flare"},
{"name": "flare-qdb.python.flare"},
{"name": "floss.python.flare"},
{"name": "fakenet-ng.python.flare"}
]
}