Black Hat USA 2018 - Finding Xori Malware Analysis Triage with Automated Disassembly @HackersOnBoard
Black Hat USA 2018 - Finding Xori Malware Analysis Triage with Automated Disassembly  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
In a world of high volume malware and limited researchers, we need a dramatic improvement in our ability to process and analyze new and old malware at scale. Unfortunately, what is currently available to the community is incredibly cost prohibitive or does not rise to the challenge. As malware authors and distributors share code and prepackaged tool kits, the white hat community is dominated by solutions aimed at profit as opposed to augmenting capabilities available to the broader community. With that in mind, we are introducing our library for malware disassembly called Xori as an open source project. Xori is focused on helping reverse engineers analyze binaries, optimizing for time and effort spent per sample.

Xori is an automation-ready disassembly and static analysis library that consumes shellcode or PE binaries and provides triage analysis data. This Rust library emulates the stack, register states, and reference tables to identify suspicious functionality for manual analysis. Xori extracts structured data from binaries to use in machine learning and data science pipelines.

We will go over the pain-points of conventional open source disassemblers that Xori solves, examples of identifying suspicious functionality, and some of the interesting things we've done with the library. We invite everyone in the community to use it, help contribute and make it an increasingly valuable tool in this arms race.
Black Hat USA 2018 - Finding Xori Malware Analysis Triage with Automated DisassemblyBlack Hat USA 2018 - Your Voice is My PassportBlack Hat USA 2018 - Stop that Release, Theres a Vulnerability!Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren SystemDEF CON 27 - Alon Weinberg - Please Inject Me a x64 Code InjectionBlack Hat USA 2018 - I, for One, Welcome Our New Power Analysis OverlordsBlack Hat USA 2018 - Last Call for SATCOM SecurityBlack Hat USA 2018 - Understanding and Exploiting Implanted Medical DevicesDEF CON 27 - Panel - Hacking Congress The Enemy Of My Enemy Is My FriendDEF CON 27 - Ali Islam - Weaponizing Hypervisors to Fight and Beat Car and Medical Devices AttacksAttacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature SchemeDEF CON 27 - Elie Bursztein - How Deep Learning Is Revolutionizing Side-Channel Cryptanalysis
HackersOnBoard |

Black Hat USA 2018 - Finding Xori Malware Analysis Triage with Automated Disassembly

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER