Philippe Lagadec Profile
Philippe Lagadec

@decalage2

Followers
5K
Following
18K
Statuses
6K

Author of oletools, olefile, ViperMonkey, ExeFilter, Balbuzard. #DFIR, #malware analysis, maldocs, file formats, #Python. @[email protected]

Joined November 2012
Don't wanna be here? Send us removal request.
@decalage2
Philippe Lagadec
5 years
Final slides of my presentation yesterday at Black Hat Europe 2019, about malicious VBA macros and recent advances in the attack & defence sides: Featuring #oletools/olevba, ViperMonkey, MacroRaptor, EvilClippy #BHEU #BHEU2019
Tweet media one
6
211
394
@decalage2
Philippe Lagadec
19 days
RT @awkwardgoogle: I had NO IDEA that Excel World Championship existed, but watching people being excellent at what they do is always fasci…
0
185
0
@decalage2
Philippe Lagadec
21 days
RT @vxunderground: This is a reminder to everyone that your malware payload does not need to be ultra-1337 for it to be effective or evasiv…
0
90
0
@decalage2
Philippe Lagadec
21 days
RT @Dinosn: Windows 11 BitLocker-Encrypted Files Accessed Without Disassembling Laptops
0
87
0
@decalage2
Philippe Lagadec
21 days
@Bit111111 Yes of course, there are lots of great examples of polyglot files available online, and there are even tools like mitra from @angealbertini that can generate such files. Here I'm really interested in malicious use of that technique "in the wild".
0
0
3
@decalage2
Philippe Lagadec
22 days
RT @angealbertini: Peeps: I'm looking for a PoC (not mine) which was a graphical game (breakout?) in PDF+JS+WebAsm (not a polyglot), Chrome…
0
5
0
@decalage2
Philippe Lagadec
27 days
RT @manekinekko: Running Doom in a... PDF file ! 🤯🤯🤯 Credits:
0
10
0
@decalage2
Philippe Lagadec
27 days
RT @EXPMON_: I've released the details of this Enjoy! Blog post: EXPMON detected "zero-day behavior" in PDF sampl…
0
7
0
@decalage2
Philippe Lagadec
28 days
RT @sekoia_io: 🇷🇺 #DoubleTap Campaign: #Russia-nexus APT possibly related to #APT28 conducts cyber espionage on Central Asia and Kazakhstan…
0
23
0
@decalage2
Philippe Lagadec
28 days
RT @thomasrinsma: Yes, PDF runs DOOM! (PDFium only for now)
0
220
0
@decalage2
Philippe Lagadec
1 month
RT @tom_doerr: A Bash script for auditing security and performance of Linux VPS, checking SSH config, firewall status, system updates, and…
0
140
0
@decalage2
Philippe Lagadec
1 month
RT @angealbertini: Let’s try something new in 2025… This saturday at 8pm CET, I'll stream about crafting a valid PDF file from scratch. We’…
0
11
0
@decalage2
Philippe Lagadec
1 month
RT @5mukx: An unexpected journey into Microsoft Defender's signature World:
Tweet media one
Tweet media two
0
108
0
@decalage2
Philippe Lagadec
1 month
RT @vivekramac: Happy New Year everyone! 2025 is a very interesting number: (a) It is the square of the sum of the first nine numbers: (…
0
7
0
@decalage2
Philippe Lagadec
1 month
RT @sans_isc: Goodware Hash Sets
Tweet media one
0
7
0
@decalage2
Philippe Lagadec
2 months
RT @Enno_Insinuator: Apple Platform Security Guide, December 2024 release [PDF]
Tweet media one
Tweet media two
Tweet media three
0
42
0
@decalage2
Philippe Lagadec
2 months
RT @blackorbird: Using LLMs to Obfuscate Malicious JavaScript
Tweet media one
0
59
0
@decalage2
Philippe Lagadec
2 months
RT @cyb3rops: I have tested and added the #YARA rules by @sekoia_io to the YARA Forge project YARA Forge automates the collection, standar…
0
42
0
@decalage2
Philippe Lagadec
2 months
RT @jstrosch: Malware Mondays #09 - File Identification and Hashing Algorithms
0
1
0
@decalage2
Philippe Lagadec
2 months
RT @ale_sp_brazil: Malwoverview version 6.1.0 has just been released: To install it: $ python -m pip install -U…
0
98
0