Zum Hauptinhalt springen
Sicherheitslücken (CVE)CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization(18.09.2026 um 20:48 Uhr)
Sicherheitslücken (CVE)CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization(18.09.2026 um 20:48 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

99 adversarial PE files: exploring malformed‑binary behaviour across major analysis tools

I’ve built a 99‑fixture adversarial PE corpus to explore how different tools behave when confronted with deliberately malformed but still loadable binaries.

Each fixture introduces one corruption pattern - no packers or multi‑anomaly noise, which allows for clean attribution of behaviour. The anomalies span:

  • entrypoint redirection
  • overlapping/invalid sections
  • header inconsistencies
  • directory OOB conditions
  • TLS edge cases
  • recursive/malformed resources
  • Authenticode structural corruption
  • entropy‑field manipulation

I tested 6 tools commonly used in exploit dev workflows:

  • IOCX
  • Ghidra
  • Detect It Easy
  • radare2
  • PEview
  • CFF Explorer

Behavioural patterns with exploit‑relevant implications:

  • Literal parsers (r2, PEview) never crashed but provided no anomaly visibility
  • Semantic parsers (CFF) “fixed” corruption, masking exploit‑useful inconsistencies
  • Heuristic tools (DIE) ignored structure, blind to malformed metadata
  • Reconstructive loaders (Ghidra) rewrote metadata, omitted fields, and crashed on entropy fixtures
  • Hybrid literal‑semantic tools (IOCX) preserved raw bytes and surfaced anomalies explicitly

For exploit dev, malformed PE structures can act as:

  • parser differentials
  • crash primitives
  • metadata confusion vectors
  • loader‑model inconsistencies
  • analysis‑evasion surfaces

This corpus maps those behaviours systematically.

Full write‑up (Part 1):

The Adversarial PE Analysis Series — Why PE Parsers Break

Corpus and fixture spec: https://github.com/iocx-dev/iocx

(fixtures are under /tests/contract/fixtures/layer3_adversarial)

submitted by /u/iocx_dev
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 99 adversarial PE files: exploring malformed‑binary behaviour across major analysis tools

Thematisch verwandte Begriffe: adversarial, files, exploring, malformedbinary · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick