frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Reverse engineered 90 legacy builder tools – created a YARA corpus

1•GokbakarE•5h ago
Over the past few months I manually emulated 94 legacy remote tool builder applications (often used to create unauthorized remote control frameworks during the 2000s–2010s) inside isolated QEMU sandboxes.

Each builder was used to generate a unique binary sample. I then:

    Wrote one variant-specific YARA rule per builder output

    Extracted PE metadata (sections, timestamps, entropy, IAT)

    Captured static capability signatures with CAPA

    Logged obfuscation artifacts via Detect It Easy (DIE)

    Committed everything granularly (1.1k commits) for traceability
The focus is not generic detection — it’s forensic fingerprinting of distinct builder families.

All samples were sandbox-generated (not recycled from VT or hybrid analysis). For ethical reasons, I do not share raw binaries, but I do provide structural hashes and extracted metadata.

The repo includes full documentation, including my QEMU workflow, rule methodology, and internal hash policy.

Repo link: https://github.com/GokbakarE/RuleSetRAT

I’m currently 15. Feedback from RE researchers and signature writers is welcome — especially if you’ve dealt with old tooling or variant detection in the wild.

Confluent Developer Courses

https://developer.confluent.io/courses/
1•saikatsg•21s ago•0 comments

Be a guest on the first AI-hosted podcast

https://ainterview.space
1•TommyKid•37s ago•0 comments

What Does Consulting Do?

https://www.nber.org/papers/w34072
1•MrBuddyCasino•59s ago•0 comments

'In the Shadow of the Moon' Film Review

https://www.hollywoodreporter.com/movies/movie-reviews/shadow-moon-1242948/
1•walterbell•59s ago•0 comments

Show HN: I built an API for extracting YouTube summaries, transcripts and stats

https://www.socialkit.dev/
1•geiger01•1m ago•0 comments

The Realities of Semantic Search

https://deepnoodle.ai/blog/the-realities-of-semantic-search
1•myzie•2m ago•0 comments

Show HN: I built an AI agent that schedules meetings from Gmail and Slack

https://meetalphie.com/
2•Riphyak•3m ago•1 comments

Plex: Perturbation-Free Local Explanations for LLM-Based Text Classification

https://arxiv.org/abs/2507.10596
1•PaulHoule•4m ago•0 comments

Show HN: Typogram Studio – like Figma but for typography

https://typogram.co/studio/
1•wentin•4m ago•0 comments

PagerDuty exploring potential sale after receiving buyer interest

https://www.reuters.com/markets/europe/pagerduty-exploring-potential-sale-after-receiving-buyer-interest-sources-say-2025-07-25/
1•m-hodges•5m ago•0 comments

Show HN: Mock Interviews for Software Engineers

https://www.mockinterviews.dev/
1•fahimulhaq•6m ago•0 comments

Transcribe speech 100x faster and 100x cheaper with open models

https://modal.com/blog/fast-cheap-batch-transcription
1•thundergolfer•6m ago•0 comments

Bet on or Against the Unicorns

https://www.bloomberg.com/opinion/newsletters/2025-07-28/bet-on-or-against-the-unicorns
1•ioblomov•6m ago•1 comments

Doco – Cursor for Microsoft Word

https://www.trydoco.com
1•arittr•9m ago•0 comments

Is SoftBank Still Backing OpenAI?

https://www.wheresyoured.at/softbank-openai/
3•samuli•11m ago•0 comments

Tesla signs $16.5B deal with Samsung to make AI chips

https://techcrunch.com/2025/07/28/tesla-signs-16-5b-deal-with-samsung-to-make-ai-chips/
1•skadamat•13m ago•0 comments

You can turn ANY AI SDR into a hacker

1•alex_varga•14m ago•0 comments

The Weakest Link Fallacy

https://www.cs.ru.nl/~jhh/publications/weakest-link-fallacy.html
1•mmsc•16m ago•0 comments

A quick note to our queer members

https://blog.nearlyfreespeech.net/2025/07/27/a-quick-note-to-our-queer-members/
2•Vinnl•17m ago•0 comments

Show HN: C2hat – Cross-Domain Chat

https://chromewebstore.google.com/detail/c2hat-cross-domain-chat/chngimmfgmkpninihhljpidnieocmhdn
1•pardnchiu•17m ago•0 comments

Claude Code new limits – Important updates to your Max account usage limits

43•ivanvas•20m ago•8 comments

GEPA: Reflective Prompt Evolution Can Outperform Reinforcement Learning

https://twitter.com/LakshyAAAgrawal/status/1949867947867984322
1•LakshyAAAgrawal•20m ago•1 comments

Parallelizing AI Coding Agents

https://ainativedev.io/news/how-to-parallelize-ai-coding-agents
1•gk1•23m ago•0 comments

How many NYT spelling bees are left?

https://gauthamsk.substack.com/p/how-many-nyt-spelling-bees-are-left
1•shrike_cultist•26m ago•0 comments

Claude Code weekly rate limits

20•thebestmoshe•29m ago•11 comments

Anthropic email to Max customers Re: Max account usage limits

3•kid64•30m ago•1 comments

Anthropic introduces new weekly limits for paid subs

3•tankenmate•30m ago•1 comments

React-three/viverse – for react and vanilla threejs

https://pmndrs.github.io/viverse/
1•BelaBohlender•30m ago•0 comments

New usage limits for Claude Code

https://twitter.com/AnthropicAI/status/1949898502688903593
3•charliermarsh•30m ago•1 comments

Model2Vec as a Fasttext Alternative

https://minish.ai/blog/2025-07-28-fasttext
3•stephantul•31m ago•1 comments