Karton Gems 3: Malware extraction with malduck
ID: def0fbe3-22c5-5321-baaa-2f314065efba
STIX ID: report--def0fbe3-22c5-5321-baaa-2f314065efba
Feed Name: CERT Polska
This tutorial introduces malduck's extraction engine and shows how to build a simple Citadel configuration extractor using Yara-based callbacks, memory reading helpers, and light disassembly, then integrates the workflow into a Karton pipeline for automated config extraction and reporting, with step-by-step setup commands and example outputs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
