Sept. 15, 2023, 4:26 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

When you need to change the prototype of a function in the decompiler, the standard way is to use the “Set item type…” action (shortcut Y).



One case where you may need to do it is to add or remove arguments. Especially in embedded code or when decompiling variadic functions, the decompiler may deduce the argument list wrongly. A good test for bogus arguments is to check whether they’re referenced in the function’s body. For this, use “Jump to xref” …

action case change code decompiler decompiling embedded function malware analysis may prototype remove standard week

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)