This repository contains several simple extension to CFF Explorer ( http://www.ntcore.com/exsuite.php ) by Daniel Pistelli. These include:
- CFFStrings
- Finds ASCII and Unicode strings within files
- CFFHashes
- Calculates CRC, MD5, SHA1 and SHA256 hashes for files and parts of files
- CFFYara
- Enables Yara scanning from within CFF Explorer.
- CFFCapstone
- Capstone disassembly from within CFF Explorer
To install, simply download and run the setup program. Ensure that your installation path is within the:
'Extensions\CFF Explorer'
folder of your CFF Explorer installation directory.
When you launch CFF Explorer, 4 new items will be displayed: 'String', 'Hashes', 'Yara', and 'Capstone' as shown below: