Skip to content

Commit 980a7da

Browse files
committed
readme update
1 parent 2919596 commit 980a7da

File tree

1 file changed

+6
-3
lines changed

1 file changed

+6
-3
lines changed

README.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,15 @@
1-
# craper-v2
2-
Temporary repo for CRAPER
1+
# KeyReaper
2+
This tool was developed as part of a reserach on Windows `HCRYPTKEY`, the internal format to represent keys in the CryptoAPI.
3+
4+
This tool is able to make a copy of the heap of the remote process and scan it looking for cryptographic keys. It is also able to manage the execution
5+
of the remote process. It is meant to be paired with an AV or EDR system for early ransomware response.
36

47
> [!WARNING]
58
> This program is architecture dependant. The compilation produces two slightly version for 32 and 64 bit where, for the most part, the pointer sizes change, but also some important constants of the scanners. Take this into account when analyzing a program, since you will need the corresponding application: for example, WannaCry, which is a 32 bit ransomware, needs to be analyzed with the x86 (32 bit) version of this program. On the other hand, a 64 bit ransomware needs to be analyzed with the 64 bit version of this program, otherwise it will fail.
69
710
## Dependencies
811

9-
* CMake
12+
* CMake (using 3.30.1)
1013
* MS Visual Studio Tools: [Offical page](https://visualstudio.microsoft.com/downloads/#tools-for-visual-studio-2022-family)
1114
* Install as individual component: [MSBuild support for LLVM](https://learn.microsoft.com/en-us/visualstudio/msbuild/walkthrough-using-msbuild?view=vs-2022#install-msbuild)
1215
* MSBuild Tools

0 commit comments

Comments
 (0)