Cerbero Suite Advanced includes all the features of the Standard edition, so make sure to check out the standard edition for the list of features. The Advanced edition comes with additional features and is especially designed for experts in the security and forensic field. Among various additional file formats, it features the Carbon Interactive Disassembler with integrated Sleigh Decompiler, the Silicon Excel Emulator and the Ghidra Native UI.
State-of-the-art suite of tools for malware triage and file analysis. Analysis for many file formats including PE, Mach-O, ELF, Java, SWF, DEX, PDF, DOC, XLS, RTF, Zip and many more. Automatic analysis, interactive analysis, Carbon Interactive Disassembler, byte-code disassemblers (.NET MSIL, Java, DEX, ActionScript2/3, VBA, fonts), hex editor with layouts, Windows memory analysis (raw dumps, WinDmp files, hibernation files), JavaScript debugger, extremely rich Python3 SDK, extension support, C++/PDB structures importer, support for projects and bookmarks. Completely multi-platform (Windows, Linux, OS X). Visit our blog to see Cerbero Suite in action!
This is a list of some relevant features of Cerbero Suite Advanced. Please note that it is not possible to enumerate all features because of the complexity and on-going improvement of the product.
Carbon Interactive Disassembler
This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (http://www.openssl.org/)
Supported file formats:
Email (EML)
Extraction of attachments
Torrent
Windows Dmp files (WINDMP)
Inspection of internal structures
Full inspection of memory when available
Windows Hibernation files
Inspection of internal structures
Full inspection of memory
Windows Raw Memory Images (WINMEM)
Support for all Windows editions
Inspection of files in memory
Inspection of SSDT, IDT, GDT
Suppport for VAD trees
User address spaces
System address space
System symbols of all supported Windows editions
This is a list of some relevant features of Cerbero Suite Advanced. Please note that it is not possible to enumerate all features because of the complexity and on-going improvement of the product.
- All the features of the Standard edition
- Carbon Interactive Disassembler
- Supported architectures: x86, x64, ARM32/Thumb, ARM64
- Integrated Sleigh Decompiler
- Loading of debug symbols
- Defining of data types
- Silicon Excel Emulator
- Ghidra native UI
- Supported file formats:
- Email (EML)
- Extraction of attachments
- Torrent
- Windows crash dumps (WINDMP)
- Support for both kernel and mini-dumps
- Completely independent from WinDBG
- Inspection of code
- Inspection of call stack
- Inspection of threads
- Inspection of exception information
- Inspection of bug check information
- Inspection of memory
- Inspection of internal structures
- Windows Hibernation files
- Inspection of internal structures
- Full inspection of memory
- Windows Raw Memory Images (WINMEM)
- Support for all Windows editions
- Inspection of code
- Inspection of files in memory
- Inspection of SSDT, IDT, GDT
- Suppport for VAD trees
- User address spaces
- System address space
- Email (EML)
- DEVELOPER: Cerbero
- OS: Windows 7, Windows 8, Windows 10
- LANGUAGE: Multilingual
- Available languages: English, Italian, Polish, Spanish, French, Chinese, Japanese, German
- License Model: Purchase
- Price: $90 (Free in DLPure.com)
- ARM32/ARM64 disassembly and decompiling.
- Decompiling and emulation of Excel macros.
- Support for Microsoft Office document decryption.
- Disassembly of Windows user address space.
- Disassembly of Windows DMP files.
- Support of XLSB and XLSM formats.
- Support of CAB format.
- Hex editing of processes, disk and drives on Windows.
- Updated native UI for Ghidra 10.
- Improved decompiler.
- Improved macOS support.