minusone

(โ˜… 101)

Powershell/Javascript deobfuscator based on tree-sitter

  • .envrc
  • .gitignore
  • Cargo.toml
  • devenv.lock
  • devenv.nix
  • devenv.yaml
  • javascript.yara
  • justfile
  • LICENSE
  • README.md

# Installation Guide

1. Get the code
git clone https://github.com/airbus-cert/minusone

Downloads the entire project code from GitHub to your computer.

cd minusone

Moves into the project folder you just downloaded.

2. Node.js

Easy Recommended
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Node.js Node.js must be installed to use npm. The LTS version is recommended.
โš ๏ธ This is a large repository, so this method may point to an internal sub-package rather than the actual core product. Check the full README as well.
cd crates/minusonejs

This project's files live in a subfolder, so move into it first.

npm install

Downloads and installs the libraries listed in package.json.

npm start

Starts the development/run server.

โœ… After running the command, open the address shown in the terminal (usually something like http://localhost:3000) in your browser.

3. Python

Easy
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Python 3 On Windows, be sure to check 'Add Python to PATH' during installation.
โš ๏ธ This is a large repository, so this method may point to an internal sub-package rather than the actual core product. Check the full README as well.
pip install .

Installs the package published on PyPI directly โ€” no need to clone the source.

python <์‹คํ–‰ํ•  ํŒŒ์ผ๋ช…>.py # README์—์„œ ์ •ํ™•ํ•œ ์‹คํ–‰ ํŒŒ์ผ๋ช…์„ ํ™•์ธํ•˜์„ธ์š”

Runs the Python script (or module).

โœ… If it runs without errors and prints output in the terminal, it worked.

4. Rust

Medium
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Rust (rustup) Installing via rustup also installs cargo.
cargo run -- --path test.ps1 # Run default ruleset

Builds and then immediately runs the program.

cargo run -- --path test.ps1 --debug # Run debug mode to print the inferred tree

Builds and then immediately runs the program.

cargo run -- --list # List available rule

Builds and then immediately runs the program.

cargo run -- --path test.ps1 -r forward,addint # Only use Forward and AddInt

Builds and then immediately runs the program.

cargo run -- --path test.ps1 -R foreach # Do not use foreach rule

Builds and then immediately runs the program.

โœ… If cargo build finishes without errors, it worked. The executable is created under target/.

Pulled directly from this repo's README.

// repository documentation