Transcription of Practical Malware Analysis - Black Hat Briefings
{{id}} {{{paragraph}}}
Practical Malware Analysis Kris Kendall and Chad McMillan Outline Why Analyze Malware ? Creating a Safe Analytical Environment Static Analysis Techniques Dynamic Analysis Techniques Packing Finding Malware 1-2. What is Malware ? Generally Any code that performs evil . Today Executable content with unknown functionality that is resident on a system of investigative interest Viruses Worms Intrusion Tools Spyware Rootkits 1-3. Analyzing Malware Why Analyze Malware ? To assess damage To discover indicators of compromise To determine sophistication level of an intruder To identify a vulnerability To catch the bad guy.
Our nice, safe analytical environment wasn’t ... Snapshots make life easier. 1-40 System Monitoring What we are after •Registry Activity •File Activity •Process Activity •Network Traffic The tools •SysInternals Process Monitor •Wireshark •+ a whole bunch of other stuff.
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}