1-Operating Modes

Preview unavailable

You must log in or sign up to view this lesson.

LoginSign up

Malware Analysis and Development

Buy nowLearn more

Introduction

  • 00-Introduction
  • MalwareAnalysisAndDevelopmentLabs.pdf
  • MalwareAnalysisAndDevelopment.pdf
  • Labs.zip
  • Demos.zip
  • Malware Samples.zip
  • Malware Samples Zip Password

Windows Internals Overview

  • 1-Processes
  • 2-Task Manager
  • 3-Process Explorer2
  • 4-Virtual Memory2
  • 5-Threads4
  • 6-System Architecture2
  • 7-APIs
  • 8-Objects and Handles5
  • 9-Labs Intro

Windows Application Development Fundamentals

  • 1-Application Development Fundamentals
  • 2-Working with Strings
  • 3-System Information
  • 4-Working with Handles
  • 5-Sharing Objects by Name2
  • 6-Duplicating Handles
  • 7-Object Names and Sessions
  • 8-Sessions
  • 9-Private Object Namespace

Processes, Memory and Threads

  • 1-Process Creation
  • 2-The CreateProcess API
  • 3-Process Termination
  • 4-Labs Solution Walkthrough
  • 5-DllMain
  • 6-Process and Thread Attributes
  • 7-Process Enumeration
  • 8-PEB and Other Details
  • 9-Process Memory
  • 10-Reserving and Committing Memory2
  • 11-Heaps
  • 12-Threads Basics
  • 13-Creating Threads3
  • 14-Odds and Ends

Dynamic Link Libraries

  • 1-Building DLLs1
  • 2-Consuming DLLs1
  • 3-Reducing Dependencies
  • 4-DLL Injection with a Remote Thread2
  • 5-DLL Injection with an APC
  • 6-Odds and Ends

x86/x64 Fundamentals

  • 1-Operating Modes
  • 2-Assembling with Visual Studio
  • 3-x86/x64 Basics
  • 4-Operands and Address Modes
  • 5-Fundamental Instructions
  • 6-Calling External Functions
  • 7-Calling Conventions
  • 8-Bitwise Operations
  • 9-Branch Instructions
  • 10-The Stack
  • 11-Shellcode
  • 12-Injecting Shellcode
  • 13-Odds and Ends

.NET Fundamentals

  • .NET Fundamentals

COM Fundamentals

  • 1-COM Basics
  • 2-COM Concepts, Clients and Servers
  • 3-Creating and Using a COM Object
  • 4-Smart Pointers
  • 5-OLE/COM Object Viewer
  • 6-COM Activation in Detail
  • 7-CoCreateInstance in Detail
  • 8-Out of Process Servers
  • 9-COM Callbacks and Implementations

The Native API

  • 1-Native API Basics
  • 2-Object Manager and Native APIs
  • 3-Registry APIs
  • 4-Enumerating Processes and Handles

Introduction to Malware Analysis and Lab Setup

  • 1 - The Importance of Understanding and Dissecting TTPs
  • 2 - Introduction to Malware Analysis
  • 3 - Understanding AV-EDR Vendor Detection Names
  • 4 - Installing Flare-VM
  • 5 - PE 101 - Part 1
  • 6 - PE 101 - Part 2
  • 7 - Strings
  • 8 - Packing Detection - Part 1
  • 9 - Packing Detection - Part 2
  • 10 - Packing Detection - Part 3
  • 11 - Detecting Malicious Functionality

Reverse Engineering .NET, VBA and Shellcode Malware

  • 1 - Introduction to the SolarWinds Sunburst Attack
  • 2 - Sunburst Backdoor Initial Analysis
  • 3 - Sunburst Backdoor Backtracking (Function Call Tree Analysis)
  • 4 - Sunburst Backdoor Reverse Engineering - Part 1
  • 5 - Sunburst Backdoor Reverse Engineering - Part 2
  • 6 - Sunburst Backdoor Reverse Engineering - Part 3
  • 7 - Sunburst Backdoor Reverse Engineering - Part 4
  • 8 - Sunburst Backdoor Reverse Engineering - Part 5
  • 9 - VBA Macro Shellcode Analysis - Part 1
  • 10 - VBA Macro Shellcode Analysis - Part 2
  • 11 - VBA Macro Shellcode Analysis - Part 3

Reverse Engineering C/C++ Malware

  • 1 - DarkSide Ransomware Initial Analysis
  • 2 - Runtime Code Unpacking - Part 1
  • 3 - Runtime Code Unpacking - Part 2
  • 4 - Runtime Code Unpacking - Part 3
  • 5 - Dynamic API Resolve
  • 6 - Rebuilding the IAT (Import Address Table)
  • 7 - DarkSide Ransomware TTPs Dissection - Part 1
  • 8 - DarkSide Ransomware TTPs Dissection - Part 2

Malware Development

  • 1-Minimal Executables
  • 2-DarkSide Malware Techniques
  • 3-Simple Memory Sharing
  • 4-Memory Mapped Files
  • 5-Payload in Resources
  • 6-More Techniques

Bonus Content

  • One Electron to Rule Them All
  • For serious people only - MAoS - Malware Analysis on Steroids