3 - Extracting IoCs using Process Hacker
Preview unavailable
You must log in or sign up to view this lesson.
Login
Sign up
Malware Analyst Professional - Level 1
Buy now
Learn more
Course Resources
Malware Analyst Professional - Level 1 Syllabus.pdf
For serious people only - MAoS - Malware Analysis on Steroids
Module 1: Foundations & Lab Setup
Malware Analysis Lab OVA Deployment
1 - Introduction to Malware Analysis
2 - Lab Setup - Intro
3 - Lab Setup - Deploying Flare-VM
4 - Lab Setup - Connecting to INetSim
Module 2: From Source to Assembly: Building & Peeking Inside C Programs
1 - Installing Visual Studio
2 - The four stages of Development
3 - Basic C Code Example - Part 1
4 - Basic C Code Example - Part 2
example1.c
example2.c
5 - Basic Reverse Engineering - Part 1
6 - Basic Reverse Engineering - Part 2
Module 3: Peering into Portable Executables
1 - PE Structure Overview - Part 1
2 - PE Structure Overview - Part 2
3 - PE-exe vs. PE-dll
Module 4: Static Triage, Unpacking & Real-World Walk-Through
1 - Purpose and Goals of Malware Analysis
2 - Understanding Signature Names and VirusTotal Overview
3 - IoC vs. IoA
4 - Identifying File Types
5 - Calculating Hashes
6 - Strings Extraction
7 - Packing Analysis - Part 1
8 - Packing Analysis - Part 2
9 - Packing Analysis - Part 3
10 - Identifying Malicious Functionality
11 - Approaching and Reading Documentations
12 - Dissecting FlawedAmmyy - Part 1
13 - Dissecting FlawedAmmyy - Part 2
14 - Saving your RE progress to an IDB File
Module 5: Live Behaviour & Dynamic Reverse Engineering
1 - Introduction to Dynamic Analysis
2 - Working with Process Explorer
3 - Extracting IoCs using Process Hacker
4 - Working with Procmon
5 - Monitoring WinAPI Functions using API Logger
6 - Inspecting Process Command Line Parameters using CMD Watcher
7 - Debugging DLL Files with IDA Disassembler
8 - FlawedAmmyy RAT - Attack Flow PCAP Analysis Overview
9 - FlawedAmmyy RAT Dynamic Analysis
10 - FlawedAmmyy RAT Dynamic Reverse Engineering - Part 1
11 - FlawedAmmyy RAT Dynamic Reverse Engineering - Part 2
12 - Detecting FlawedAmmyy RAT with YARA
Module 6: Dissecting Malicious Documents: PDFs & Office Macros
1 - Introduction to Malicious Documents
2 - Introduction to Analyzing Malicious PDF Files
3 - Analyzing the CVE-2008-2992 PDF Exploit
4 - Analyzing VBA Macros - Introduction
5 - Analyzing VBA Macros - Shellcode Injection
Malware Lab Samples
404 Not Found - Isn't that a Mystery?!
space1 - FlawedAmmyy.zip
Malicious Documents Lab Samples.zip
YARA Rules
sodinokibi.yara
PE.yara
WannaCry.yara
UPX.yara
Cryak.yara