Deep Dive into OS Internals with Windbg
Malware and OS Internals
[ 01 ] Reversing Windows Internals
[ 02 ] Portable Executable Anatomy
[ 03 ] Data Directories of Interest
[ 04 ] Import Directory
[ 05 ] Import Address Table
[ 06 ] Export Directory
[ 07 ] Manual Walkthrough of Export Directory
[ 08 ] Process Environment Block
[ 09 ] Different methods to locate the PEB
[ 10 ] Understanding an Example Shellcode
[ 11 ] Using _PEB_LDR_DATA
[ 12 ] Using _LDR_DATA_TABLE_ENTRY
[ 13 ] Practical Example with Rustock.B Rootkit
Malware and OS Internals
[ 01 ] Reversing Windows Internals
[ 02 ] Portable Executable Anatomy
[ 03 ] Data Directories of Interest
[ 04 ] Import Directory
[ 05 ] Import Address Table
[ 06 ] Export Directory
[ 07 ] Manual Walkthrough of Export Directory
[ 08 ] Process Environment Block
[ 09 ] Different methods to locate the PEB
[ 10 ] Understanding an Example Shellcode
[ 11 ] Using _PEB_LDR_DATA
[ 12 ] Using _LDR_DATA_TABLE_ENTRY
[ 13 ] Practical Example with Rustock.B Rootkit
👍3❤2🔥1
TinyTurla-NG in-depth tooling and command and control analysis
https://blog.talosintelligence.com/tinyturla-ng-tooling-and-c2/
#c2
https://blog.talosintelligence.com/tinyturla-ng-tooling-and-c2/
#c2
👍3
A Deep Dive Into Exploiting Windows Thread Pools
https://urien.gitbook.io/diago-lima/a-deep-dive-into-exploiting-windows-thread-pools
#window_internals , #exploitation
https://urien.gitbook.io/diago-lima/a-deep-dive-into-exploiting-windows-thread-pools
#window_internals , #exploitation
👍2🔥1
Static Analysis Automation for Hunting Vulnerable Kernel Drivers
https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html
Slides 👇
https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html
Slides 👇
👍2
Unpacking RC4 Encrypted Malware - REvil ransomware
Link
#malware_analysis
#reverse
---------
@islemolecule_source
Link
#malware_analysis
#reverse
---------
@islemolecule_source
❤5
❤2
A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass
Link
#edr
#malware_dev
------
@islemolecule_source
Link
#edr
#malware_dev
------
@islemolecule_source
❤3
IRC Botnet sinkhole:full reverse process
Link
#malware_analysis
#reverse
---------
@islemolecule_source
Link
#malware_analysis
#reverse
---------
@islemolecule_source
❤2
🔥1
Keylogging in the Windows kernel with undocumented data structures
Link
#malware_dev
------
@islemolecule_source
Link
#malware_dev
------
@islemolecule_source
🔥3
Xeno RAT: A New Remote Access Trojan with Advance Capabilities
Link
#malware_analysis
------
@islemolecule_source
Link
#malware_analysis
------
@islemolecule_source
CYFIRMA
Xeno RAT: A New Remote Access Trojan with Advance Capabilities - CYFIRMA
EXECUTIVE SUMMARY At CYFIRMA, we are dedicated to providing current insights into prevalent threats and strategies utilized by malicious entities,...
👍2