04/08/2025
āĻŽā§āϝāĻžāϞāĻā§ā§āϝāĻžāϰ āĻ
ā§āϝāĻžāύāĻžāϞāĻžāĻāϏāĻŋāϏ āϞāĻžāϰā§āύāĻŋāĻ āϰā§āĻĄāĻŽā§āϝāĻžāĻĒ (āĻŦāĻžāĻāϞāĻž)
đš ā§§āĻŽ āĻŽāĻžāϏ: āĻŦā§āϏāĻŋāĻ āĻ āϏā§āĻā§āϝāĻžāĻāĻŋāĻ āĻ
ā§āϝāĻžāύāĻžāϞāĻžāĻāϏāĻŋāϏ
â
āϞāĻā§āώā§āϝ: āύāĻŋāϰāĻžāĻĒāĻĻ āϞā§āϝāĻžāĻŦ āϏā§āĻāĻāĻĒ āĻ āĻŽā§āϝāĻžāϞāĻā§ā§āϝāĻžāϰ āĻĢāĻžāĻāϞ āϏā§āĻā§āϰāĻžāĻāĻāĻžāϰ āĻŦā§āĻāĻž
đ āĻļā§āĻāĻžāϰ āĻŦāĻŋāώā§āĻ
VirtualBox/VMware āĻĻāĻŋā§ā§ āϏā§āϝāĻžāύā§āĻĄāĻŦāĻā§āϏ āϤā§āϰāĻŋ
Windows Internals (Process, Services, Registry)
Assembly Language āĻŦā§āϏāĻŋāĻ (x86/x64)
Static Analysis Tools āĻŦā§āϝāĻŦāĻšāĻžāϰ
đ ī¸ āĻā§āϞāϏāĻ
VirtualBox āĻŦāĻž VMware
PEiD
Strings
PEview
---
đš ⧍⧠āĻŽāĻžāϏ: āĻĄāĻžāĻāύāĻžāĻŽāĻŋāĻ āĻ
ā§āϝāĻžāύāĻžāϞāĻžāĻāϏāĻŋāϏ
â
āϞāĻā§āώā§āϝ: āĻŽā§āϝāĻžāϞāĻā§ā§āϝāĻžāϰā§āϰ āĻāĻāϰāĻŖ āĻĒāϰā§āϝāĻŦā§āĻā§āώāĻŖ āĻ āϞāĻ āϤā§āϰāĻŋ
đ āĻļā§āĻāĻžāϰ āĻŦāĻŋāώā§āĻ
Process Monitoring
File System āĻ Registry Changes
Network Traffic Analysis
Sandbox Analysis
đ ī¸ āĻā§āϞāϏāĻ
Process Monitor
Process Explorer
Wireshark
Regshot
Cuckoo Sandbox
---
đš ā§Šā§ āĻŽāĻžāϏ: āĻ
ā§āϝāĻžāĻĄāĻāĻžāύā§āϏāĻĄ āĻ
ā§āϝāĻžāύāĻžāϞāĻžāĻāϏāĻŋāϏ āĻ āϰāĻŋāĻāĻžāϰā§āϏ āĻāĻā§āĻāĻŋāύāĻŋā§āĻžāϰāĻŋāĻ
â
āϞāĻā§āώā§āϝ: āĻĄāĻŋāĻŦāĻžāĻāĻŋāĻ, Payload Extraction, Anti-Debugging āĻŦāĻžāĻāĻĒāĻžāϏ
đ āĻļā§āĻāĻžāϰ āĻŦāĻŋāώā§āĻ
OllyDbg/x64dbg āĻĻāĻŋā§ā§ āĻā§āĻĄ āϏā§āĻā§āĻĒ-āĻŦāĻžāĻ-āϏā§āĻā§āĻĒ āϰāĻžāύ āĻāϰāĻž
IDA Pro āĻŦāĻž Ghidra āĻĻāĻŋā§ā§ Disassembly
Rootkit āĻ Kernel-level Malware āĻŦā§āĻāĻž
YARA Rules āϞā§āĻāĻž āĻāĻŦāĻ IOC āϤā§āϰāĻŋ
đ ī¸ āĻā§āϞāϏāĻ
x64dbg
OllyDbg
IDA Free
Ghidra
YARA