Skip to content

Materials for Windows Malware Analysis training (volume 1)

Notifications You must be signed in to change notification settings

cloudfast-bit/malware_training_vol1

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

25 Commits
 
 
 
 
 
 

Repository files navigation

malware_training_vol1

Materials for Windows Malware Analysis training (volume 1)

🚧 WARNING: work in progress! More material will be added gradually.

Content

The goal of this training it to build understanding of various common techniques used by malware. It contains elements of programming as well as reverse engineering, and introduction to some Windows internals concepts.

It also showcases how various tools (including my own) can be used to achieve particular analysis goals.

Target audience

This material would fit best to people who already have technical knowledge from surrounding areas: basics of programming and reverse engineering - yet, who want to enter into the field of Windows malware analysis.

License

Creative Commons BY License

This material is published under the Creative Commons BY License, which means:

This license lets others distribute, remix, adapt, and build upon your work, even commercially, as long as they credit you for the original creation.

Noticed an error?

If you noticed any error in this material, please report it in the Issues

Covered topics vs planned

Module 1

Slides Exercises Topic
compilation
PE
Process
WoW64
shellcode
PE loaders

Module 2

Slides Exercises Topic
Malware missions & tactics (intro)
hooking
persistence
UAC bypass
Banking trojans
RATs
Ransomware
Lateral movements

Module 3

Slides Exercises Topic
Evasion and self-defence (intro)
☐/☑ Fingerprinting
String obfuscation
Imports obfuscation
Flow obfuscation
Malware antihooking
Review of approaches to deobfuscation
Kernel-mode malware components

About

Materials for Windows Malware Analysis training (volume 1)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Assembly 95.0%
  • Batchfile 2.9%
  • C# 1.2%
  • C++ 0.9%