Book description
A computer forensics "how-to" for fighting malicious code and analyzing incidents
With our ever-increasing reliance on computers comes an ever-growing risk of malware. Security professionals will find plenty of solutions in this book to the problems posed by viruses, Trojan horses, worms, spyware, rootkits, adware, and other invasive software. Written by well-known malware experts, this guide reveals solutions to numerous problems and includes a DVD of custom programs and tools that illustrate the concepts, enhancing your skills.
Security professionals face a constant battle against malicious software; this practical manual will improve your analytical capabilities and provide dozens of valuable and innovative solutions
Covers classifying malware, packing and unpacking, dynamic malware analysis, decoding and decrypting, rootkit detection, memory forensics, open source malware research, and much more
Includes generous amounts of source code in C, Python, and Perl to extend your favorite tools or build new ones, and custom programs on the DVD to demonstrate the solutions
Malware Analyst's Cookbook is indispensible to IT security administrators, incident responders, forensic analysts, and malware researchers.
Table of contents
- Copyright
- Credits
- About the Authors
- Acknowledgments
- Introduction
- On The Book's DVD
- 1. Anonymizing Your Activities
- 2. Honeypots
- 3. Malware Classification
- 4. Sandboxes and Multi-AV Scanners
-
5. Researching Domains and IP Addresses
-
5.1. Researching Suspicious Domains
- 5.1.1. WHOIS on Linux and Mac OS X
- 5.1.2. Cygwin on Windows
- 5.1.3. WHOIS with Sysinternals on Windows
- 5.1.4. Additional Tools for Windows
- 5.1.5. Web Tools
- 5.1.6. The Host Command (Unix only)
- 5.1.7. The Dig Command (Unix only)
- 5.1.8. The nslookup command
- 5.1.9. The Ping Command
- 5.1.10. Web-Based Tools
- 5.2. Researching IP Addresses
- 5.3. Researching with Passive DNS and Other Tools
- 5.4. Fast Flux Domains
- 5.5. Geo-Mapping IP Addresses
-
5.1. Researching Suspicious Domains
- 6. Documents, Shellcode, and URLs
- 7. Malware Labs
- 8. Automation
- 9. Dynamic Analysis
- 10. Malware Forensics
- 11. Debugging Malware
- 12. De-obfuscation
- 13. Working with DLLs
- 14. Kernel Debugging
- 15. Memory Forensics with Volatility
- 16. Memory Forensics: Code Injection and Extraction
- 17. Memory Forensics: Rootkits
- 18. Memory Forensics: Network and Registry
Product information
- Title: Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code
- Author(s):
- Release date: November 2010
- Publisher(s): Wiley
- ISBN: 9780470613030
You might also like
book
Hacking Exposed Malware & Rootkits: Security Secrets and Solutions, Second Edition, 2nd Edition
Arm yourself for the escalating war against malware and rootkits Thwart debilitating cyber-attacks and dramatically improve …
book
Ransomware Revealed: A Beginner’s Guide to Protecting and Recovering from Ransomware Attacks
Know how to mitigate and handle ransomware attacks via the essential cybersecurity training in this book …
book
Malware Forensics Field Guide for Linux Systems
Malware Forensics Field Guide for Linux Systems is a handy reference that shows students the essential …
book
Advanced Malware Analysis
A one-of-a-kind guide to setting up a malware research lab, using cutting-edge analysis tools, and reporting …