Overview
Syllabus
Intro
About This Talk
Dynamic Analysis Intro
Process Explorer
Process Monitor
INetSim + Wireshark
Debugger Video
Static Analysis
PE Studio
010 Editor Templates
Types of Malware Armor
Detecting Virtualization Artifacts
Virtual Mac Address Detection
Emotet Anti-Virtualization - Kaspersky
IDA Script to Highlight Anti-VM Instructions
How do we bypass Anti-VM
Anti-Debugging
Timing Checks
Thread Local Storage (TLS) Callbacks
Anti-Disassembly
Two Types of Disassemblers
Breaking Your Disassembler
Interactive Disassembler
Shiva Anti-RE
Shiva RE Redefined
Veil Framework
Obfuscation
XOR
Cryptography
Top Packers
Unpacking Tools
Memory Collection
Yara - "pattern matching swiss knife"
Conclusion
References
FIDELIS