Overview
Explore malware analysis techniques and sandbox evasion strategies in this 41-minute conference talk from Derbycon 2015. Dive into the world of unknown samples, feature vectors, and behavior summaries as Mike Schladt demonstrates how to create effective spreadsheets for analysis. Learn about Cuckoo sandbox reports, family plotting, and archetype identification. Discover methods for pruning vectors, retrieving data, and generating meaningful outputs. Gain insights into best practices for malware detection and analysis, including practical examples and next steps for implementation. Engage with a quiz to test your understanding and participate in a Q&A session to deepen your knowledge of advanced malware analysis techniques.
Syllabus
Intro
About Me
Disclaimer
My Wife
Agenda
Objectives
Sandboxing
Starting with unknown samples
Creating an awesome spreadsheet
Cuckoo sandbox reports
Feature Vectors
Feature Vector Duck Pie
Behavior Summary
Project Overview
Pruning Vector
Retrieve Vectors
Family Plot
Family Group Plot
Family Group Tubing
Archetypes
Tight Features
Best Guest Up High
Output
Quiz
Scan
Example
Next Steps
Questions