DCART - Decoupled Components for Automated Ransomware Testing
Hack In The Box Security Conference via YouTube
Overview
Syllabus
Introduction
Overview
Ransomware
Ransomware Modification Patterns
Behavioral Ransomware Detection
Behavioral Ransomware Testing
Limitations
Event Traces
Event Listener
Event Race Format
File Access Auditing
MiniFilter Driver
MiniFilter Framework
Analysis Objectives
Entropy
File Header
File Rename
Demo
Log File
Log File Analysis
Automation
Limitations of Automation
Taught by
Hack In The Box Security Conference