Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Automated Extraction of Configuration and Payloads from Sophisticated Malware

44CON Information Security Conference via YouTube

Overview

Explore an innovative solution for automated malware analysis in this 42-minute conference talk from the 44CON Information Security Conference. Delve into the challenges of reverse engineering sophisticated malware samples and discover CAPE (Automated Extraction of Configuration and Payloads), an open-source platform designed to streamline the process. Learn how CAPE combines various techniques and tools to extract payloads, configurations, and indicators from complex malware families, particularly those associated with nation-state actors. Gain insights into the system's capabilities, its potential to revolutionize threat intelligence, and how it can be expanded to combat increasingly sophisticated malware. Understand the technical aspects of malware obfuscation, manual analysis approaches, and automated techniques employed by CAPE. Witness a walkthrough demonstration of the platform and explore its extensibility features, including how to create custom packages and utilize the CAPE API for config parsing.

Syllabus

Intro
A bit of background..
Malware Obfuscation
Manual Approach
Automated Analysis
Techniques & tools from manual analysis
Debugger
Dumper
Import Reconstruction
CAPE Walkthrough Demo Plug
DLL Side loading
Extracting/loading modules in memory
Process injection: Shellcode or DLL
Process Hollowing (RunPE)
Executable Packers/Custom Crypto
Current Coverage
CAPE Extensibility
How do you make a package? CAPE API
Config Parsing
CAPE Resources

Taught by

44CON Information Security Conference

Reviews

Start your review of Automated Extraction of Configuration and Payloads from Sophisticated Malware

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.