|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/malware-analysis-intermediate/
课程评论:没有评论
课程名称:逆向工程与恶意软件分析 - 中级课程 课程概述:如果你已经掌握了一些基础的逆向工程和恶意软件分析知识,并希望进一步提升,那么这门课程非常适合你。课程将通过大量实用的演练,从基础提升到中级水平,专注于如何解包恶意软件。许多现代恶意软件使用打包技术来抵御分析,因此本课程将提供解包恶意软件所需的知识和技能。所有所需的工具都会被介绍和解释。完成本课程后,你将掌握中级恶意软件分析的技能,为继续深入学习该领域打下基础。即使你不打算将恶意软件分析作为职业,这些逆向工程和分析的知识与技能也将对你反向软件开发有所帮助。课程内容以实用为主,避免枯燥的理论或讲座,更多是可复制的操作演练。 课程重点包括API Hooking和内存分析与追踪,以确定在恶意软件解包其有效负载到内存中后,何时以及如何转储内存。我们将使用安装有Flare-VM的Oracle虚拟机进行学习。注意,课程中使用的所有软件均为免费。 主要内容涵盖: - 恶意软件类型与术语 - 动态与静态分析 - 汇编语言基础与恶意API - API Hooking、进程劫持、内存转储 - 修复节对齐、取消映射和重新基准化转储文件 - 枚举断点与内存追踪 - Hooking常用API(如VirtualProtect、VirtualAlloc、GetProcAddress、CreateProcessInternalW等) - 使用Scylla插件转储内存 - 使用Delphi交互重构器 - 从内存查看器、进程黑客和内存映射中转储内存 - API枚举计数技巧以确定何时转储 - 自我注入与远程线程注入等 适合对象: - 参加过基础恶意软件分析课程的学生 - 寻找额外逆向软件工具与技术的黑客 - 希望进入恶意软件分析领域的逆向工程师 课程先决条件: - 具备基本的恶意软件分析或软件逆向工程知识 - 带有安装Flare-VM的Windows PC虚拟机 备注:如果你没有恶意软件分析的基础,建议先参加我的基础课程《逆向工程与恶意软件分析基础》。 现在就来报名吧,期待在课程中见到你!
If you already have some basic reverse engineering and malware analysis knowledge and wish to go further, then this course is for you. I will take you from basic to intermediate level in reverse engineering and analyzing malware. You will learn using plenty of practical walk-throughs. The focus of this course will be on how to unpack malware. Most modern malware are packed in order to defeat analysis. Hence, this Intermediate Level Course provides the required knowledge and skills to unpack malware. All the needed tools will be introduced and explained. By the end of this course, you will have the intermediate level skill in malware analysis under your belt to further your studies in this field. Even if you do not intend to take up malware analysis as a career, still the knowledge and skills gained in reverse engineering and analysis would be beneficial to you to reverse software as well.Everything is highly practical. No boring theory or lectures. More like walk-throughs which you can replicate and follow along. We will focus on API Hooking and Memory Analysis and Tracing to determine where and when to dump memory after a malware has unpacked its payload into memory. In this course, we will be using Oracle Virtual Machine installed with Flare-VM. Take note that all software used in this course are free.Topics include:Types of Malware and TerminologiesDynamic and Static AnalysisAssembly Language Refresher and Malicious APIsAPI Hooking, Process Hijacking, Dumping MemoryFixing Section Alignments, Un-mapping and Re-Basing Dumped FilesEnumerating Breakpoints and Memory TracingHooking VirtualProtect, VirtualAlloc, GetProcAddress, CreateProcessInternalW and other common API'sUsing Scylla Plugin to Dump MemoryUsing Delphi Interactive ReconstructorDumping Memory from Memory Viewer, Process Hacker and Memory MapsAPI Enumeration Count Trick To Know When to DumpSelf-Injection and Remote Thread Injectionand more...This course is suitable for:Students who has already done a basic level malware analysis courseHackers looking for additional tools and techniques to reverse softwareReverse Engineers who want to venture into malware analysisThe prerequisites:Some basics in malware analysis or software reverse engineering.Windows PC with Virtual Machine and Flare-VM Installed.Note:If you do not have the basics of malware analysis, it is recommended to take my earlier course first, which is entitled:Reverse Engineering & Malware Analysis FundamentalsGo ahead and enroll now. I will see you inside!