|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/reverse-engineering-deep-dive/
课程评论:没有评论
课程名称:逆向工程深入探讨 课程概述:本课程旨在系统地引导学生深入了解实际恶意软件的静态和动态分析的复杂部分。我们不会仅仅表面上广泛地覆盖主题,而是将样本带来的各种问题作为深入学习的机会。在调查过程中,我们将涉及众多相关主题。学生将编写Python去混淆脚本,将汇编算法嵌入C++库,分析隐写术技巧和加密缺陷等许多内容。课程非常实用,练习已针对更新的Windows 8.1操作系统进行了设计和测试。学习本课程不需要任何先决条件,只需具备一个Windows虚拟机和学习的意愿。课程中讨论的所有第三方工具均可在网上免费获取。熟悉Python和C/C++将对学习有帮助,因为这两种语言在各个模块中被广泛使用。 评估:为了充分利用本课程,我推荐完成所有作业。所有6个实践作业均可使用课程中的信息来解决。我们不提供解决方案,因为我相信通过实践学习效果最佳。课程结束时,我希望每位学生将自己的作业方案提交上来。如果在学习过程中遇到困难或有任何问题,我随时乐意帮助。可以直接联系我或通过问答部分寻求帮助。欢迎在问答部分与其他学生讨论作业,但请勿在线发布解决方案或答案。
This course is logically designed to guide students gradually through some of the complicated parts of static and dynamic analysis of real-world malware. Instead of covering the topic broadly on the surface, we will take all the ramifications presented to us by the sample and use them as opportunities to deep dive and learn.During our investigations we will cover a lot of adjacent topics. We will write Python deobfuscation scripts, embed assembly algorithms into C++ libraries, analyse steganography tricks and encryption flaws and many many more.The course is very practical and exercises have been designed and tested for an updated Windows 8.1 operating system. There are no pre-requisites for this class other that a Windows virtual machine and the will to learn. All the 3rd party tools discussed are freely available online. Familiarity with Python and C/C++ is beneficial because these two are heavily used throughout the modules.Assessments:To get the most out of this course, I recommend doing all the assignments. All the 6 practical assignments can be solved using information from the course. There are no solutions provided, because I believe we learn best by doing. I'm asking each student to send in their solutions to all the exercises at the end of the course. If you stumble or have any questions, I'm more than happy to help anytime. Reach out directly or via the Q & A section.Feel free to discuss the assignments with other students in the Q & A section, but please don't post the solutions or answers online.