What happened, how did it happen, and what can the software tell us about it? This book develops the understanding needed to investigate compiled programs and connect their behavior to security incidents. Follow unfamiliar executables from an initial inspection through static and dynamic analysis, system interactions, vulnerabilities and concealed code, then combine the findings with incomplete incident evidence. Across eight substantial parts, Ghidra and GDB become tools for answering concrete questions. Assembly, executable formats and other foundations enter where they unlock a discovery. Explanatory prose carries the argument, supported by code, disassembly, diagrams and optional runnable examples. The goal is to find hidden capabilities, understand what activates them and establish what the evidence supports—from the first suspicious file to a technical account another investigator can assess.
Open book cover →Unfold book
Unfold part
- 1.What did we find on this server?Free preview
- 2.A harmless name tells us very littleFree preview
- 3.The first clues inside the fileFree preview