Part 4

Reverse Engineering for Security Investigations

Trace the program’s interaction with the system

Follow activity across processes, libraries, files, permissions and network connections. Investigate persistence, process injection, privilege boundaries and communication with other components. Explain how local mechanisms fit into a larger intrusion—and what additional evidence is needed to connect them.

0 Chapter

HackerBoost

Subscriptions coming soon

We are preparing the HackerBoost library. You can create an account now; subscriptions will open later.

Sign in to read the first three chapters of the first part for free.

Contents