Part 1

Reverse Engineering for Security Investigations

Investigate an unfamiliar executable

Start with a suspicious program found during an incident. Establish what it can do, what deserves attention and which questions require deeper analysis. Introduce executable formats, imports and assembly through discoveries about the specimen, while distinguishing suspicious features from evidence of malicious behavior.

3 Chapter

HackerBoost

Subscriptions coming soon

We are preparing the HackerBoost library. You can create an account now; subscriptions will open later.

Sign in to read the first three chapters of the first part for free.

Contents

  1. 1What did we find on this server?Free preview
  2. 2A harmless name tells us very littleFree preview
  3. 3The first clues inside the fileFree preview