Timestamps:
00:00 - ambient sound
00:13 - Introduction
01:51 - Content of today's video
05:35 - Introducing dynamic analysis
25:47 - Combining static and dynamic analysis
1:08:00 - VM crashed but explaining caution with Ghidra
1:24:20 - Winding down analysis
HELLO EVERYONE! It's been a hot minute! I would say I have been out finding myself and doing my daily stretching routine, but the truth is I've just been super busy with work.
This video is a little longer than I wanted it to be, but it lays the foundations for essentially the rest of the videos on this channel. It is an introduction to the use of the debugger for malware analysis (of x32 and x64 samples), and how to interweave the use of dynamic analysis with the static tools available to us. I make use of an older, now defunct ransomware called Darkside (well, its first function lol) to show how valuable the debugger can be. I would also love to say I prepared the analysis beforehand, but it will become very obvious I filmed it live ;)
I wanted this video to be entry level, but I have a bit of a fear that I walked over some of the fundamental principles, which I hope to go back and look at the more we spend time debugging!
As always, I want to give a big shoutout to some of the people who put out regular content, and who have been inspirations for me in this field:
OALabs:
/ @oalabs
L!nkCabin
/ @lnkinfosec
For those of you wondering about my Ghidra setup (please go and downlaod the latest edition it has native dark mode) feel free to download my scripts from Github! The dark mode one might not be relevant for you anymore but the hotkey one will save you so much hassle!:
https://github.com/katechondic
More videos to come and PLEASE send me recommendations on what you'd like to see next; this channel is here to help you and not to make me feel good!