From this video you will learn how concepts from CPU and process emulator were used by AV products to emulate kernel mode rootkits as well.
#malware #antimalware #cpu #rootkit #emulator #detection #analysis
#cyberdefense #cybersecurity
#cyber #cyberllama #cyberllamatalks
00:00 Intro
00:26 Mapping Rootkit to emulator
01:38 Kernel structures to emulate
03:18 Modules and tables to emulate
04:33 Emulation loop
05:28 IRP emulation
8:32 Suspicious Code detection
10:28 Summary