Summer 2021: Theory of Static Detectors, Stanislav Rakovsky

Опубликовано: 06 Июнь 2026
на канале: CTF в Петербурге
1,125
55

A presentation from the SPbCTF Summer New Year's Meeting (https://vk.com/spbctf)

Stas discussed the usefulness of detection tools in malware analysis and CTFs. He discussed the Detect It Easy static analyzer, Yara, the Findcrypt plugin for IDA, and the use of CAPA for complex cases. Finally, he touched on recording executable traces using the Speakeasy and Qiling emulators.

Presentation → https://vk.com/doc-114366489_607589965

Basic dynamic analysis is covered in our reversal course → https://rev-kids20.forkbomb.ru/tasks

0:00 Benefits of fast static analysis
3:42 Seeing with your own eyes
8:03 DIE (Detect It Easy) and its rules
10:17 Yara and its rules
13:10 Findcrypt plugin for IDA
18:28 Complex logical signatures, Flare Capa
30:37 Analysis using emulation, Speakeasy, qiling
38:59 Questions