1、Malware Magic:Revealing Intel Leads Without Reverse EngineeringWhoami?Previous experienceWeb app vulnerability assessmentBinary analysis researchAndroid forensicsPrototype dev in Python,C,C+Author of Open Security Training IDA Debugging mini classCreator of multiple intro to reverse engineering work
2、shops for HS STEM and Womens Society of Cyberjutsu(WSC)Low level systems internals nerdChristina JohnsPrincipal Malware AnalystRed Canarybitmaize.bsky.socialAgenda 1.Reverse engineering-not a requirement2.Skills to prioritize3.Tools and resources4.Malware case studiesReverse engineering-not a requir
3、ementSo you want to do malware analysis?Common recommendations:C/C+codingOperating system internalsComputer architectureAssembly CodeThis is really great advice for reverse engineeringMalware analysis!=reverse engineeringMalware analysisReverse engineeringMalware reverse engineeringStatic analysis t
4、oolsSandboxYARA matchesBackwards compatibilityVulnerability analysisGoals for malware analysis varyIs this something that already has a name?Is it malicious?IOC extractionEstimate of capabilitiesTell me everything it could possibly doMost of these things dont necessarily require reverse engineeringW
5、ays to accomplish these goalsIOCsSandbox Config extractors Static analysis toolsCapability estimation Sandbox ATT&CK mappingsStatic analysis toolsFamily identificationOverlaps in IOC/capability data File metadata overlapsRE knowledge is not a silver bulletFocusNeed to know what you are looking for i
6、n the binaryVarietyNot all malware is compiled codeEfficiencyTools can assist with IOCs,family identification and an estimate of capabilitiesProgramming languages associated with Red Canarys top 10 threats1.SocGholish(JavaScript)2.Impacket(PowerShell)3.Scarlet Goldfinch(JavaScript)4.Mimikatz(C)5.Amb