🔴 Portable Executable Files: Analyzing In-Memory versus On Disk

preview_player
Показать описание
Portable Executable files will have different characteristics, depending on whether they are loaded into memory for execution, or residing on disk. In this session, we'll take a look at some of those key differences and how they affect your analysis. We'll explore section alignment, discuss the entry point and wrap things up by looking at dumping PE files from memory, a common task when unpacking malware.

Please note, this session is a continuation of a series exploring the PE file, and you can check out the first video title "Getting Started Analyzing the Portable Executable (PE) File Format" on my YouTube channel.
Рекомендации по теме
Комментарии
Автор

Thanks for these uploads. You explain very well :)

BlueCultist
Автор

Keep up a great work sharing the knowledge, Dr Josh!

xrZt
Автор

Nice work.
Have you uploaded the Imports exports session?

aniketbose
Автор

Thank you very much for sharing these courses but is there a way to make them in 1080p (HD), some texts are quite hard to see in 720p?

xrZt
Автор

hello Josh. your web page is still working, there are things that I am studying but the page does not work. might you help me? . thank you for your work.

christiangualteros