MM#01 - Behind the Scenes - How to Capture Malicious Activity with Process Monitor!

preview_player
Показать описание
Here it is, the inaugural Malware Monday Episode 01 - Analyzing Amadey activity with ProcMon. This video is a behind-the-scenes look at how I captured the artifacts. Make sure to join the live stream as I discuss how to analyze this data on Friday! You can find links to join the live stream as well as the artifacts for analysis at:

Cybersecurity, reverse engineering, malware analysis and ethical hacking content!
🌶️ YouTube 👉🏻 Like, Comment & Subscribe!
Рекомендации по теме
Комментарии
Автор

Looking forward to the new series and learning from you. Thanks!

Andrew-petrus
Автор

Thank you so, so, so much! Really enjoyed the video and look forward to more Malware Mondays. One thing I'd like to call your attention to is the background music made it a bit more difficult to hear the instruction.

ikfkqnz
Автор

Great video! ProcMon is such an amazing tool. BTW, love the new intro you've been putting on the last few videos. Very cool

KenPryor
Автор

Title 01- Using Process Monitor (Procmon) to investigate malicious system activity.
Using FLARE-VM + before doing dynamic analysis, make sure VM is NOT CONNECTED to the Internet (= set network adapter to host-only mode, so the network traffic will not escape the VM)
To cut down amount of noise, ONLY START PROCMON right before execute the malware
Open Process Explorer, so can monitor process behavior in real time, but Process Montor provide mỏe in-depth analysis
Next launch FakeNet-NG -> it will provide a number of simulated network service (~ DNS resolution, HTTP requests)
NEED adminstrative privilege command prompt

izeo
Автор

Thank you, Dr. I was looking for a video on Windows sysinternal. Please do more videos on sysinyernal

yonite
Автор

Is it possible to get events of VirtualAlloc and VirtualProtect through ProcMon?

sachinoliver
Автор

What is the password to unzip the pcap? Pls

diegomed
Автор

great, but the bk-music is distracting and annoying at the same time, who really needs that ?

guruware