WCU / Cybersecurity
Home
CSC 471
CSC 472
Search
/
~
/
CSC 471
/
Class 05
CSC 471 · Class 05
Static Analysis Tools and Techniques
26 knowledge points. Work through them in order, or jump to any topic.
//
Knowledge Points
01
Two Ways to Look at Malware
→
02
What Static Analysis Gets You
→
03
The Limits: Packing and Obfuscation
→
04
Fingerprinting a Sample: Hashes
→
05
File Type Identification
→
06
Threat Intel: VirusTotal and Friends
→
07
Strings: The Cheapest Big Win
→
08
What to Look For in Strings
→
09
When Strings Are Obfuscated: FLOSS
→
10
Ghidra: The Free Reverse-Engineering Suite
→
11
Ghidra: The Decompiler
→
12
Ghidra: Navigating and Annotating
→
13
A Small Ghidra Workflow
→
14
Reading Capabilities from the Import Table
→
15
Mapping APIs to Malicious Behavior
→
16
Signs a Sample Is Packed
→
17
UPX: The Friendly Packer
→
18
YARA: Pattern-Matching for Malware
→
19
YARA Rule Anatomy
→
20
A Complete YARA Rule
→
21
Reading That Condition
→
22
Why YARA Scales
→
23
capa: Capabilities to ATT&CK
→
24
Putting It Together: Static Triage Checklist
→
25
Tie-In to Lab 1
→
26
Summary
→