WCU / Cybersecurity
~/CSC 471/Class 05
CSC 471 · Class 05

Static Analysis Tools and Techniques

26 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01Two Ways to Look at Malware 02What Static Analysis Gets You 03The Limits: Packing and Obfuscation 04Fingerprinting a Sample: Hashes 05File Type Identification 06Threat Intel: VirusTotal and Friends 07Strings: The Cheapest Big Win 08What to Look For in Strings 09When Strings Are Obfuscated: FLOSS 10Ghidra: The Free Reverse-Engineering Suite 11Ghidra: The Decompiler 12Ghidra: Navigating and Annotating 13A Small Ghidra Workflow 14Reading Capabilities from the Import Table 15Mapping APIs to Malicious Behavior 16Signs a Sample Is Packed 17UPX: The Friendly Packer 18YARA: Pattern-Matching for Malware 19YARA Rule Anatomy 20A Complete YARA Rule 21Reading That Condition 22Why YARA Scales 23capa: Capabilities to ATT&CK 24Putting It Together: Static Triage Checklist 25Tie-In to Lab 1 26Summary