WCU / Cybersecurity
~/CSC 471/Class 05
CSC 471 · Class 05

Static Analysis Tools and Techniques

26 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01Two Ways to Look at Malware → 02What Static Analysis Gets You → 03The Limits: Packing and Obfuscation → 04Fingerprinting a Sample: Hashes → 05File Type Identification → 06Threat Intel: VirusTotal and Friends → 07Strings: The Cheapest Big Win → 08What to Look For in Strings → 09When Strings Are Obfuscated: FLOSS → 10Ghidra: The Free Reverse-Engineering Suite → 11Ghidra: The Decompiler → 12Ghidra: Navigating and Annotating → 13A Small Ghidra Workflow → 14Reading Capabilities from the Import Table → 15Mapping APIs to Malicious Behavior → 16Signs a Sample Is Packed → 17UPX: The Friendly Packer → 18YARA: Pattern-Matching for Malware → 19YARA Rule Anatomy → 20A Complete YARA Rule → 21Reading That Condition → 22Why YARA Scales → 23capa: Capabilities to ATT&CK → 24Putting It Together: Static Triage Checklist → 25Tie-In to Lab 1 → 26Summary →