, HITCON Pacific 2016 - The Fifth Domain: Cyber | Homeland Security

課程摘要 Course Description

In this course, you will learn advanced skill of malware analysis.

We will demonstrate how hacking skills (e,g, injection, dll sideloading, antivm, and hooking) implemented in program, and you will be able practice to do reverse engineer on real APT malware. Moreover, we will take an insight view of CUCKOO sandbox of its structure and features. With these information, you will be able to build your automatic analyzer.

Course Outline

- Advanced view of malware behavior
- Advanced view of malware reverse engineering
- cAdvanced view of malware reverse engineering

Prerequisite skills for the course

At least one year low-level programming experience(C/C++, Assembly is a plus)
Knowledge of operation system (e.g., process, thread, socket, file, memory, and system call)
Malware analysis or knowledge about malware

What students should bring

ladtop able to run VMware

Speaker Brief Introduction

Charles is an experienced researcher of network security. He has worked for Trend Mirco. Charles has a lot experience of malware analysis and reverse engineering. Charles is also an speaker of HITCON. Charles is currently works for Team T5, focus APT research , Analysis of attack event and Tracing of Attacker force.