Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
kh4sh3i authored Jan 8, 2022
1 parent 53c1290 commit 7dc03df
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,6 +150,23 @@ A curated list of awesome malware analysis tools and resources
* [Python 3.8.0](https://www.python.org/downloads/release/python-380/) - for ret-sync & ida module
* [yara-python](https://pypi.org/project/yara-python/) - require for ida module

### malicious Windows API
* malware tye
* downloader
* urldownloadtofile
* shellexec
* dropper
* findresource
* loadresource
* lockresource
* sizeofresource
* keylogger
* getkeystate
* getasynckeystate
* setwindowshook
* c2 server
* internetopenurla
* socket


### Tips
Expand All @@ -172,6 +189,7 @@ A curated list of awesome malware analysis tools and resources
* we can use psscan command in volatility for finding rootkit and hidden process
* .pdb file is so important for detection function name and indexing of system dll that use in malware
* in vmware we can suspend vm and copy .vmem for memory analysis. the file size is equal to whole memory size
* in ida pro use [tab] key to decompile code, use [x] key to find how many time item called in pe file



Expand Down

0 comments on commit 7dc03df

Please sign in to comment.