Index
A
- analysis
- analysis passes
- AND gate
- API Monitor
- assembler
- assembly code
- assembly language
- Authenticode Digital Signature Viewer
B
- base conversion
- binary
- binary reconnaissance, performing
- about / Performing binary reconnaissance
- malware, scanning on web / Scanning malware on the web
- view, obtaining with PEView / Getting a great view with PEView
- PEInsider, using / Know the ins and outs with PEInsider
- PEiD, using / Identifying with PEiD
- DeepFreeze, using / Walking on frozen terrain with DeepFreeze
- HexEditors, using / Meeting the rex of HexEditors
- string theory, digesting with strings / Digesting string theory with strings
- hashing utilities, using / Hashish, pot, and stashing with hashing tools
- XNResource, using / Getting resourceful with XNResource Editor
- Dependency Walker, using / Too much leech with Dependency Walker
- Dumpbin / Getting dumped by Dumpbin
- Binder
- Bintext
- bit masking
- Bochs
- Bochs 2.4.6
- Boolean logic
- branch lists
- BSA Buster Sandbox
- BSA Buster Sandbox Analyzer
- byte code decompilers
C
- Canari
- carry flag
- CleanMX
- code constructs, x86 disassembly
- COFF Specification
- collector types
- combinations
- Combinatorics
- command types, Windbg
- complements
- Complex Instruction Set Computer (CISC)
- Comprehensive Redline Collectors
- console-based C program
- CreateThread API
- Cuckoo
- Cuckoo Sandbox
D
- Dark Seoul
- Data Type Inspection and Display
- Debugging Tools for Windows(x86)
- decimal
- decoding
- DeepFreeze
- Deep Freeze
- default box
- Dependency Walker
- direction flag
- disassembler
- disassemblers
- disassembly, of native code
- DLoad
- do-while loop
- document analysis
- document analysis, tools
- dry run
- Dumpbin
- dynamic analysis
- dynamic in-memory function pointers table
- dynamic versioning / Static and dynamic analysis:
E
- 010 Editor
- encoding
- Entropy
- ephemeral realm
- executive summaries
- executive synopsis
- ExeInfo
F
- FakeNet
- far jump
- Fast Library Identification and Recognition Technology (FLIRT)
- FileAlyzer
- Filealyzer 2
- Firebug
- for loop
- full analysis, performing steps
- full analysis, performng steps
- function prologue
- fuzzy hash
G
H
- HashMyFiles
- HeaventoolsPEExplorer
- hexadecimal
- HexEditors
- Hex workshop
- honeypots
- HxD Editor
I
- IA32 instruction set
- IDA Pro
- IDA Pro 6.1
- IDA Pro Kernel Debugging Setup
- if-then-else loop
- immediate value
- Import Reconstructor
- ImpRec
- Indicators of Compromise (IOC)
- Indicators of Compromises (IOCs)
- inline assembler
- Inspector
- instruction sequence
- Intel microprocessor
- Intermediate Language (IL)
- Interrupt Descriptor Table (IDT)
- In The Wild (ITW)
- IRP (I/O Request Packets)
J
K
L
- lab setup
- linked lists
- Linux
- Literature and Latte
M
- Malc0de
- Malcom
- malicious web script analysis
- Maltrieve crawls
- malware
- malware analysis
- Malware Communication Analyzer
- Malware Control Monitor
- Malware Domain List
- Malware Intelligence
- Malware Memory Forensics
- Malware Risk Index (MRI)
- Malware samples crawler
- malware specific commands
- Malware URLs
- Malzilla
- MapBox
- MBR infection
- MBR integrity
- MBR reading
- mechanism, XMLHTTP
- memory addressing
- memory regions
- Microsoft Intermediate Language (MSIL) / The static library generator
- Microsoft PE
- mitigation
- mnemonic
- Modern Honey Network
- Most Significant Bit (MSB)
- MSDN via Internet
- multi-snort and honeypot sensor management
N
- natural or processor word / Binary to hexadecimal (and vice versa)
- near jump
- negative numbers
- network activity
- networking modes, VMWare
- network traffic analysis
- nibble
- notation system
- number system
O
- objects
- octal base conversion / Octal base conversion
- OfficeCat
- OfficeMalScanner
- OffVis
- OllyBone plugin
- OllyDBG 1.10/2.0
- OllyDump plugin
- On-Access Scanning
- On-Demand Scanning
- OpenIOC
- ordinals
- OR gate
- OSR Driver Loader
- overflow flag
P
- packed binaries
- PackerBreaker
- parity flag
- payload code region
- PDF Examiner
- PDF StreamDumper
- PE/Coff (common object file format) / The static library generator
- PEB (Process Environment Block)
- PEB traversal code
- PE Explorer
- PE format
- PEiD
- PEiD/ExeInfo
- PEInsider
- percent-encodeing
- permutations
- PEView
- PEView tool / The static library generator
- post infection
- ProcDOT
- ProcDot
- Process Environment Block (PEB)
- program counters
Q
- Quick Function Syntax Lookup
R
- Redline
- Redline.msi package
- Reduced Instruction Set Computer (RISC)
- registers
- relay switch
- Resource Editor
- resume flag
- return list
S
- Sandboxie
- scanning modes, PEiD
- Scrivener
- section object creation
- SEH (Structured Exception Handling) / First chance and second chance debugging
- semaphores
- short jump
- signed data type overflow conditions table
- signed numbers
- special-purpose registers, Intel microprocessor
- Standard Redline Collectors
- static library generator
- static versioning / Static and dynamic analysis:
- structs
- Structured Exception Handling (SEH)
- SWF Decompiler
- switch case
- Symbols
- syscalls
- Sysinternals Suite
- system programming, Intel chips
T
- taskkill invocation, for antivirus services
- temp file check
- thread
- TitanEngine
- tools, debugging and disassembly
- tools, fingerprinting
- tools, MISC
- tools, monitoring
- tools, user mode sandboxing
- Total Commander
- trap flag
U
- 592 UDP port
- Ultimate Packer for Executables (UPX)
- Unicode
- UPX
- URLquery
V
- VB decompiler
- VC++ debugger
- VDL (Virus Definition Language)
- VirtualBox
- VirtualKD
- VirusTotal
- Visual Studio C++ 2008 Express Edition
- VMWare
- VX Vault
W
- WDK procurement
- web
- Wepawet
- while loop
- Win32Override
- Windbg
- WINDBG/IDA PRO
- Windows help file / Getting help
- WinHex
- word (computer architecture)
X
- x86 disassembly
- XNResourceEditor
- XOR Boolean operation
- XORSearch
- XORStrings
Y
Z