Malware
Hunting for malware
Hunting for malware can be a difficult task
Types
Many different types of malware exist
Common types include:
Persistence mechanisms
Malware needs a way to ensure that it will be run again after being killed or a computer restart
Common persistence mechanisms include:
Antivirus evasion
Malware can evade antivirus in a variety of different ways
Antivirus logs
Examples of strings to look for:
Baselines
Volatility plugins can be used:
Detection and analysis tools
Good starting points for detection include antivirus, IDS and IPS systems
Once potential malware has been identified, tool choice depends on the desired level of analysis
Last updated