Practical Malware Analysis

Practical Malware Analysis

Authored by Michael Sikorski
Malware Analysis 2 views 0 downloads 2012
Published 2012
Language eng
Publisher No Starch Press
'Practical Malware Analysis' by Michael Sikorski is the industry-standard textbook for analyzing, reversing, and eradicating malicious software on Windows systems. Combining practical lab exercises with deep technical theory, this guide equips incident responders and security analysts with the skills to dissect modern malware.

The book covers safe lab configuration, basic static and dynamic triage, x86 assembly language disassembly, IDA Pro workflows, live debugging with OllyDbg/x64dbg, kernel-level rootkit inspection, covert process injection, and custom packer unpacking. Real-world malware specimens illustrate every concept.

Crucial for SOC analysts, digital forensic investigators, reverse engineers, and malware researchers tasked with responding to advanced persistent threats.
Contents at a Glance
Chapter 1: Basic Static Analysis Techniques (Strings, Hashes, PE Headers)
Chapter 2: Malware Analysis in Virtual Machine Environments
Chapter 3: Basic Dynamic Analysis Techniques (Regshot, Process Hacker, Wireshark)
Chapter 4: A Crash Course in x86 Assembly Disassembly
Chapter 5: IDA Pro: Advanced Disassembly and Control Flow Analysis
Chapter 6: Recognizing C Code Constructs in Assembly
Chapter 7: Analyzing Malicious Windows Programs and Win32 APIs
Chapter 8: Debugging with OllyDbg and x64dbg
Chapter 9: Kernel Debugging with WinDbg and Rootkit Analysis
Chapter 10: Malware Behavior: Covert Launching, Process Injection, and Hooking
Chapter 11: Data Encoding: XOR, Base64, and Cryptographic Algorithms
Chapter 12: Anti-Reverse Engineering: Anti-Disassembly Techniques
Chapter 13: Anti-Debugging: Detecting Debuggers and Exceptions
Chapter 14: Anti-Virtual Machine Techniques and Evasion
Chapter 15: Unpacking Packed Malware (UPX, Custom Packers)
Index & Further Reading