No detailed description available for "Windows APT Warfare".
Sprache
Verlagsort
Basel/Berlin/Boston
Großbritannien
Zielgruppe
Editions-Typ
Produkt-Hinweis
Dateigröße
ISBN-13
978-1-80461-721-2 (9781804617212)
Schweitzer Klassifikation
Ma Sheng-Hao:
Sheng-Hao Ma is currently working as a threat researcher at TXOne Networks, specializing in Windows reverse engineering analysis for over 10 years. In addition, he is currently a member of CHROOT, an information security community in Taiwan. He has served as a speaker and instructor for various international conferences and organizations such as Black Hat USA, DEFCON, CODE BLUE, HITB, VXCON, HITCON, ROOTCON, Ministry of National Defense, and Ministry of Education.
Table of Contents - From Source to Binaries - The Journey of a C Program
- Process Memory - File Mapping, PE Parser, tinyLinker, and Hollowing
- Dynamic API Calling - Thread, Process, and Environment Information
- Shellcode Technique - Exported Function Parsing
- Application Loader Design
- PE Module Relocation
- PE to Shellcode - Transforming PE Files into Shellcode
- Software Packer Design
- Digital Signature - Authenticode Verification
- Reversing User Account Control and Bypassing Tricks
- Appendix - NTFS, Paths, and Symbols