Tracking APT SideWinder Domains With Regular Expressions, Whois Records and Domain Registrars
Leveraging Passive DNS to identify APT infrastructure. Building on public intelligence reports.
Advanced CyberChef techniques using Registers, Regex and Flow Control
Decoding a .hta script with CyberChef and analysing Shellcode with the SpeakEasy Emulator.
Using Ghidra Entropy Analysis to Identify a decryption function.
Demonstrating basic techniques for decoding a darkgate .vbs loader.
How to develop Yara rules for .NET Malware. Utilising IL instructions and associated bytecodes.
Introduction to dotnet configuration extraction. Leveraging RevengeRat and Python.
Practical examples and breakdowns of indicators that can be used to produce effective yara rules.