Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

anti-analysis

0001-01-01 anti-analysis malware

Malware may implement features to make analysis more difficult. These are known as anti-analysis techniques.


Links to this note

  • anti-debugger
  • Main Index
  • defendingagainstmaliciousshims-pierce2015
  • knockknock-osxreverser2021
  • process masquerading
  • rootkits hiding CPU usage
  • most observed sshd backdoors shared the same rough feature set
  • cesare1999
  • Payload Encryption
  • Azazel rootkit
  • Compiler Options - Anti-Reversing
  • crypter
  • dynamic obfuscation
  • function name randomization
  • hidden files and directories
  • homoglyph obfuscation
  • honeypot detection
  • IP Address Obfuscation
  • IPfuscation
  • Main Index - A
  • malware blending in with the system
  • Manual Analysis
  • matryoshka obfuscation
  • MemFiles
  • Skidmap malware
  • stack strings
  • string encryption
  • string hashing
  • string obfuscation
  • timestomping
  • unset HISTFILE
  • userland exec
  • Virtual Machine Detection

Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.