malware often attempts to determine if security tools or reverse engineering software is running on a host as a defensive measure. The malware, if it determines that it is being analyzed, can alter its execution flow to thwart analysis.
malware checking for security software
0001-01-01
Recent Posts
Linux Persistence: Startup Scripts
2024-11-10 DFIR CTF linux persistence systemd SysV init startup script
Linux Persistence: Cron
2024-11-10 DFIR CTF linux persistence cron