Files
securedorg.github.io/retools.md
2017-06-30 15:26:37 -07:00

3.8 KiB

layout, permalink, title
layout permalink title
default /RE101/section3/ RE Tools

Go Back to Reverse Engineering Malware 101

Section 3: Reverse Engineering (RE) Tools

Disassemblers


Debuggers


Decompilers


Information Gathering

Helpful Websites


Support


Tools Used in the Workshop

Disassembler: IdaFree

alt text

  • Visual Modes
    • Graph Mode - control flow diagram
    • Text Mode - default view of disassembled code
  • Command Cheatsheet
  • Common Commands
Action Command
Jump to xref to operand X
Jump to address G
Enter comment Shift+;

Debugger: x64dbg

alt text

Common Commands

Action Command
Enter comment ;
BreakPoint F2
Step into F7
Step over F8
Run F9
Edit Instruction Space

Keyboard Layout for IdaFree and x64dbg

alt text


Information Gathering: CFF Explorer

  • Parses the PE headers
  • Explores Resources
  • Unpacks UPX

alt text

Information Gathering: Sysinternals Suite

  • advanced system utilities
  • ProcMon - Monitor processes/thread, files system, network, and registry activity on the system
  • ProcExp - Monitor processes running on the system

alt text

Section 2.1 <- Back | Next -> Section 4