Check out capa v4 with:
1. support for analyzing .NET executables
2. finer grained capability detection via instruction and operand features
3. many new and updated detection rules
Blog: https://t.co/0WPjK5jKNI
Binaries: https://t.co/QPpiGZgtap
Source: https://t.co/gWbLkjgYG9
The specifics change over the years, but these days I recommend reading reporting on @malpedia website, searching for and downloading related samples on #malwarebazaar website, and setting up FLAREVM
A college student recently asked me how to learn more about malware analysis. Apart from online tutorials and expensive training, I recommend reading othersβ analyses and trying to replicate their findings. Even after all these years, I always learn something when I do that
One of the bigger initial barriers for newer analysts to break through is understanding exactly where investigative work happens. Much of it happens in the web browser and search engine rather than the SIEM or command line. 1/
Code similarity is a common and powerful way to cluster malware samples and make connections between seemingly unrelated malware families. Although it sounds simple, it is actually a complex problem and is hard to automate at scale without generating false positives. 1/