Here is a list of what tools I recommend downloading:
- Virtualization software - VMware Workstation Player or VirtualBox
- This will allow us to perform analysis in a safe/isolated environment
- VMware is preferred but VirtualBox will also do the job!
- Windows 7 Image
- Most malware is written for Windows and we must provide it with the right environment for it to run correctly
- List of tools to download for this VM:
- Exeinfo
- PEID
- PEView
- PEStudio
- Resource Hacker
- HxD
- Process Monitor
- Process Hacker
- Autoruns
- RegShot
- API Monitor
- FakeNet
- Apate DNS
- WinPcap
- Wireshark
- IDAPro (idafree)
- Ollydbg
- x64Dbg
- Python
- PyCharm
- REMnux
- This is a free VM/fully loaded Linux-based toolkit with tons of amazing tools for analyzing malware
- Primarily for static analysis
- Tons of python scripts to run against malware
- Especially awesome for deobfuscation, malicious PS/VB scripts, shellcode, etc...
- SIFT Workstation
- This is a free VM/fully loaded Linux-based toolkit with tons of amazing tools for forensics
- Can be used to analyze malware forensically
- Identify artifacts that malware leaves on disk
- Analyze evasive fileless malware that doesn't touch disk
- Easily spot code injection, API hooks, and rootkits
- Kali Linux
- This is a free VM/fully loaded Linux-based toolkit with tons of amazing tools for penetration testing
- Recreate compromises, create and deploy payloads
- Think like the adversary
SOCIAL SHARE CARD GENERATOR