Text
Cuckoo malware analysis: analyze malware using cuckoo sandbox
Cuckoo Sandbox is a leading open source automated malware analysis system. This means that you can throw any suspicious file at it and, in a matter of seconds, Cuckoo will provide you with some detailed results outlining what said file did when executed inside an isolated environment.
Cuckoo Malware Analysis will cover basic theories in sandboxing, automating malware analysis, and how to prepare a safe environment lab for malware analysis. You will get acquainted with Cuckoo Sandbox architecture and learn how to install Cuckoo Sandbox, troubleshoot the problems after installation, submit malware samples, and also analyze PDF files, URLs, and binary files. This book also covers memory forensics – using the memory dump feature, additional memory forensics using Volatility, viewing result analyses using the Cuckoo analysis package, and analyzing APT attacks using Cuckoo Sandbox, Volatility, and Yara.
Table of contents
1. Getting Started with Automated Malware Analysis using Cuckoo Sandbox
2. Using Cuckoo Sandbox to Analyze a Sample Malware
3. Analyzing the Output of Cuckoo Sandbox
4. Reporting with Cuckoo Sandbox
5. Tips and Tricks for Cuckoo Sandbox
Index
No other version available