A concise reference for incident responders, forensic analysts and penetration testers: essential tools, indicators of compromise, static and dynamic malware analysis, YARA tips and sandbox workflows. Printable, and meant to sit beside you while you work.
What is inside
- Tooling — The analysis tools worth knowing and when each one earns its place.
- Indicators of compromise — What to look for, and what a false positive usually looks like.
- Static analysis — Examining a sample without running it.
- Dynamic analysis — Sandbox workflow and what to record while it runs.
- YARA — Writing rules that match what you actually mean.
