Главная
Study mode:
on
1
Definition of TLS on MSDN
2
TLS Structure Definition
3
Our Sample Program
4
Identifying TLS Callbacks in 010
5
Finding the First Callback in 010
6
TLS Callbacks in IDA Pro
7
Switching to Malcat
8
Why Do We Need to Know This?
9
How Prevalent are TLS Callbacks? Investigating with Yara
10
Expanding our Search with Yaraify
11
Investigating Recent Examples
Description:
Explore the intricacies of TLS (Thread Local Storage) callbacks in this 17-minute video tutorial. Dive into the PE file format to understand how malware authors exploit TLS callbacks as an anti-debugging technique. Learn to identify and analyze these callbacks using tools like Yara, MalCat, and 010 editor. Examine the internal structures of PE files supporting TLS callbacks, and investigate their prevalence in modern malware. Gain practical insights into cybersecurity, reverse engineering, and malware analysis through hands-on demonstrations and real-world examples.

TLS Callbacks in PE Files - Detection and Analysis

Dr Josh Stroschein
Add to list