Skip to Content
Malware Forensics Field Guide for Windows Systems
book

Malware Forensics Field Guide for Windows Systems

by Cameron H. Malin, Eoghan Casey, James M. Aquilina
May 2012
Intermediate to advanced
560 pages
12h 55m
English
Syngress
Content preview from Malware Forensics Field Guide for Windows Systems

Chapter 5

File Identification and Profiling

Initial Analysis of a Suspect File on a Windows System

Solutions in this chapter:

• Overview of the File Profiling Process

• Profiling a Suspicious File

• File Similarity Indexing

• File Visualization

• File Signature Identification and Classification

• Embedded Artifact Extraction

• Symbolic and Debug Information

• Embedded File Metadata

• File Obfuscation: Packing and Encryption Identification

• Embedded Artifact Extraction Revisited

• Profiling Suspect Document Files

• Profiling Suspect Portable Document Format (PDF) Files

• Profiling Suspect Microsoft (MS) Office Files

• Profiling Suspect Compiled HTML Help Files

Introduction

This chapter addresses the methodology, techniques, and tools for ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Malware Forensics

Malware Forensics

Eoghan Casey, Cameron H. Malin, James M. Aquilina
Malware Forensics Field Guide for Linux Systems

Malware Forensics Field Guide for Linux Systems

Eoghan Casey, Cameron H. Malin, James M. Aquilina

Publisher Resources

ISBN: 9781597494724