Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

ProcDOT, a new way of visual malware analysis

$
0
0
There are plenty of tools for behavioral malware analysis. The defacto standard ones, though, are Sysinternals’s Process Monitor (also known as Procmon) and PCAP generating network sniffers like Windump, Tcpdump, Wireshark, and the like. These “two” tools cover almost everything a malware analyst might be interested in when doing behavioral malware analysis. But there’s a major problem with these tools. Any of them works in a so to say separated or isolated way, not knowing anything from each other. Hence it’s kinda hard to get accordingly recorded activities together in one piece or picture. That’s where ProcDOT enters the stage. It fills this actual gap by merging those records together

more here..........http://www.procdot.com/index.htm

Viewing all articles
Browse latest Browse all 8064

Trending Articles