File Identification and Profiling
Initial Analysis of a Suspect File on a Linux System
Solutions in this Chapter:
• Overview of the File Profiling Process
• Working with Linux Executable Files
• Profiling a Suspicious File
• File Similarity Indexing
• File Visualization
• File Signature Identification and Classification
• Embedded Artifact Extraction
• Symbolic and Debug Information
• Embedded File Metadata
• File Obfuscation: Packing and Encryption Identification
• Embedded Artifact Extraction Revisited
• Executable and Linkable Format (ELF)
• Profiling Suspect Document Files
• Profiling Adobe Portable Document Format (PDF) Files
• Profiling Microsoft (MS) Office Files
Introduction
This chapter addresses the methodology, techniques, ...
Get Malware Forensics Field Guide for Linux Systems now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.