O'Reilly logo

Malware Forensics Field Guide for Windows Systems by James M. Aquilina, Eoghan Casey, Cameron H. Malin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Chapter 5

File Identification and Profiling

Initial Analysis of a Suspect File on a Windows System

Solutions in this chapter:

• Overview of the File Profiling Process

• Profiling a Suspicious File

• File Similarity Indexing

• File Visualization

• File Signature Identification and Classification

• Embedded Artifact Extraction

• Symbolic and Debug Information

• Embedded File Metadata

• File Obfuscation: Packing and Encryption Identification

• Embedded Artifact Extraction Revisited

• Profiling Suspect Document Files

• Profiling Suspect Portable Document Format (PDF) Files

• Profiling Suspect Microsoft (MS) Office Files

• Profiling Suspect Compiled HTML Help Files

Introduction

This chapter addresses the methodology, techniques, and tools for ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required