MALWARE ANALYSIS // How to get started with John Hammond

David Bombal · Beginner ·🔐 Cybersecurity ·4y ago
The amazing John Hammond tells us how to get into Malware Analysis. Learn about jobs, what you need to know and much more! Menu: 0:00 ▶️ Pretty sketchy stuff! 0:37 ▶️ Welcome John Hammond 0:53 ▶️ Don't divide cyber in your mind 2:00 ▶️ John's day job 3:17 ▶️ Hacker's crafty methods 4:02 ▶️ Will AI take jobs away? 4:55 ▶️ How do I become like you? 5:35 ▶️ Windows is very important 6:12 ▶️ Malware vs CTFs 6:32 ▶️ Is Malware mainly on Windows systems? 7:28 ▶️ Always comes back to the same thing 8:50 ▶️ Practical Example 9:29 ▶️ John's setup 11:42 ▶️ Python malware example 12:50 ▶️ Malware code 1…
Watch on YouTube ↗ (saves to browser)

Chapters (47)

Pretty sketchy stuff!
0:37 Welcome John Hammond
0:53 Don't divide cyber in your mind
2:00 John's day job
3:17 Hacker's crafty methods
4:02 Will AI take jobs away?
4:55 How do I become like you?
5:35 Windows is very important
6:12 Malware vs CTFs
6:32 Is Malware mainly on Windows systems?
7:28 Always comes back to the same thing
8:50 Practical Example
9:29 John's setup
11:42 Python malware example
12:50 Malware code
15:50 Bad guys can sell this information
16:30 But this is in the clear?
17:14 Obfuscated version
18:28 Real world? Don't want to touch disk
19:50 How do I find this stuff
20:58 Weird Spam SMS messages
21:30 Real World: Finding malware
23:42 John's real world company example
24:20 Real world logic to find malware
25:23 Detectors
25:48 Hunting malware
26:25 Use your eyes - don't trust an automated systems
27:15 Input from other systems
27:49 How do I become like you?
28:00 What kind of skills would you look for in a person to get a job
29:24 Look at malware sites
30:15 Build out a library
30:38 David pushes John for a job on LinkedIn
33:05 How did John get his job?
33:30 Use social media
34:31 How John got his first job
35:55 It's who you know, not what you know
36:30 How John got his current job
38:19 Would you hire someone with certs; or someone you know
39:50 Windows bat script example
45:08 Which languages does John know
45:38 How do you know if it is good or bad code?
46:45 Office Macros Malware Example
50:40 Cool Linux command
51:26 Is this a good job? Are there lots of job?
52:30 What hours do you work?
53:31 Any books you recommend?

Playlist

Uploads from David Bombal · David Bombal · 0 of 60

← Previous Next →
1 RYU SDN Controller Part 3: OpenFlow 1.3: Practical GNS3 SDN and OpenFlow
RYU SDN Controller Part 3: OpenFlow 1.3: Practical GNS3 SDN and OpenFlow
David Bombal
2 RYU SDN Controller Part 4: Graphical User Interface (GUI): Practical GNS3 SDN and OpenFlow
RYU SDN Controller Part 4: Graphical User Interface (GUI): Practical GNS3 SDN and OpenFlow
David Bombal
3 GNS3 Talks: IOSvL2 switching appliance import & configuration
GNS3 Talks: IOSvL2 switching appliance import & configuration
David Bombal
4 HPE Network Protector SDN Application Part 1 - Introduction
HPE Network Protector SDN Application Part 1 - Introduction
David Bombal
5 HPE Network Protector SDN Application Part 2 : DNS Interception using OpenFlow
HPE Network Protector SDN Application Part 2 : DNS Interception using OpenFlow
David Bombal
6 HPE Network Protector SDN Application Part 3 - Lab Setup using Physical Switches
HPE Network Protector SDN Application Part 3 - Lab Setup using Physical Switches
David Bombal
7 HPE Network Protector SDN Application Part 4 - Demo of malicious websites blocked
HPE Network Protector SDN Application Part 4 - Demo of malicious websites blocked
David Bombal
8 HPE Network Protector SDN Application Part 5 - Demo OpenFlow table interception flows
HPE Network Protector SDN Application Part 5 - Demo OpenFlow table interception flows
David Bombal
9 HPE Network Protector SDN Application Part 6 - Demo of Physical Switch configuration
HPE Network Protector SDN Application Part 6 - Demo of Physical Switch configuration
David Bombal
10 GNS3 Talks: IOSv Appliance - get IOS 15.X on GNS3
GNS3 Talks: IOSv Appliance - get IOS 15.X on GNS3
David Bombal
11 HPE Network Protector SDN Application Part 7 - Demo Service Insertion Tunnel / GRE Tunnel
HPE Network Protector SDN Application Part 7 - Demo Service Insertion Tunnel / GRE Tunnel
David Bombal
12 HPE Network Protector SDN Application Part 8 - Demo SDN OpenFlow Reporting
HPE Network Protector SDN Application Part 8 - Demo SDN OpenFlow Reporting
David Bombal
13 HPE Network Protector SDN Application Part 9 - Demo switches interception of DNS traffic
HPE Network Protector SDN Application Part 9 - Demo switches interception of DNS traffic
David Bombal
14 GNS3 Talks: GNS3 version 1.5.X Appliance Tips
GNS3 Talks: GNS3 version 1.5.X Appliance Tips
David Bombal
15 CCNA 200-125 Exam: AAA demo: TACACS+ with GNS3
CCNA 200-125 Exam: AAA demo: TACACS+ with GNS3
David Bombal
16 CCNA 200-125 Exam: PPPoE Server Demo with GNS3
CCNA 200-125 Exam: PPPoE Server Demo with GNS3
David Bombal
17 CCNA VLOG #001: Troubleshooting OSPF for the CCNA 120-125 exam
CCNA VLOG #001: Troubleshooting OSPF for the CCNA 120-125 exam
David Bombal
18 CCNA VLOG #002: Q&A: Loopback? What? Why? CCNA 120-125 questions
CCNA VLOG #002: Q&A: Loopback? What? Why? CCNA 120-125 questions
David Bombal
19 GNS3 Talks: Install GNS3 1.5.X on a Mac with GNS3 VM
GNS3 Talks: Install GNS3 1.5.X on a Mac with GNS3 VM
David Bombal
20 CCNA VLOG #003: What's your name? That won't work! CCNA Troubleshooting
CCNA VLOG #003: What's your name? That won't work! CCNA Troubleshooting
David Bombal
21 CCNA VLOG #004: IP default gateway versus default route
CCNA VLOG #004: IP default gateway versus default route
David Bombal
22 CCNA VLOG #005: Why is the network broken? CCNA 200-125 Troubleshooting
CCNA VLOG #005: Why is the network broken? CCNA 200-125 Troubleshooting
David Bombal
23 CCNA VLOG #006: Troubleshoot Telnet issues in preparation for the CCNA 200-125 exam
CCNA VLOG #006: Troubleshoot Telnet issues in preparation for the CCNA 200-125 exam
David Bombal
24 CCNA VLOG #007: BGP configuration and verification for the CCNA 200-125 exam
CCNA VLOG #007: BGP configuration and verification for the CCNA 200-125 exam
David Bombal
25 CCNA VLOG #008: BGP troubleshooting for the CCNA 200-125 exam
CCNA VLOG #008: BGP troubleshooting for the CCNA 200-125 exam
David Bombal
26 CCNA VLOG #009: BGP troubleshooting 2 - lost BGP route - CCNA 200-125 exam
CCNA VLOG #009: BGP troubleshooting 2 - lost BGP route - CCNA 200-125 exam
David Bombal
27 GNS3 2.0.0 beta 2 install
GNS3 2.0.0 beta 2 install
David Bombal
28 CCNA VLOG #010: Q&A: Loopbacks? Another good reason to use loopbacks! CCNA 120-125
CCNA VLOG #010: Q&A: Loopbacks? Another good reason to use loopbacks! CCNA 120-125
David Bombal
29 CCNA VLOG #011: BGP troubleshooting 3 - Neighbor down! CCNA 200-125 exam
CCNA VLOG #011: BGP troubleshooting 3 - Neighbor down! CCNA 200-125 exam
David Bombal
30 CCNA #012: Learn SNMP with GNS3, Wireshark and Solarwinds NPM - CCNA 200-125 exam
CCNA #012: Learn SNMP with GNS3, Wireshark and Solarwinds NPM - CCNA 200-125 exam
David Bombal
31 CCNA #013: Spanning Tree CCNA Exam Questions: Know the answer? CCNA 200-125 exam
CCNA #013: Spanning Tree CCNA Exam Questions: Know the answer? CCNA 200-125 exam
David Bombal
32 CCNA #014: Routing decisions? OSPF or EIGRP? CCNA 200-125 exam questions
CCNA #014: Routing decisions? OSPF or EIGRP? CCNA 200-125 exam questions
David Bombal
33 CCNA #015: DHCP Server and client configuration using Cisco IOS: CCNA 200-125 exam
CCNA #015: DHCP Server and client configuration using Cisco IOS: CCNA 200-125 exam
David Bombal
34 CCNA #016: OSPF, EIGRP, RIP or Static Routes? Routing decisions? CCNA 200-125 exam
CCNA #016: OSPF, EIGRP, RIP or Static Routes? Routing decisions? CCNA 200-125 exam
David Bombal
35 GNS3 2.0.0 beta : GNS3 VM integration with GNS3 GUI
GNS3 2.0.0 beta : GNS3 VM integration with GNS3 GUI
David Bombal
36 CCNA #017: What is a RIB Failure? EBGP versus IBGP? CCNA 200-125 exam questions
CCNA #017: What is a RIB Failure? EBGP versus IBGP? CCNA 200-125 exam questions
David Bombal
37 CCNA #018: Routing exam questions: Who wins? OSPF, EIGRP or RIP? Sure? CCNA 200-125 exam
CCNA #018: Routing exam questions: Who wins? OSPF, EIGRP or RIP? Sure? CCNA 200-125 exam
David Bombal
38 CCNA #019: Spanning Tree CCNA Exam Questions: Root Bridge, Root Port and more: CCNA 200-125 exam
CCNA #019: Spanning Tree CCNA Exam Questions: Root Bridge, Root Port and more: CCNA 200-125 exam
David Bombal
39 CCNA #020: Static NAT Demo: CCNA 200-125 exam
CCNA #020: Static NAT Demo: CCNA 200-125 exam
David Bombal
40 GNS3 Talks: GNS3 and Physical device OSPF route exchange
GNS3 Talks: GNS3 and Physical device OSPF route exchange
David Bombal
41 GNS3 Download, installation and configuration - GNS3 1.5.3 and Windows 10
GNS3 Download, installation and configuration - GNS3 1.5.3 and Windows 10
David Bombal
42 ESXi Part 1: GNS3, VMware ESXi and the GNS3 VM
ESXi Part 1: GNS3, VMware ESXi and the GNS3 VM
David Bombal
43 CCNA VLOG #021 EIGRP Neighbor Troubleshooting: Debugs show not common Subnet: CCNA 200-125 Exam
CCNA VLOG #021 EIGRP Neighbor Troubleshooting: Debugs show not common Subnet: CCNA 200-125 Exam
David Bombal
44 ESXi Part 2: GNS3, VMware ESXi and the GNS3 VM
ESXi Part 2: GNS3, VMware ESXi and the GNS3 VM
David Bombal
45 ESXi Part 3: GNS3, VMware ESXi and the GNS3 VM
ESXi Part 3: GNS3, VMware ESXi and the GNS3 VM
David Bombal
46 ESXi Part 4: GNS3, VMware ESXi and the GNS3 VM
ESXi Part 4: GNS3, VMware ESXi and the GNS3 VM
David Bombal
47 CCNA #022 EIGRP Neighbor Troubleshooting for the CCNA 200-125 Exam
CCNA #022 EIGRP Neighbor Troubleshooting for the CCNA 200-125 Exam
David Bombal
48 GNS3 VM Integration: GNS3 1.5.3, VMware and Windows 10 with GNS3 Talks
GNS3 VM Integration: GNS3 1.5.3, VMware and Windows 10 with GNS3 Talks
David Bombal
49 GNS3 GUI and VM upgrade on Windows: How to upgrade to 1.5.3 (includes GNS3 VM upgrade process)
GNS3 GUI and VM upgrade on Windows: How to upgrade to 1.5.3 (includes GNS3 VM upgrade process)
David Bombal
50 CCNA #023 EIGRP Neighbor Troubleshooting (DUAL Issues) for the CCNA 200-125 Exam
CCNA #023 EIGRP Neighbor Troubleshooting (DUAL Issues) for the CCNA 200-125 Exam
David Bombal
51 CCNA #024 EIGRP Retransmission retry limit exceeded? EIGRP Neighbor Troubleshooting CCNA
CCNA #024 EIGRP Retransmission retry limit exceeded? EIGRP Neighbor Troubleshooting CCNA
David Bombal
52 GNS3 Talks: Integrate Windows Virtual Machine with GNS3 = GNS3+GNS3 VM + Windows 10 VM + Cisco
GNS3 Talks: Integrate Windows Virtual Machine with GNS3 = GNS3+GNS3 VM + Windows 10 VM + Cisco
David Bombal
53 GNS3 GUI and VM upgrade on Mac OS X: How to upgrade to 1.5.3 (includes GNS3 VM upgrade process)
GNS3 GUI and VM upgrade on Mac OS X: How to upgrade to 1.5.3 (includes GNS3 VM upgrade process)
David Bombal
54 CCNA #025 EIGRP Neighbor Troubleshooting for the CCNA 200-125 Exam
CCNA #025 EIGRP Neighbor Troubleshooting for the CCNA 200-125 Exam
David Bombal
55 CCNA #026 EIGRP Neighbor Troubleshooting (no neighbors) for the CCNA 200-125 Exam
CCNA #026 EIGRP Neighbor Troubleshooting (no neighbors) for the CCNA 200-125 Exam
David Bombal
56 GNS3 2.0 Architecture and schema Part 1: What is the GNS3 Controller?
GNS3 2.0 Architecture and schema Part 1: What is the GNS3 Controller?
David Bombal
57 GNS3 2.0 Architecture and schema Part 2: Emulators and virtualization
GNS3 2.0 Architecture and schema Part 2: Emulators and virtualization
David Bombal
58 CCNA #027 200-125 Exam: MAC OS Simulator - are you ready for exam sims?
CCNA #027 200-125 Exam: MAC OS Simulator - are you ready for exam sims?
David Bombal
59 GNS3 Talks: Mac OS with Windows 10 Virtual Machine = Mac+GNS3+GNS3 VM+Windows 10 VM+Cisco
GNS3 Talks: Mac OS with Windows 10 Virtual Machine = Mac+GNS3+GNS3 VM+Windows 10 VM+Cisco
David Bombal
60 GNS3 2.0 New Features: Smart packet capture and capture on any link
GNS3 2.0 New Features: Smart packet capture and capture on any link
David Bombal
Emergency Webcast Briefing: Axios NPM Supply Chain Compromise
Next Up
Emergency Webcast Briefing: Axios NPM Supply Chain Compromise
SANS Institute