新手上路
前天 08:18
主楼
- 完整课程体系:涵盖恶意软件分类、静态分析、动态调试等核心知识;
- 丰富讲座视频:历年的全套课程录像可随时观看;
- 实操实验作业:包括 Ghidra 脚本编写、PDF 载荷分析等实战项目;
- 工具详细教程:覆盖 Ghidra、Yara、IDA、Volatility 等主流分析工具;
- 按主题分类索引:可快速定位到汇编、调试器、虚拟化等具体主题。
- README.md
- _config.yml
- _gen_tags.py
- _get-tags.sh
- _layouts
- _posts
- 2017-01-10-introduction.md
- 2017-01-12-virtualbox-lab-setup.md
- 2017-01-17-simple-attack.md
- 2017-01-19-malware-analysis-intro.md
- 2017-01-24-malware-taxonomy-terminology.md
- 2017-01-26-malware-research-online.md
- 2017-01-31-static-analysis-introduction.md
- 2017-02-02-static-analysis-extraction.md
- 2017-02-05-HW01-VM-Capture.md
- 2017-02-05-kali-metasploit.md
- 2017-02-05-static-analysis-utility.md
- 2017-02-07-yara.md
- 2017-02-09-asm-crash-course-1.md
- 2017-02-14-asm-crash-course-2.md
- 2017-02-21-static-analysis-1.md
- 2017-02-23-static-analysis-2.md
- 2017-02-28-data-encoding-structures-layout.md
- 2017-03-02-analysis-complex-data-structures.md
- 2017-03-07-pdf-document-analysis.md
- 2017-04-12-HW04-strings-analysis-yara.md
- 2017-04-12-HW05-binary-analysis-yara.md
- 2017-04-22-Final-Analysis.md
- 2018-01-16-virtualbox-lab.md
- 2018-01-18-example-attack.md
- 2018-01-25-HW01-VM-Capture-and-Attack.md
- 2018-01-25-container-model-analyzing-attack.md
- 2018-02-20-code-based-yara-strings.md
- 2018-02-22-malware-research-online.md
- 2018-02-27-HW02-strings-analysis-yara.md
- 2018-03-09-HW03-binary-analysis-yara.md
- 2018-03-20-document-format-analysis.md
- 2018-04-03-debugger-vm-detect.md
- 2018-04-08-HW04-dynamic-tracing.md
- 2018-04-24-Final-Analysis.md
- 2020-01-14-malware-analysis-lab.md
- 2020-01-16-LAB01-VM-Setup-and-Test.md
- 2020-01-19-malware-taxonomy.md
- 2020-01-20-building-an-attack.md
- 2020-01-21-metasploit-and-pupy.md
- 2020-01-23-LAB02-Building-a-custom-attack.md
- 2020-01-24-static-analysis-host.md
- 2020-01-28-analysis-exercise.md
- 2020-02-02-asm-crash-course.md
- 2020-02-04-exe-file-analysis-1.md
- 2020-02-05-ghidra-intro.md
- 2020-02-09-run-time-analysis-and-editing.md
- 2020-02-11-continued-analysis-ghidra.md
- 2020-02-11-immdbg-malware-analysis.md
- 2020-02-16-more-on-immdb.md
- 2020-02-16-simple-program-analysis.md
- 2020-03-02-multi-stage-document-attacks.md
- 2020-03-07-yara-signatures.md
- 2020-03-10-more-yara-examples.md
- 2020-03-29-hunting-using-yara.md
- 2020-04-05-pdf-document-analysis.md
- 2020-04-10-java-analysis-intro.md
- 2020-04-13-obfuscation-and-java-malware.md
- 2020-04-18-android-intro-and-tools.md
- 2020-04-22-android-analysis-part2.md
- 2021-01-13-course-introduction.md
- 2021-01-13-malware-taxonomy.md
- 2021-01-24-malware-research-online.md
- 2021-01-28-LAB01-VM-Setup-and-Test.md
- 2021-02-01-static-analysis-of-malware.md
- 2021-02-08-ghidra-intro.md
- 2021-02-08-z-asm-crash-course-1.md
- 2021-02-08-z-asm-crash-course-2.md
- 2021-02-12-LAB02-PDF-payload-analysis-101.md
- 2021-02-28-ghidra-code-analysis.md
- 2021-03-05-more-ghidra-code-analysis.md
- 2021-03-08-ghidra-scripting.md
- 2021-03-18-LAB03-Ghidra-101-and-OSINT.md
- 2021-03-21-ghidra-scripting-feature-extraction.md
- 2021-04-06-LAB04-Ghidra-Scripting.md
- 2021-04-06-host-exploitation-and-forensic-analysis.md
- 2021-04-11-dynamic-analysis-run-time-debugging-yara.md
- 2021-04-11-java-and-mobile-malware-analysis.md
- _tags
- code
- asmprog.dot.pdf
- bdconsole.py
- evil_pdf.hdb
- evil_pdf.ldb
- evil_pdf.yar
- ex1.ltx
- ex1.pdf
- extract-image-base.sh
- make-objs.sh
- metadata_import.py
- mw_report.ltx
- struct-test.cpp
- struct-test2.cpp
- tea1-32.hex
- tea1-32.o
- tea1-32.s
- tea1-64.hex
- tea1-64.o
- tea1-64.s
- tea1.c
- tea2-32.hex
- tea2-32.o
- tea2-32.s
- tea2-64.hex
- tea2-64.o
- tea2-64.s
- tea2.c
- test_samples.hdb
- treyfer1-32.hex
- treyfer1-32.o
- treyfer1-32.s
- treyfer1-64.hex
- treyfer1-64.o
- treyfer1-64.s
- treyfer1.c
- treyfer2-32.hex
- treyfer2-32.o
- treyfer2-32.s
- treyfer2-64.hex
- treyfer2-64.o
- treyfer2-64.s
- treyfer2.c
- yara_chat.c
- yara_chat.py
- yara_chat.yar
- index.md
- lecture-slides
- lecture-ss18-w01-1.pdf
- lecture-ss18-w01-2.pdf
- lecture-ss18-w02.pdf
- lecture-ss18-w03.pdf
- lecture-ss18-w04-1.pdf
- lecture-ss18-w05-1.pdf
- lecture-ss18-w05-2.pdf
- lecture-ss18-w06.pdf
- lecture-ss18-w07-2.pdf
- lecture-ss18-w08-1.pdf
- lecture-ss18-w08-2.pdf
- lecture-ss18-w09-2.pdf
- lecture-ss18-w11-1.pdf
- lecture-w01-1.pdf
- lecture-w01-2.pdf
- lecture-w02-1.pdf
- lecture-w02-2.pdf
- lecture-w03-1.pdf
- lecture-w03-2.pdf
- lecture-w04-1.pdf
- lecture-w04-2.pdf
- lecture-w05-1.pdf
- lecture-w05-2.pdf
- lecture-w06.pdf
- lecture-w08-1.pdf
- lecture-w08-2.pdf
- lecture-w09-1.pdf
- lecture-w09-2.pdf
- old_lectures.md
- stuff
- alice.txt
- android-analysis-options.png
- asm1.png
- classes_algo1.png
- classes_algo1_full.png
- classes_algo1_full_both.png
- comments_ex.png
- data-convert.png
- defined-strings.png
- disable-acrobat-protected-mode.png
- edit_listing_fields.png
- edit_main_sig.png
- entry_renamed.png
- ex2_2-running.png
- fun_00401590_comment.png
- fun_labels.png
- func-graph-button-highlighted.png
- func_instr_stats.png
- funcs_algo1.png
- funcs_algo1_full.png
- function-call-graph.png
- function-call-trees.png
- ghidra-annotated.png
- ghidra-batch-import.png
- ghidra-func-graph.png
- ghidra-jar-project.png
- ghidra-java-screenshot.png
- ghidra_algo1_project.png
- ghidra_docs
- GhidraAPI_javadoc.zip
- GhidraClass
- Advanced
- Examples
- GHIDRA_1.png
- ghidraRight.png
- improvingDisassemblyAndDecompilation.pdf
- improvingDisassemblyAndDecompilation.tex
- AdvancedDevelopment
- Images
- contrib
- gadc
- ghidra_scripts
- ghidra-format
- Beginner
- Images
- Introduction_to_Ghidra_Student_Guide.html
- Introduction_to_Ghidra_Student_Guide_withNotes.html
- README.txt
- ExerciseFiles
- Advanced
- Emulation
- VersionTracking
- Source
- Mod1
- Mod2
- Original
- WallaceSrc.exe
- WallaceVersion2.exe
- WinhelloCPP
- source
- Intermediate
- GhidraCodingStandards.html
- InstallationGuide.html
- README_PDB.html
- UserAgreement.html
- WhatsNew.html
- api
- db
- Database
- DatabaseUtils.html
- DatabaseUtils.json
- Field.UnsupportedFieldException.html
- Field.html
- Field.json
- Field
- FieldIndexTable.html
- FieldIndexTable.json
- FieldIndexTable
- FieldKeyInteriorNode.html
- FieldKeyInteriorNode.json
- FieldKeyNode.json
- FieldKeyRecordNode.json
- FixedField.json
- FixedField10.html
- FixedField10.json
- FixedKeyFixedRecNode.json
- FixedKeyInteriorNode.json
- FixedKeyNode.json
- FixedKeyRecordNode.json
- FixedKeyVarRecNode.json
- FixedRecNode.json
- IllegalFieldAccessException.html
- IllegalFieldAccessException.json
- IndexField.json
- IndexTable.json
- IntField.html
- IntField.json
- InteriorNode.html
- InteriorNode.json
- JavaBinarySearcher.json
- JavaBinarySearcher2.json
- KeyToRecordIterator.html
- KeyToRecordIterator.json
- LegacyIndexField.json
- LongField.html
- LongField.json
- LongKeyInteriorNode.json
- LongKeyNode.json
- LongKeyRecordNode.json
- MasterTable.json
- NoTransactionException.html
- NoTransactionException.json
- NodeMgr.json
- ObjectStorageAdapterDB.html
- ObjectStorageAdapterDB.json
- OpenMode.html
- PrimitiveField.json
- RecordIterator.html
- RecordIterator.json
- RecordNode.html
- RecordNode.json
- RecordTranslator.html
- RecordTranslator.json
- Schema.html
- Schema.json
- ShortField.html
- ShortField.json
- SparseRecord.html
- SparseRecord.json
- StringField.html
- StringField.json
- Table.html
- Table.json
- TableRecord.json
- TableStatistics.html
- TableStatistics.json
- TerminatedTransactionException.html
- TerminatedTransactionException.json
- TestSpeed.html
- TestSpeed.json
- TranslatedRecordIterator.html
- TranslatedRecordIterator.json
- VarKeyInteriorNode.json
- VarKeyNode.json
- VarKeyRecordNode.json
- VarRecNode.json
- buffers
- LocalBufferFile
- LocalManagedBufferFile.html
- LocalManagedBufferFile.json
- LocalManagedBufferFile
- ManagedBufferFile.html
- ManagedBufferFile.json
- ManagedBufferFileAdapter.html
- ManagedBufferFileAdapter.json
- ManagedBufferFileHandle.html
- ManagedBufferFileHandle.json
- OutputBlockStream.html
- OutputBlockStream.json
- RecoveryFile.json
- RecoveryMgr.json
- RemoteBufferFileHandle.html
- RemoteBufferFileHandle.json
- RemoteManagedBufferFileHandle.html
- RemoteManagedBufferFileHandle.json
- VersionFile.json
- VersionFileHandler.html
- VersionFileHandler.json
- package-summary.html
- package-tree.html
- package-summary.html
- package-tree.html
- util
- decompiler
- deprecated-list.html
- docking
- element-list
- foundation
- generic
- ghidra
- help-doc.html
- help
- index-all.html
- index.html
- jquery
- log
- member-search-index.js
- member-search-index.zip
- org
- overview-summary.html
- overview-tree.html
- package-search-index.js
- package-search-index.zip
- resources
- script.js
- search.js
- serialized-form.html
- stylesheet.css
- type-search-index.js
- type-search-index.zip
- util
- utilities
- utility
- images
- languages
- ghidra_new_project.png
- ghidra_phases.png
- ghidra_script_execution.png
- ghidra_script_refresh.png
- gnumeric-data.png
- immdbg-assemble.png
- immdbg-bar.png
- immdbg-binary-fill.png
- immdbg-context-copy-to-exe.png
- immdbg-copy-to-exe.png
- immdbg-ex1-calleax.png
- immdbg-ex1-exe.png
- immdbg-ex1-msgboxa-callstack.png
- immdbg-new-origin.png
- immdbg-noted.png
- immdbg-patch-call.png
- immdbg-patches.png
- immdbg-selected-instrs-1.png
- immdbg-this-console.png
- immdbg-writestr-and-winmain.png
- lab8_malware.exe
- list_objects.py
- listing_edit_main.png
- loading-dalvik.png
- main_decompiled.png
- mal-pdf.png
- mwreport-template.docx
- nardella
- network-menu.png
- network-status.png
- pcode_ex.png
- pcode_header_disabled.png
- proguard-input-output.png
- proguard-optimization.png
- rename-readDictionary.png
- renamed-in-steal-function.png
- script_directories_button.png
- script_manager.png
- setting-dns-server.png
- svcho5t.png
- symbol-tree.png
- symbol-tree-filtered-messagebox.png
- var-dep-graph.png
- viewing-messagebox-call.png
- syllabus.md