You are on page 1of 77

sigcheck -e -u -s c:\

listdlls -u

strings <file>

http://www.e-markettop.com/

http://blogs.technet.com/b/markrussinovich/archive/2011/03/14/3412374.aspx

Process Monitor UI
User Mode
Kernel Mode
Process Monitor Driver
File System
Filter

Registry Callback

TCP/IP Driver ETW


events
Kernel
Callouts

Function 1
Function 2
Function 3

Function 3
Function 2
Function 1

Stack Display

Filter Manager
Virus Scanner

Kernel Mode

Kernel

System Library
SuperFetch
User Mode
(root cause)
System Library
Note: user stack capture isnt supported on 64-bit versions of Windows XP/Server 2003

Category is Write

http://blogs.technet.com/b/markrussinovich/archive/2011/03/08/3392087.aspx

http://blogs.technet.com/b/markrussinovich/archive/2011/02/27/3390475.aspx

http://blogs.technet.com/b/markrussinovich/archive/2011/03/30/3416253.aspx

www.zerodaythebook.com

http://www.youtube.com/watch?v=ucyMBYg9RWU

http://technet.microsoft.com/en-us/sysinternals/hh290819

http://www.symantec.com/content/en/us/enterprise/media/security_response/
whitepapers/w32_stuxnet_dossier.pdf
http://www.wired.com/threatlevel/2011/07/howdigital-detectives-deciphered-stuxnet/
http://www.virusbtn.com/pdf/conference_slides/2010/Johnson-VB2010.pdf

You might also like