Professional Documents
Culture Documents
listdlls -u
strings <file>
http://www.e-markettop.com/
http://blogs.technet.com/b/markrussinovich/archive/2011/03/14/3412374.aspx
Process Monitor UI
User Mode
Kernel Mode
Process Monitor Driver
File System
Filter
Registry Callback
Function 1
Function 2
Function 3
Function 3
Function 2
Function 1
Stack Display
Filter Manager
Virus Scanner
Kernel Mode
Kernel
System Library
SuperFetch
User Mode
(root cause)
System Library
Note: user stack capture isnt supported on 64-bit versions of Windows XP/Server 2003
Category is Write
http://blogs.technet.com/b/markrussinovich/archive/2011/03/08/3392087.aspx
http://blogs.technet.com/b/markrussinovich/archive/2011/02/27/3390475.aspx
http://blogs.technet.com/b/markrussinovich/archive/2011/03/30/3416253.aspx
www.zerodaythebook.com
http://www.youtube.com/watch?v=ucyMBYg9RWU
http://technet.microsoft.com/en-us/sysinternals/hh290819
http://www.symantec.com/content/en/us/enterprise/media/security_response/
whitepapers/w32_stuxnet_dossier.pdf
http://www.wired.com/threatlevel/2011/07/howdigital-detectives-deciphered-stuxnet/
http://www.virusbtn.com/pdf/conference_slides/2010/Johnson-VB2010.pdf