Malware Analysis & Reverse Engineering Roadmap (Advanced Version)
├── 0. Foundations
│ ├── OS Internals
│ │ ├── Windows: WinAPI, NTAPI, Syscalls, Kernel Objects
│ │ ├── Linux: /proc, Syscall Table, ELF Loader
│ │ └── Tools: Process Hacker, Sysinternals, strace/ltrace
│ ├── Computer Architecture
│ │ ├── x86/x64: Instruction Set, Registers, Calling Conventions
│ │ ├── ARM: Stack Usage, Branch Instructions, Thumb Mode
│ │ └── Practice: Ripes, cpulator, Intel Manuals
│ ├── Programming
│ │ ├── C: Memory Model, Stack/Heap, Struct & Pointer Manipulation
│ │ ├── Assembly: NASM/GAS Syntax, Control Flow, Syscalls
│ │ └── Python: File Parsing, PE/ELF Tools, Automation Scripts
│ └── File Formats
│ ├── PE: Headers, Sections (.text/.data/.rdata), Imports/Exports
│ └── ELF: Section vs Segment, .plt/.got, Symbol Resolution
│
├── 1. Static Analysis
│ ├── Disassembly
│ │ ├── Tools: IDA Pro, Ghidra, Hopper, Radare2
│ │ └── Views: Assembly, Pseudocode, Control Flow Graph
│ ├── Binary Inspection
│ │ ├── Strings: FLOSS (decoded), Strings.exe
│ │ ├── File Metadata: Detect-It-Easy, PEStudio
│ │ └── Entropy & Packer Detection: Binwalk, Exeinfo PE
│ ├── Import & Dependency Mapping
│ │ ├── DLL Discovery, API Resolution
│ │ └── Tools: Dependency Walker, CFF Explorer
│ └── Obfuscation Recognition
│ ├── Techniques: Junk Code, Encrypted Strings
│ └── Packers: UPX, Themida, VMProtect, custom cryptors
│
├── 2. Dynamic Analysis
│ ├── Sandboxing
│ │ ├── Cuckoo (custom VM, signatures)
│ │ └── Any.Run (interactive web environment)
│ ├── Debugging
│ │ ├── x64dbg (graph view, patching, memory map)
│ │ ├── OllyDbg (older binaries, plugin-rich)
│ │ └── WinDbg (kernel-mode analysis)
│ ├── Behavior Monitoring
│ │ ├── Procmon: Registry, File, Network filters
│ │ ├── Sysmon: Event tracing via XML rules
│ │ └── Regshot: Before/After snapshots
│ └── Network Monitoring
│ ├── Wireshark: Deep packet inspection
│ ├── Fakenet-NG: Simulated internet services
│ └── INetSim: Malware network mimicry
│
├── 3. Reverse Engineering Techniques
│ ├── Assembly Analysis
│ │ ├── Function Blocks, Syscalls, API Calls
│ │ └── Recognizing Compiler Artifacts (e.g. MSVC prologue)
│ ├── CFG Reconstruction
│ │ ├── Loops, Branches, Switch-case structures
│ │ └── Tools: Ghidra CFG View, Binary Ninja Graph Mode
│ ├── Deobfuscation & Unpacking
│ │ ├── Manual: Control flow flattening, decrypting routines
│ │ ├── Automatic: UPX unpacking, Qiling emulator
│ │ └── Custom loaders: Debugging Execution Path
│ └── Function & API Mapping
│ ├── Signature Matching: IDA Patterns, FLIRT
│ └── Behavior Mapping: WinAPI to Malicious Intent (e.g. WriteProcessMemory)
│
├── 4. Malware Taxonomy
│ ├── Classic Families
│ │ ├── Ransomware: Encryption detection, Key extraction
│ │ ├── Rootkits: SSDT Hooks, PatchGuard bypass
│ │ ├── RATs & Trojans: C2 signaling, persistence mechanisms
│ │ └── Worms: Propagation vectors, replication logic
│ ├── APTs & Targeted Attacks
│ │ ├── TTP Analysis: MITRE technique mapping
│ │ ├── Payload chaining, lateral movement
│ │ └── Language & infrastructure fingerprinting
│ └── Exploits
│ ├── Shellcode analysis (msfvenom, custom loaders)
│ ├── Stack Overflows, SEH exploits
│ └── ROP gadget hunting, Control hijacking
│
├── 5. Threat Intelligence
│ ├── IOC Extraction
│ │ ├── Static: Embedded IPs, Strings, Registry keys
│ │ └── Dynamic: DNS, dropped files, mutexes
│ ├── YARA Rules
│ │ ├── Patterns: Opcode sequences, String signatures
│ │ └── Conditions: Offset checks, file size, metadata
│ ├── CTI Platforms
│ │ ├── MISP (Indicators + Relations)
رودمپ مهندسی معکوس و تحلیل بدافزار 🚨