│ │ ├── VirusTotal Intelligence (sandbox + retrohunt)
│ │ └── Malpedia (family-level info, samples)
│ └── MITRE ATT&CK
│ ├── Mapping to tactics: Initial Access, Execution...
│ └── Correlation: Technique → Procedure → IOC → YARA
│
├── 6. Reporting & Documentation
│ ├── Flowcharts: Reverse-engineered malware stages
│ ├── Timeline: Execution map & persistence flow
│ ├── Attribution: Language hints, coding style, infrastructure
│ └── Remediation:
│ ├── Registry restoration, kill persistence
│ ├── Network block rules
│ └── Endpoint detection rules (via EDR tools)
│
├── 7. Certifications
│ ├── eMAP – eLearnSecurity Malware Analysis Professional
│ ├── GREM – GIAC Reverse Engineering Malware
│ ├── OSED – Offensive Security Exploit Development
│ └── Malware Unicorn / REAcademy – Challenge-based curriculum
│
└── 8. Continuous Learning
├── Blogs: FireEye, Hexacorn, Malwarebytes Labs, ReversingLabs
├── GitHub: PE Tools, unpackers, sandbox frameworks
├── CTFs: Flare-on, Crackmes.one, HTB RE Tracks
└── Forums: Reddit r/ReverseEngineering, Malware Discords
رودمپ مهندسی معکوس و تحلیل بدافزار 🚨
ادامه