Malware Analysis Tools YOU COULD USE

Ғылым және технология

Malware analysis tools for 2024: I look at some up and coming malware analysis tools everyone can use like Triage, Capa and ActivityView. Whether you want to do system forensics or binary reverse engineering, you'll find one of these quite useful. Get NordVPN (discounted) : nordvpn.com/tpsc (sponsor)
Buy the best antivirus: thepcsecuritychannel.com/best...
Join the discussion on Discord: discord.tpsc.tech/
Get your business endpoints tested by us: tpsc.tech/
Contact us for business: thepcsecuritychannel.com/contact

Пікірлер: 124

  • @Orblets
    @Orblets4 ай бұрын

    Bro I was looking for something exactly like last activity view today and couple hours later this video shows in my recommended. Thank you!

  • @Q-432hz
    @Q-432hz4 ай бұрын

    Excellent upload 🎉 Thank for your work 👍🏾

  • @GeorgeG-is6ov
    @GeorgeG-is6ov4 ай бұрын

    thank you bro I was waiting so long for this

  • @FurryNonsense
    @FurryNonsense4 ай бұрын

    I wish there was a website that just said what the virus did (steal passwords, lock you out of your computer, etc) instead of a bunch of random codes and saying "yeah, this is bad, but we're not gonna say why this is bad"

  • @SmilerRyanYT

    @SmilerRyanYT

    4 ай бұрын

    Technically chatgpt might be able to do that now. I know I use AnyRun often and that has an option to summarise the whole thing.

  • @ChrisM541

    @ChrisM541

    4 ай бұрын

    False positives/negatives. This kind of analysis is similar to going to your doctor to get a diagnosis done on a health problem...it's very uncommon for a single test to conclusively point you to the answer. In PC forensic analysis you need to use multiple tools - and have a the correct level of skill yourself - in order to get to the bottom of any problem. A simple virus scanner needs a database of known 'signatures', and even then, they can still return false positives. You can reduce risk by following good practice, but you can never reduce that to zero, unfortunately. Even many closed systems are not risk-free.

  • @prof.poopypants8671

    @prof.poopypants8671

    4 ай бұрын

    Every security analyst wishes the exact same thing. Unfortunately, the reality is that a lot of malware performs activities on the system that are indistinguishable from user behavior (which can vary a LOT, depending on the user) or legitimate system processes. This makes it nearly impossible to provide a simple, concise, clear-cut answer in an automated way.

  • @Jordan-xy9hs

    @Jordan-xy9hs

    4 ай бұрын

    tell me how that would work, genius.

  • @superbaggio87

    @superbaggio87

    4 ай бұрын

    facts bruh

  • @Wahinies
    @Wahinies4 ай бұрын

    Yooo this is an amazing example of enhancing the global security posture by educating. Thank you for this set!

  • @alexxx4434
    @alexxx44344 ай бұрын

    Nir Soft freeware system tools are great! Been using them a long time.

  • @HoshangGovil
    @HoshangGovil4 ай бұрын

    I have learnt a lot from you and will be learning more in the future. Thank you!

  • @akureiokamii

    @akureiokamii

    4 ай бұрын

    Thank you! Do not redeem good sarr!

  • @balajisharathkumar9753
    @balajisharathkumar97534 ай бұрын

    wow awesome tools thanks for knowledge sharing for security knowledge is there any equal siem tool available in the market ?

  • @HikaruAkitsuki
    @HikaruAkitsuki4 ай бұрын

    My main Working Station is Virtual Machine. I refuse to do my activity on Bare Metal. VM is easy to deal if there is something went wrong. You can just Snapshot it or delete entirely and install a fresh one.

  • @wannabedal-adx458

    @wannabedal-adx458

    4 ай бұрын

    That is actually a great idea. So the snapshot has all of your applications previously configured to it, right? and then how do you move or work with you data in and out of the VM? Meaning how do you keep it secure if it is sitting on a NAS or a USB flash drive (that you don't share)? Thanks.

  • @user-jm8sy5ox2j

    @user-jm8sy5ox2j

    4 ай бұрын

    Using a VM 24/7 is great if you don't mind the massive performance penalty for doing it. If you want to do any kind of video editing, gaming, data processing, etc type of tasks then you'll extend the runtime by at least 2x if you run it in a VM instead of bare metal

  • @HikaruAkitsuki

    @HikaruAkitsuki

    4 ай бұрын

    @@user-jm8sy5ox2j Yea, there is indeed must on BM. But if you do research and gonna enter on a random website, it should be on VM.

  • @michaell7877
    @michaell78773 ай бұрын

    I like your vids. Quite often it’s over my head. I would like to learn how as a beginner of trying to protect my pc from outside hacks. What do you suggest how I get started? Do you have a video on how to start out? Tyvm.

  • @DdragonGun001
    @DdragonGun001Ай бұрын

    Some tools I use are Capa, bstrings, procmon, pestudio, and running things on inetsim

  • @samfisher5302
    @samfisher53022 ай бұрын

    Great video! Thank you!

  • @a7xnexus
    @a7xnexus4 ай бұрын

    please make a video about famous software used in forensic

  • @wolfbrave4866
    @wolfbrave48664 ай бұрын

    Imagine one day you sent a sample that could breach through the Sandbox environment. 🤔

  • @bobwyde4026
    @bobwyde40264 ай бұрын

    Your channel is a god send

  • @jesusivanguerrazaldivar8303
    @jesusivanguerrazaldivar83034 ай бұрын

    Wow ! new for me, thanks !

  • @m6yki_
    @m6yki_4 ай бұрын

    Ahh yess, this is a great video. But TPS, how do we know what is a walware or what executable is a malware?

  • @shadowstorm657
    @shadowstorm6574 ай бұрын

    Amazing video thank you

  • @fernandohg225
    @fernandohg2254 ай бұрын

    Good to know !!!

  • @gamereditor59ner22
    @gamereditor59ner224 ай бұрын

    Nice!! Where can I get it?

  • @Fortexik
    @Fortexik4 ай бұрын

    1:26 What do you use for iCloud Drive and Photos right in the explorer, please?

  • @ripleyhrgiger4669
    @ripleyhrgiger46694 ай бұрын

    PC Guy, is what canta is doing what cloud scanners do when you submit samples to them?

  • @hoteny
    @hoteny4 ай бұрын

    My friend got his many accs stolen somehow, instagram shows no logs of ips while steam showed morocco. So, we think its his google chrome cookies and possibly account (but no session exists outside his own devices as we checked), not passwords though?, but maybe the pc itself was controlled? So anyway, since he cant format rn, we had to just use many tools you mentioned. We dont know if this is enough. Do you think we should do anything extra?

  • @WilfredoCayabyab
    @WilfredoCayabyab10 күн бұрын

    do you have anything for remote access tool analysis??

  • @guilherme5094
    @guilherme50944 ай бұрын

    👍Thanks.

  • @AlexAlex-869
    @AlexAlex-8692 ай бұрын

    Super cool!

  • @mnageh-bo1mm
    @mnageh-bo1mm4 ай бұрын

    hmm what about something like that online automated sandbox but offline?

  • @AgonTheFirst
    @AgonTheFirst4 ай бұрын

    Hello, how to analyze dll file. with cape... Example: Some software basically has nothing until they download a DLL file to perform their task.

  • @maketank
    @maketank27 күн бұрын

    It would be very helpful if you posted the official links to the software you present across your videos. There are also lots of duplicates from other sources.

  • @Thedude897
    @Thedude8974 ай бұрын

    This dude called the security channel is seriously plugging nord

  • @tienatnguyen3412
    @tienatnguyen34123 ай бұрын

    Do we have any ransomware Stop djvu online ID solutions ?

  • @moormoor4281
    @moormoor42814 ай бұрын

    Any thing too help recover off lost data on android

  • @projectzsavage
    @projectzsavageАй бұрын

    how to acces triage vms?

  • @azizgoi2066
    @azizgoi20663 ай бұрын

    How do we know if our computer is infected with malware stealer which is 100% FUD?

  • @Skul1ybe
    @Skul1ybe4 ай бұрын

    Cool

  • @lewangandrover6441
    @lewangandrover64414 ай бұрын

    🔥

  • @hakusu
    @hakusu4 ай бұрын

    Win 11 Home or Pro? :)

  • @rutera24
    @rutera244 ай бұрын

    Мan, provide the links you show!

  • @SM-1010

    @SM-1010

    4 ай бұрын

    He can b extremely bland

  • @TheHeroHunterGarou
    @TheHeroHunterGarou19 күн бұрын

    Can you please scan crack game made by empress group because the emp.dl is detected by windows defender and i dont know if its safe or not

  • @lolcorporation7308
    @lolcorporation73084 ай бұрын

    Any.run and intizer

  • @TruthNTime
    @TruthNTime4 ай бұрын

    Off topic - I have had Comodo Antivirus installed for about 3 years and I want to uninstall it because it's taking up too much disc space. However, I read from a few different people that it's very hard to uninstall and it could also cause your system to start acting up because of residual files it leaves on your system after uninstalling it. Now I'm kind of wary to uninstall it. Is there any truth to what they are saying, or is there some sort of certain way to uninstall it so it doesn't cause problems? Please help...?

  • @HamedEmine

    @HamedEmine

    4 ай бұрын

    Bulk Crap Uninstaller (in short BCUninstaller or BCU) is very effective with "residual files", you might want to give it a try!

  • @marcfabricatore1506

    @marcfabricatore1506

    4 ай бұрын

    Reinstall Windows

  • @marcfabricatore1506

    @marcfabricatore1506

    4 ай бұрын

    @@absolutemadchad8637 Sometimes not even the Uninstaller from the company’s work which is why I recommended reinstalling

  • @aBc-123-XyZ

    @aBc-123-XyZ

    4 ай бұрын

    Try to remove the program in safe mode.

  • @duplicake4054

    @duplicake4054

    4 ай бұрын

    Just use the built-in uninstall tool. Go to add or remove programs > comodo > uninstall. I don't recommend uninstalling it though because it's really good.

  • @Agony.
    @Agony.4 ай бұрын

    Anyone know why I can't see youtubers profile pics on the home page, BUT it goes back to normal when I switch accounts?

  • @niamotullah99
    @niamotullah994 ай бұрын

    Running Malware analysis tool into a Malware

  • @lewiskelly14
    @lewiskelly144 ай бұрын

    How can I trust you with that choice of sponsor and you don't bother to link the software and websites you talk about in the description?

  • @luddedagoat3599
    @luddedagoat35992 ай бұрын

    Can i get infected from seeing the live sandbox and get it on my main pc.

  • @amniositynew

    @amniositynew

    3 күн бұрын

    no

  • @ARabdurrahmanar
    @ARabdurrahmanar4 ай бұрын

    Nice🥰

  • @gir489returns2
    @gir489returns24 ай бұрын

    If it contains a cryptominer, wouldn't they want it uploaded to a VM like this with a lot of hardware and ran? Seems like you're doing them a favor by running it at all.

  • @jackjack3358

    @jackjack3358

    4 ай бұрын

    If you think a crappy a few gigs RAM VM is capable of mining anything at all i have bad news to you, and VMs get generated and destroyed after each run so it can't do anything even if it was capable of mining

  • @user-jm8sy5ox2j

    @user-jm8sy5ox2j

    4 ай бұрын

    No, a VM is worst case scenario for any kind of malware attacker because generally you destroy the VM entirely after using it. A VM is typically sandboxed too so the malware has no chance to spread itself before the VM is destroyed too

  • @kkekang7
    @kkekang74 ай бұрын

    Scamio by BitDefender?

  • @MTGeomancer

    @MTGeomancer

    4 ай бұрын

    I just copied and pasted a link from a phishing email in my spam folder to Scamio. It said there was nothing suspicious and probably not a scam. I wouldn't trust it, at all.

  • @kent_calvin
    @kent_calvin4 ай бұрын

    Were those bullets

  • @HazzyDevil
    @HazzyDevil4 ай бұрын

    I recommend any.run and joe’s sandbox as well

  • @CaptainMC554
    @CaptainMC5544 ай бұрын

    Leo

  • @dismalbreadmaps
    @dismalbreadmaps4 ай бұрын

    Mandient is owned by Google

  • @onegenius6390
    @onegenius63904 ай бұрын

    HEY, HOW ABOUT LINKS TO THESE TOOLS? 🤔

  • @RK-ly5qj
    @RK-ly5qj4 ай бұрын

    Madiant account were hacked on twitter xD

  • @robloxfan4271
    @robloxfan42713 ай бұрын

    don't forget virus total

  • @lukehjo
    @lukehjo4 ай бұрын

    Process Monitor but worse.

  • @lussor1
    @lussor14 ай бұрын

    You got sponsored by the scummy Nord, but hopefully the viewers know that the VPN is bad

  • @adamion1993
    @adamion19933 ай бұрын

    He has very good info but the vpn bullshit is annoying, I get that for a channel that is about cybersec there aren't many sponsor options but cmon a vpn doesn't do anything...encryption this encryption that literally every site is "peer to peer encrypted" or whatever their buzzword is it has never stopped anyone from doing anything ever...great advice but I see vpn ads everywhere and it's just disheartening

  • @KonuralpBalcik
    @KonuralpBalcik4 ай бұрын

    There are only 2 viruses in Windows, one is Edge and the other is Defender, no matter how much you delete and block them, they download and install themselves without asking anything. 🤣

  • @freezeadq8748
    @freezeadq87483 ай бұрын

    but any of these tools can anylize a simple encrypted .luac file...

  • @truefeelings7
    @truefeelings74 ай бұрын

    i used this tool for manipulating my frnds not in bad way ... installed on his laptop 🤣🤣 7 years back 1st tool

  • @gta5anti-griefer882
    @gta5anti-griefer8824 ай бұрын

    🗿

  • @spypath5616
    @spypath56164 ай бұрын

    Leoo

  • @Waryam2
    @Waryam24 ай бұрын

    1 st comment

  • @Waryam2
    @Waryam24 ай бұрын

    1 comment

  • @Idkwholmao
    @Idkwholmao4 ай бұрын

    Leo :)

  • @godbacchus
    @godbacchus4 ай бұрын

    15 hackers have seen this video so far... lol 👎

  • @unguidedone
    @unguidedone4 ай бұрын

    if your looking at a executable then the tool of choice is ghidra. you can also use ida pro if on windows or reflector. if your looking at network activity then wireshark works fine. i am disappointed at the videos lack of technical ability and this is coming from someone who has very basic computer ability skills 2/10 lol.

  • @Nick41622
    @Nick416224 ай бұрын

    You don't need a third-party antivirus. It is far more important to update your PC & browser. This is your first line of defence. Windows security is all you need. You don't need none of this shit!

  • @Epic-so3ek
    @Epic-so3ek2 күн бұрын

    BOO nord vpn 👎👎👎

  • @logikaibukfenc4599
    @logikaibukfenc45994 ай бұрын

    any.run

  • @janmillerty4528
    @janmillerty45284 ай бұрын

    Leo

  • @ayush0477
    @ayush04774 ай бұрын

    Leo

  • @xxXKogasaWe3dL0rd420Xxx
    @xxXKogasaWe3dL0rd420Xxx4 ай бұрын

    Leo

  • @abhilashsingh2576
    @abhilashsingh25764 ай бұрын

    Leo

  • @arpitbala8042
    @arpitbala80424 ай бұрын

    Leo

  • @saigoo6445
    @saigoo64454 ай бұрын

    Leo

  • @slyant630
    @slyant6304 ай бұрын

    Leo

  • @MiniFishDabz
    @MiniFishDabz4 ай бұрын

    Leo

  • @NxVernxual
    @NxVernxual4 ай бұрын

    Leo

  • @WololoWololo2
    @WololoWololo24 ай бұрын

    Leo

  • @fell_eagle5093
    @fell_eagle50934 ай бұрын

    Leo

  • @Xsiayd
    @Xsiayd4 ай бұрын

    Leo

Келесі