Malware 2-4
20.11.2013
3 things ?
5 cents from me
5 cents from me
5 cents from me
5 cents from me
5 cents from me
5 cents from me
Plan for today
Your presentations
Clarification on processor aridecture
Network forensic ..
Lab time
Presentations ?!
Clarification on processor architecture
Network ...
Lab
Hints and other pcap
Enisa Pcap lab +
Pcap1 < even
or
Pcap2 < odd including 0
Results
Malware what is downloaded
Where from is downloaded
Any C&C or P2P connection data .
Timeline.
Snort or Suricata rule do detect.
How you did it ?
network lab ideas
suricata -l /folder/where /log/goes -r startstop.pcap
snort -qdexNA cmg -c all.rules -r startstop.pcap
�