Тёмный

MALWARE ANALYSIS // How to get started with John Hammond 

David Bombal
Подписаться 2,6 млн
Просмотров 293 тыс.
50% 1

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 351   
@saroarahmed7764
@saroarahmed7764 3 года назад
Yo David, just wanted to thank you for the free courses on Udemy! Being from Bangladesh 🇧🇩 it is difficult (not impossible) for us to make international transaction legitimately through a bank. So, your free courses are kinda life saver!!! So thank you very much!!!
@davidbombal
@davidbombal 3 года назад
I'm really happy to hear that I could help you Saroar 😀
@itsme7570
@itsme7570 3 года назад
That's awesome, David you were a major factor in me signing up for school so thank you for that sir
@toioburrahman7864
@toioburrahman7864 3 года назад
Are you Bangladeshi?
@rubayethassan5615
@rubayethassan5615 3 года назад
Saroar Ahmed.....glad to have you in that channel...I don't know why our Bangladeshi people's don't watch these channels....
@toioburrahman7864
@toioburrahman7864 3 года назад
@@rubayethassan5615 where is your house in Bangladesh?
@davidbombal
@davidbombal 3 года назад
Menu: 0:00 ▶ Pretty sketchy stuff! 0:37 ▶ Welcome John Hammond 0:53 ▶ Don't divide cyber in your mind 2:00 ▶ John's day job 3:17 ▶ Hacker's crafty methods 4:02 ▶ Will AI take jobs away? 4:55 ▶ How do I become like you? 5:35 ▶ Windows is very important 6:12 ▶ Malware vs CTFs 6:32 ▶ Is Malware mainly on Windows systems? 7:28 ▶ Always comes back to the same thing 8:50 ▶ Practical Example 9:29 ▶ John's setup 11:42 ▶ Python malware example 12:50 ▶ Malware code 15:50 ▶ Bad guys can sell this information 16:30 ▶ But this is in the clear? 17:14 ▶ Obfuscated version 18:28 ▶ Real world? Don't want to touch disk 19:50 ▶ How do I find this stuff 20:58 ▶ Weird Spam SMS messages 21:30 ▶ Real World: Finding malware 23:42 ▶ John's real world company example 24:20 ▶ Real world logic to find malware 25:23 ▶ Detectors 25:48 ▶ Hunting malware 26:25 ▶ Use your eyes - don't trust an automated systems 27:15 ▶ Input from other systems 27:49 ▶ How do I become like you? 28:00 ▶ What kind of skills would you look for in a person to get a job 29:24 ▶ Look at malware sites 30:15 ▶ Build out a library 30:38 ▶ David pushes John for a job on LinkedIn 33:05 ▶ How did John get his job? 33:30 ▶ Use social media 34:31 ▶ How John got his first job 35:55 ▶ It's who you know, not what you know 36:30 ▶ How John got his current job 38:19 ▶ Would you hire someone with certs; or someone you know 39:50 ▶ Windows bat script example 45:08 ▶ Which languages does John know 45:38 ▶ How do you know if it is good or bad code? 46:45 ▶ Office Macros Malware Example 50:40 ▶ Cool Linux command 51:26 ▶ Is this a good job? Are there lots of job? 52:30 ▶ What hours do you work? 53:31 ▶ Any books you recommend? John Hammond Playlist: davidbombal.wiki/johnhammond ================== Web Sites mentioned: ================== Use at your own risk: vx-underground: twitter.com/vxunderground theZoo: twitter.com/vxunderground Malware Bazaar: bazaar.abuse.ch/ Joe Sandbox: www.joesecurity.org/ Any run: any.run/ VirusTotal: www.virustotal.com/gui/home/upload ====== Books: ====== The IDA Pro Book: amzn.to/3DtEATW Black Hat Go: Go Programming For Hackers and Pentesters: amzn.to/3gISKa4 Black Hat Python: Python Programming for Hackers and Pentesters: amzn.to/3ta50FH Python Pocket Reference amzn.to/3mQPME2 Linux Pocket Guide: Essential Commands: amzn.to/2UWBwya Regular Expression Pocket Reference: amzn.to/3gJoP1f Linux Basics for Hackers: Getting Started with Networking, Scripting, and Security in Kali: amzn.to/3Ds22Rq ================ Connect with me: ================ Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal RU-vid: ru-vid.com ================ Connect with John: ================ RU-vid: ru-vid.com Twitter: twitter.com/_johnhammond LinkedIn: www.linkedin.com/in/johnhammond010
@reastle1307
@reastle1307 3 года назад
i got exited from only intro
@tsaltslinger3268
@tsaltslinger3268 3 года назад
Thank you, Mr Bombal.
@roshantiwaree7617
@roshantiwaree7617 3 года назад
David Sir.. I am a student. I want to start my career in cybersecurity specially bug bounty hunting. Please 🥺 suggest me how do I start my journey in cybersecurity. Please 🙏 reply 🥺
@geekmuralin
@geekmuralin Год назад
Thank you
@MisterK-YT
@MisterK-YT 2 года назад
I love the conciseness of this channel. Timestamps, no time wasted, doesn’t talk _too_ much. 👌
@halfdemon88
@halfdemon88 2 года назад
Every time I have a question about something I want to know, you've got a video about it. Thx, bud
@Nicrophelia
@Nicrophelia Год назад
These “old” videos are so under utilized by people trying to get into the industry, this one is a GEM. Seeing where the people I look up to were a couple years ago is super inspiring! One of my favorite parts about both of you is your pursuit of learning, thank you for creating!
@jeezboi5079
@jeezboi5079 3 года назад
These guys are pro in their field and they are so humble and down to earth
@Rake141
@Rake141 3 года назад
My two favorite IT teachers in one video ? Hell yes!! 🔥
@davidbombal
@davidbombal 3 года назад
Thank you Aftab!
@akan1783
@akan1783 3 года назад
What I like about you David is that you ask very relevant questions! Keep it up
@davidbombal
@davidbombal 3 года назад
Thank you Akan
@RAZREXE
@RAZREXE 3 года назад
This is GOLD! I cannot thank you enough David and John, you are the best!
@mbm6048
@mbm6048 3 года назад
Its Finally here,Malware Analysis, Thank you David. Would be nice if you released a Full udemy course on Malware analysis
@anshumishra9368
@anshumishra9368 3 года назад
John and David, has something special about our future
@MoonarkGG
@MoonarkGG 3 года назад
I always disable my adblock and watch the ads on david videos, thanks for the free courses and the amazing content on youtube
@ViolentbyDesign
@ViolentbyDesign 2 года назад
David you have the best content on cyber security by far. There is no one even close! Congratulations
@davidbombal
@davidbombal 2 года назад
Thank you! You are very kind to say that 😀
@aviano5
@aviano5 3 года назад
David you are the best of best. It is hard to find someone like you, who gives amazing courses for free and all these video tutorials. As a cyber security undergraduate, I'm really thankful to you for all your efforts. Wish you best of luck Dav. ❤️💯
@theodoremiskel4057
@theodoremiskel4057 3 года назад
There's always great content on this channel. I went from Help desk to Network Admin to Security admin to IT manager from this channel. Thank you for providing these things to us.
@davidbombal
@davidbombal 3 года назад
That's fantastic Theodore! Thank you for sharing 😀
@randyg666
@randyg666 2 года назад
Nice!!!
@samerkia
@samerkia 3 года назад
I've really been wanting/hoping for something such as this! Thank you so much!!!
@davidbombal
@davidbombal 3 года назад
Thank you Samerkia! You're welcome!
@SpaceOfSoul23
@SpaceOfSoul23 2 года назад
Thank you so much for covering this. I’m on my own journey of getting into cyber security, and have been growing a big interest in malware analysis. I’ve asked around and no one knew what I was talking about. Was getting really discouraged, thanks!!!
@EUU100
@EUU100 3 месяца назад
Hey, did you end up sticking with malware analysis?
@dharunkanna10
@dharunkanna10 3 года назад
Wow David ! really excited with JH series 🥳❤
@RickHenderson
@RickHenderson 2 года назад
Really useful, thanks. As a teacher trying to find work, it was almost difficult to have something to show to potential employers. But as a security Analyst maybe working towards malware analysis - really interesting that John mentions being so out there in the community actually being useful for job hunting. But then I'd have to be careful of NDA and make sure I don't do anything that might put me at cross purposes with my current employer.
@TalsonHacks
@TalsonHacks 3 года назад
As a pentester, I would like to see more of malware analysis and blue team stuff.
@paradoxicaluniverse
@paradoxicaluniverse 3 года назад
Thanks to the universe for 2 good guys like you two. Thanks guys!
@diamondnita1543
@diamondnita1543 2 года назад
John is a genius, I just love humble attitude.....
@gueroloco8687
@gueroloco8687 3 года назад
Love John Hammond and you as well David!! Thanks so much for the help!!!
@oiphellipe
@oiphellipe 2 года назад
David, your questions were perfect. Actually, those were the questions I would like to ask him, because I see John as an example to me. So, thanks for that. Great job. And John, you're a monster!!!! :)
@raginranga3494
@raginranga3494 3 года назад
Many thanks to yourself, John and all your guests for providing Insight 🙏🇦🇺
@keirnbug8762
@keirnbug8762 2 года назад
Man, everything I watch some of your stuff, I always end up going down a different rabbithole , inspireing and fun !
@pranavaraoperuvaje2089
@pranavaraoperuvaje2089 3 года назад
Jhon and David together, that is amazing!!!!!! Big fan of you both also!! The video was amazing. Thank you
@davidbombal
@davidbombal 3 года назад
Thank you Pranava!
@Matheus-lk9lh
@Matheus-lk9lh 3 года назад
Wow, I never see a course cover this topic, thank you David
@yamitvargas8065
@yamitvargas8065 3 года назад
David, once again, Thanks so much, as always great materialand Thanks and amazing job to John Hammond.
@davidbombal
@davidbombal 3 года назад
Thank you so much for your support Yamit!
@Alain9-1
@Alain9-1 3 года назад
What an amazing episode with David and john
@shanecoursen
@shanecoursen 3 года назад
It's nice to see the new guard. Enjoying your vids, David. Thank you.
@Vercingetorix061983
@Vercingetorix061983 2 года назад
I would like to have three attributes of John that I really admire: his knowledge, that hair and that great smile
@liderlink4113
@liderlink4113 Год назад
What I like about David Bombal is that he is here, on RU-vid, to learn and to teach. I really passionate about cybersecurity and you can really tell that he wants to learn. Respect!
@davidbombal
@davidbombal Год назад
Thank you! We can all learn from each other :)
@andre9036
@andre9036 3 года назад
Shamshing content by Sir David and John. Thank you for sharing this. Superb!
@iamkaustubh
@iamkaustubh 3 года назад
Hey David Thanks Man this interview was really very helpful for me i live in india just passed my Diploma in Computer Technology. I am following you since from last 6 months i just watched whole video without skipping anything it influenced me more to learn. Best wishes again David .🔥
@chandranirmal2995
@chandranirmal2995 3 года назад
Tnx sir I watched full video . You are trying to help more people who r financially down. Great job sir tnx 🙏🙏🙏🙏 Love from Tamil Nadu India 🔥🔥🔥🔥👍👍👍👍🙏🙏🙏
@Sparerime
@Sparerime 3 года назад
To me,this is a gold mine! Thank you guys for taking time and educate us 👌🏻👍🏻
@TANKBM
@TANKBM 3 года назад
We thank you, dear teacher, for your valuable efforts for us
@iftikharhusain1
@iftikharhusain1 3 года назад
Hey David thank you so much for the efforts that you put Big thanks 👍
@karanb2067
@karanb2067 3 года назад
I really look up to you and John, glad you discussed this :)!!
@alaahaider
@alaahaider 2 года назад
Great interview, and so much info. Thank you David. I loved the way John broke down the powers hell code in vscode. I find it very useful and smart tip.
@ibrahimabdeltawab6418
@ibrahimabdeltawab6418 Год назад
Thanks so much David and John ❤
@mohammed9033
@mohammed9033 2 года назад
Hey David. Thanks a ton for this, would request you for more such podcasts
@mckeanethomas3830
@mckeanethomas3830 2 года назад
Nuff Respect @ David and @John. Thanks for these contents
@viv_2489
@viv_2489 3 года назад
David thank you for raising all valid questions which one or other may get..
@Bluedragon-co4kb
@Bluedragon-co4kb 2 года назад
@David Bombal Hi David, thank you very much for sharing all your knowledge with special guests!! It helps us all alot in what we are all trying to learn! ^^ 😀
@TiTo_SPB
@TiTo_SPB 3 года назад
David, just wanted to thank you for everything ,,, i just passed my CCNA exam 2 hrs ago
@davidbombal
@davidbombal 3 года назад
Huge congratulations!! That is great news! Well done
@supriyochatterjee4095
@supriyochatterjee4095 3 года назад
Great to see two of the very best together, it's a request if you can make a video regarding the latest scenarios and situations about "Dark Web" and all kinds of security and prevention methods to stay safe from "Dark Web", also have seen some videos on RU-vid about "Paranormal and Creepy" creatures on "Dark Web" so any relevant videos with proper information on whether they are real or not could be very interesting for all to know and explore
@poca1068
@poca1068 Год назад
David, thank you for being you!
@liviupopeanga6581
@liviupopeanga6581 Год назад
Appreciate ! i have a test for crowdstrike advanced threat internship and info helps me getter the piece together ! great job guys !
@infotechyeti
@infotechyeti 3 года назад
Great video and appreciate his presentation. Great to see the way how one has to comb through the script to see the malicious process being executed.
@scottym50
@scottym50 2 года назад
That was a fantastic video. Thanks to the both of you for taking the time to share ed that wealth of information to everyone. Thank you again, I never fail to not learn something from your videos.
@jessh6995
@jessh6995 3 года назад
Good morning David!! Thank you for all you do!
@davidbombal
@davidbombal 3 года назад
Good morning Jess. Thank you!
@razorr1920
@razorr1920 2 года назад
Hey, David. I take your paid courses on Udemy just for the reason that you're a great community uplifting power. My sincere appreciation for your efforts. Also, your sessions like this are quite enjoyable. Pls do keep them coming.
@jwdory
@jwdory 2 года назад
Very interesting video! John just touched on how to set up a secure environment to investigate malware. A video with more detail on how to set up a secure environment would be of value.
@divakarbisht7951
@divakarbisht7951 3 года назад
Man I just Love David Collab with such Pros Keep up the good work David 🥳
@davidbombal
@davidbombal 3 года назад
Thank you Divakar
@cacurazi
@cacurazi 2 года назад
8:16 John is so humble... god damn it John...
@godstimenkechi7779
@godstimenkechi7779 Год назад
Astounding work *EXELASUPPORT* - so euphoric you are out there battling these failure. We recognize that ought to do all that we can for save the more settled and the overall people from these contemptible mutts! Approval to YOU!! You merit the Nobel prize for safeguarding us epic up family
@GoonCity777
@GoonCity777 3 года назад
Once somebody does Python, they may be finding some enjoyment in working with C++ or Rust or Win32 API in Python using CTypes for the purpose of Malware Analysis. Working "low-level" close to the metal will really help anyone's overall professional skills & and make even better network automation tools because low-level can do things that abstract libraries cant. The Malware Analysis spoke to me with the Win32 API being important in finding viruses in Assembly Language. Also, the free giveaway of Ethical Hacking made the previous hacking videos about Red & Blue team clearer
@JasonDavisWebDeveloper
@JasonDavisWebDeveloper 2 года назад
Interesting to me is videos like this. I’ve actually done the exact same things in my path to becoming a programmer over the years and just for how it was exploring, for fun. So I guess I keep discovering things that I have experience in but didn’t realize that these other jobs existed. Very cool. Loving the content thank you 🙏
@sp3ct3r71
@sp3ct3r71 3 года назад
great job mr.david badly wanted to see collobaration with john...thankz🥰❤🔥
@XtremuZ
@XtremuZ 3 года назад
Great content, thanks for this collab!
@donnie1581
@donnie1581 3 года назад
Loved this interview! you both are awesome!
@hamzahouri8647
@hamzahouri8647 3 года назад
David you are great teacher, i follow you from Morocco. You are best and your course very helpful than university.
@billiraydray
@billiraydray 3 года назад
Dear David thank you for all the free courses on Udemy. I'm benefiting a lot from these courses.......hoping to repay you back in future LOVE all the way from Sierra Leone...............
@LightVibrationPresenseKindness
great content david! kudos to john
@nallachi2913
@nallachi2913 3 года назад
I really thanks to both of you with lot of love ❤️❤️
@b33tleosint15
@b33tleosint15 3 года назад
You did a great job david...fully respect you but can you make a video on creating CTFs
@mbm6048
@mbm6048 3 года назад
When it comes to Malware Analysis always Remember this quote "Documentation is lies ,Source is abstraction but Assembly is the key 🔑 " Hope you get the message
@mayavik1034
@mayavik1034 3 года назад
Wow playa...genius stuff..
@smnomad9276
@smnomad9276 2 года назад
no one got the message bro, speak english.
@rayamoooooo685
@rayamoooooo685 2 года назад
@@smnomad9276 ingles
@imt3206
@imt3206 2 года назад
@@smnomad9276 hahaha. Still don’t get it? I’ll explain it if you haven’t understood
@imt3206
@imt3206 2 года назад
@@rayamoooooo685 no, message is in British.
@m.almansoori9726
@m.almansoori9726 2 года назад
Well done and thanks for the amazing contents
@vijayshinde8356
@vijayshinde8356 3 года назад
Yay! John is here too
@guilherme5094
@guilherme5094 3 года назад
That was great. Thanks David and John.
@ibrahimyosif
@ibrahimyosif 3 года назад
great video, you should do more collabs like this.
@specialmoments_clip
@specialmoments_clip 3 года назад
Hi devid it's great video but I waiting for video for WiFi adaptors increase a TX power use a main three factors 1.domain regularly code for a contry,2.hardware like usb port limitetion milliampere power power usb hub for increasing milliampere power and last 3. With wifi adaptor which type of attack we perform like package injection , vertual mobile towers type of bands we scan! Thank you!
@Riborwahz
@Riborwahz 3 года назад
*John Hammond* he look like a good person he welcome us and we welcome him
@oy9804
@oy9804 3 года назад
continue this course David because we need to know about Malwer Analysis also ❤️
@davidbombal
@davidbombal 3 года назад
Thank you
@uzumakiuchiha7678
@uzumakiuchiha7678 3 года назад
I thought I will watch for two minutes switching between titles and here I am writing this comment after the end watching from starting to end without switching 😄. That's how interesting it gets🎉
@davidbombal
@davidbombal 3 года назад
Fantastic! Happy to hear that 😀
@adamsnetiker
@adamsnetiker 7 месяцев назад
I feel like it’s hard to name specifics. I’m struggling with this one because it’s exactly what I wanna know and do. As far as a resume… is it C? Python? Assembly? IDApro and other tools? What should actually be on a resume to avoid the trash pile - and if I don’t know it, what specific things do I need to learn and what do I need to be able to demonstrate? Example: TryHackMe is good, but WHAT should I do on there? John showed an obfuscated Bash script - how deeply do I need to know Bash and Powershell? How do I learn to identify and interpret the obfuscation?
@mangeshgupta5677
@mangeshgupta5677 3 года назад
Awating for solar winds analysis , great job 👍❤️
@ajaybalaji4937
@ajaybalaji4937 3 года назад
Just now started internship in malware analysis field great recommendation
@davidbombal
@davidbombal 3 года назад
All the best Ajay
@ajaybalaji4937
@ajaybalaji4937 3 года назад
@@davidbombal thank u sir need some resources regarding malware analysis
@jesussaeta8383
@jesussaeta8383 3 года назад
Wow David incredible stuff, Thank you you are incredible.....and Kudos to Mr. Hammond as well .....
@davidbombal
@davidbombal 3 года назад
Glad you enjoyed it 😀
@TamaRe
@TamaRe 2 года назад
Hi David, love your content. I recently gained my ccna cert, wondering what to do next, I've only installed security cameras thus far which wasn't part of the course.. lol
@jessh6995
@jessh6995 3 года назад
David you have a heart of gold!
@davidbombal
@davidbombal 3 года назад
Thank you Jess
@kostudas1
@kostudas1 2 года назад
I LOVE John Hammond
@Kicsa
@Kicsa 3 года назад
Thanks for this insightful video!
@mahendrakathe
@mahendrakathe 2 года назад
This was a great insight in malware stuff , at least a good content to start with , I would like to thank you both David and John for bringing this to your viewers. However I have one question for both of you here , as john was showing he has collected all those malware samples on his Linux(ubuntu) box , I hope there were no malware detection software like AV, end point security etc. , had that been a case we would have a hard time opening those files in editors and IDEs for analysis, Do you guys agree with me here ? . Since we are not protected in such environment what precaution we should take while doing analysis of these malware samples ? How do we deal with this malware samples in real world environment ? Do we have kind of some isolated environments or sandboxed environment where we analyze these samples ? . if yes , Can you guys pour some light on how to create such environment as a part of one's home lab ?
@gjsatru3383
@gjsatru3383 3 года назад
Omg such an important topic david and John great work guys you are just making hacking with a robust approach . David please say thanks to John from me .
@davidbombal
@davidbombal 3 года назад
Thank you Sunil
@jenniferbatt3548
@jenniferbatt3548 2 года назад
Still working as of today, ty!
@rgk1579
@rgk1579 3 года назад
David , you are superb ... You have to make Heath adams join in your army .. Super cool to see you interact with all these experts
@davidbombal
@davidbombal 3 года назад
Thank you
@alvionjames5925
@alvionjames5925 2 года назад
So great content ...BEST!!👌👌
@PerumalJegan
@PerumalJegan 3 года назад
Wow, What a coincidence!!!! just before a while I was searching for malware analysis videos... Also I am david and john's fan boy !!!, so I love this very much ...
@davidbombal
@davidbombal 3 года назад
Very happy to hear that Perumal
@rayanjames3050
@rayanjames3050 3 года назад
Tuned in from Africa 🌍
@davidbombal
@davidbombal 3 года назад
Welcome Africa!
@commanderxcod9291
@commanderxcod9291 3 года назад
Again high level information thanks sir.
@purpl3grape
@purpl3grape 3 года назад
18:44 "They never want to touch discs" sounded dirty as hell hahaha
@umangmishra7505
@umangmishra7505 3 года назад
Thank you. you are future of next gen
@snafulegend6689
@snafulegend6689 2 года назад
The batch file you can replace all the characters easily and see what's actually being done.
@mosaabmorgan8302
@mosaabmorgan8302 3 года назад
I love u man u are the best one on RU-vid ❤❤
@bonnieblue-blade7376
@bonnieblue-blade7376 3 года назад
Subscribed to John...💝
@chathurakariyawasam8675
@chathurakariyawasam8675 3 года назад
Most waited moment..! ❤
@s.aravindh6227
@s.aravindh6227 3 года назад
Nice video bro 👍👍👍👍👍👍👍👍👍👍👍
Далее
Hacking Tools (with demos) that you need to learn in 2024
1:27:34
V16 из БЕНЗОПИЛ - ПЕРВЫЙ ЗАПУСК
13:57
When you Accidentally Compromise every CPU on Earth
15:59
Ex-NSA hacker tools for real world pentesting
1:16:40
Просмотров 1,1 млн
Hacker hunting with Wireshark (even if SSL encrypted!)
1:07:16
2022 Cybersecurity roadmap: How to get started?
25:22
Просмотров 929 тыс.