Malicious File Investigation Procedures

Software debuggers will often hook exception handling APIs. In Linux systems, SE_Linux will often hook the sys call table. ... and for Linux, init.d, rcX.d, .bash_profile, .bashrc, /etc/profile, cron and at jobs also. ... and Python scripts, so support libraries for these programming languages may be an indicator of malicious activity. Network ... ................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download