Skip to content

Hide Navigation Hide TOC

Function: Reverse engineering (679596e0-afd5-5e54-ba56-716d47e1a1aa)

To provide a deeper analysis of malware artefacts to include identifying hidden actions and triggering commands. Reverse engineering allows the analyst to dig past any obfuscation and compilation (for binaries) and identify the program, script, or code that makes up the malware, either by uncovering any source code or by disassembling the binary into assembly language and interpreting it. The analyst uncovers all of the machine language exposed functions and actions the malware can perform. Reverse engineering is a deeper analysis that is carried out when surface and runtime analysis do not provide the full information needed.

Cluster A Galaxy A Cluster B Galaxy B Level
Function: Reverse engineering (679596e0-afd5-5e54-ba56-716d47e1a1aa) FIRST CSIRT Services Framework Service: Artifact and forensic evidence analysis (eda3b2d9-4a66-5803-98c7-e87bb8068b97) FIRST CSIRT Services Framework 1