ISC StormCast for Thursday, May 30th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, May 30th, 2019 edition of the San Antonio Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:08.8 | I'm recording from San Antonio, Texas. |
| 0:13.0 | Xavier today provided a quick write-up in how to do behavioral malware analysis using Microsoft's attack surface analyzer. This tool was |
| 0:24.2 | originally released in 2012 but just about a month ago Microsoft did release version |
| 0:31.3 | 2 of the tool. The idea of the tool is to compare systems before and after you ran the malware and it will |
| 0:40.5 | summarize some of the significant changes, like for example, changes to the file system, added |
| 0:47.0 | user accounts, services, certificates, network ports, and changes to the registry. |
| 0:54.4 | Sure, you can probably come up with other things that you would like to see in this list, |
| 0:58.9 | and Microsoft is still actively developing the tool, so they may certainly expand this. |
| 1:05.0 | Now, main selling point, of course, it's easy to use, but the one thing that's probably |
| 1:10.0 | often overlooked is this |
| 1:10.9 | is not just a Windows tool. It also works on Mac OS and Linux. Asksaville explains this is |
| 1:19.5 | sort of a pretty neat tool to use in a quick triage of malware. It doesn't give you the complete |
| 1:24.3 | picture, but hopefully enough to tell you whether or not it's |
| 1:28.4 | worthwhile spending more time analyzing the particular malware sample that you're looking at. |
| 1:35.1 | Also up to now Malver is not looking for this tool like many other tools that may change how |
| 1:43.9 | Malver behaves. Now this of that may change how malware behaves. |
| 1:45.7 | Now, this, of course, may change if more people become familiar with this tool |
| 1:50.6 | and if it's more and more used to actually analyze malware. |
| 1:56.6 | And if you are using Docker, be aware. |
| 1:59.9 | A new vulnerability has been patched in all versions of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

