Avatar

As malware researchers, we spend several days a week debugging malware in order to learn more about it. For that, we have several powerful and popular user mode tools to choose from, such as OllyDbg, x64dbg, IDA Pro and Immunity Debugger.

All these debuggers utilize some scripting language to automate tasks, such as Python or proprietary languages like OllyScript. When it comes to analyzing in kernel mode, there is really one one option: Windows debugging engine and its interfaces cdb, ntsd, kd and WinDbg.

Read more about this here.



Authors

Talos Group

Talos Security Intelligence & Research Group