#FOR610
📌 SANS Stormcast Episode Highlights Cybersecurity Tools and Git Vulnerability https://www.cyberhub.blog/article/28550-sans-stormcast-episode-highlights-cybersecurity-tools-and-git-vulnerability
SANS Stormcast Episode Highlights Cybersecurity Tools and Git Vulnerability
The July 9, 2026, episode of the SANS Internet Storm Center Stormcast, presented by Johannes Ullrich from Jacksonville, Florida, introduced three key cybersecurity topics. The first was Stack Simulator, a web-based learning tool developed for the SANS FOR610 (Reverse Engineering Malware) course, designed to help users understand stack operations, pointer manipulation, and command execution in exploit development and malware analysis. The second tool discussed was rootasrole, a Linux privilege management utility that enables granular assignment of capabilities to users, unlike traditional sudo, though it is currently only natively supported on Arch Linux and requires manual compilation for other distributions. The episode also highlighted a supply chain security vulnerability identified by Jacob Guinness of Carnegie Mellon University, demonstrating how Git commit signatures and hashes can be spoofed due to inconsistent normalization in GitHub and local Git implementations, allowing attackers to create valid signatures for malicious commits. The issue underscores the need for bug fixes in Git and GitHub while raising awareness of potential detection methods.
www.cyberhub.blog
September 21, 2026 at 12:37 PM
Some Malicious PE Stats, (Thu, Aug 27th)

During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we…
#hackernews #news
Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
isc.sans.edu
August 29, 2026 at 4:44 AM
An Example of Stack String in High Level Language, (Sat, May 23rd)

This week, I'm attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control”). From my point of view, this training fits perfectly with FOR610 or FOR710 (m…
#hackernews #news
An Example of Stack String in High Level Language, (Sat, May 23rd)
This week, I'm attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control”). From my point of view, this training fits perfectly with FOR610 or FOR710 (malware analysis) because it addresses malware from the opposite: Instead of performing reverse engineering, you write malicious code! Always interesting to have another point of view.
isc.sans.edu
May 24, 2026 at 9:25 AM
An Example of Stack String in High Level Language, (Sat, May 23rd) This week, I’m attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Cont...

#Malware #News

Origin | Interest | Match
An Example of Stack String in High Level Language, (Sat, May 23rd)
This week, I’m attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control”). From my point of view, this training fits perfectly with FOR610 or FOR710 (malware analysis) because it addresses malware from the opposite: Instead of performing reverse engineering, you write malicious code! Always interesting to have another point of view. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using co...
malware.news
May 23, 2026 at 7:17 AM
2026 64-Bits Malware Trend, (Mon, Feb 16th)

In 2022 (time flies!), I wrote a diary about the 32-bits VS. 64-bits malware landscape[1]. It demonstrated that, despite the growing number of 64-bits computers, the "old-architecture" remained the standard. In the SANS malwa…
#hackernews #microsoft #news
2026 64-Bits Malware Trend, (Mon, Feb 16th)
In 2022 (time flies!), I wrote a diary about the 32-bits VS. 64-bits malware landscape[1]. It demonstrated that, despite the growing number of 64-bits computers, the "old-architecture" remained the standard. In the SANS malware reversing training (FOR610[2]), we quickly cover the main differences between the two architectures. One of the conclusions is that 32-bits code is still popular because it acts like a comme denominator and allows threat actors to target more Windows computers. Yes, Microsoft Windows can smoothly execute 32-bits code on 64-bits computers. It is still the case in 2026? Did the situation evolved?
isc.sans.edu
February 17, 2026 at 2:08 AM
Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)

When I'm teachning FOR610[1], I always say to my students that reverse engineering does not only apply to “executable files” (read: PE or ELF files). Most of the time, the infection path involves many stages to defe…
#hackernews #news
Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)
When I'm teachning FOR610[1], I always say to my students that reverse engineering does not only apply to “executable files” (read: PE or ELF files). Most of the time, the infection path involves many stages to defeat the Security Analyst or security controls. Here is an example that I found yesterday. An email was received via an attached ZIP archive. It contained a simple file: “Payment_confirmation_copy_30K__202512110937495663904650431.vbs” (SHA256:d9bd350b04cd2540bbcbf9da1f3321f8c6bba1d8fe31de63d5afaf18a735744f) identified by 17/65 antiviruses on VT[2]. Let's have a look at the infection path.
isc.sans.edu
November 14, 2025 at 3:32 AM
Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th) When I’m teachning FOR610[1], I always say to my students that reverse engineering does not only apply to “executable files” (read...

#Malware #News

Origin | Interest | Match
Formbook Delivered Through Multiple Scripts, (Thu, Nov 13th)
When I’m teachning FOR610[1], I always say to my students that reverse engineering does not only apply to “executable files” (read: PE or ELF files). Most of the time, the infection path involves many stages to defeat the Security Analyst or security controls. Here is an example that I found yesterday. An email was received via an attached ZIP archive. It contained a simple file: “Payment_confirmation_copy_30K__202512110937495663904650431.vbs” (SHA256:d9bd350b04cd2540bbcbf9da1f3321f8c6bba1d8fe31...
malware.news
November 13, 2025 at 10:19 AM
FOR610: Reverse-Engineering Malware: Malware Analysis Tools and TechniquesAdvancedQuick view FOR610: Reverse-Engineering Malware: Malware Analysis Tools and TechniquesAdvancedFOR610Digital Forensic...

Origin | Interest | Match
Digital Forensics and Incident Response Training | SANS Institute
Learn about SANS Digital Forensics courses, training and certifications as well as an extensive suite of free Digital Forensics resources.
www.sans.org
August 13, 2025 at 11:26 AM
SANS FOR610 is a potent gateway drug
July 21, 2025 at 3:13 PM
FOR610: Day 3 ✅, last hour or so kicked my tookis but better for it (inshallah)
July 16, 2025 at 9:48 PM
FOR610: Day 1 of 6 wrapped at SANSFIRE I can’t say enough good things
July 14, 2025 at 9:40 PM
I’ve been working on improving the 3rd party integrations with MalChela (the updated release is coming soon). To really test the capabilities, I’ve been working through a bunch of the static analysis labs from FOR610.
May 2, 2025 at 2:40 AM
@xme I assume you've seen the #bsidesluxembourg2025 date and announcement? Even if you can't attend (can you? will you?) please share it on your various profiles for us?
Xavier Mertens 🇧🇪 (@xme@infosec.exchange)
118 Posts, 46 Following, 816 Followers · Freelance | Blogger | SANS ISC Handler | FOR610 & FOR710 Instructor | BruCON Co-organizer | BlueTeam | DFIR | Drones | MTB | PGP: 0x42D006FD51AD7F2C | Msgs are mine!
infosec.exchange
April 25, 2025 at 11:25 AM
XORsearch: Searching With Regexes, (Mon, Apr 7th)

Xavier asked me a question from one of his FOR610 students: "how can you perform a regex search with XORsearch"?

#hackernews #news
XORsearch: Searching With Regexes, (Mon, Apr 7th)
Xavier asked me a question from one of his FOR610 students: "how can you perform a regex search with XORsearch"?
isc.sans.edu
April 8, 2025 at 8:25 AM
Shellcode Encoded in UUIDs, (Mon, Mar 10th)

I returned from another FOR610[1] class last week in London. One key tip I give to my students is to keep an eye on "strange" API calls. In the Windows ecosystem, Microsoft offers tons of API calls to developers. The fact th…

#hackernews #microsoft #news
Shellcode Encoded in UUIDs, (Mon, Mar 10th)
I returned from another FOR610[1] class last week in London. One key tip I give to my students is to keep an eye on "strange" API calls. In the Windows ecosystem, Microsoft offers tons of API calls to developers. The fact that an API is used in a program does not always mean we are facing malicious code, but sometimes, some of them are derived from their official purpose. One of my hunting rules for malicious scripts is to search for occurrences of the ctypes[2] library. It allows Python to call functions in DLLs or shared libraries.
isc.sans.edu
March 11, 2025 at 2:02 AM
📌 Cybersecurity analyst advises monitoring unusual API calls in Windows. Some can be misused. Watch for ctypes library in malicious scripts. #CyberSecurity #Windows https://tinyurl.com/29cqh8tn
Cybersecurity Analyst Shares Key Advice on Monitoring API Calls in Windows
A cybersecurity analyst recently returned from a FOR610 class in London, where he shared a crucial piece of advice: monitoring "strange" API calls within the Windows ecosystem. Although API calls are not always malicious, some can be misused from their intended purpose. A hunting rule for malicious scripts is to look for occurrences of the ctypes library, which allows Python to call functions in DLLs or shared libraries.
tinyurl.com
March 10, 2025 at 12:20 PM
Let’s wrap up the week with the malware analysis tournament! Wanna join the fun? My next class is in March in London #FOR610 #SANSEMEA
January 25, 2025 at 8:15 AM
Make Malware Happy, (Mon, Jan 6th)

When I teach FOR610[1], I like to use a funny quotation with my students: “Make malware happy!” What does it mean? Yes, we like malware, and we need to treat it in a friendly way. To help the malware work or detonate successfully, it's reco…

#hackernews #news
Make Malware Happy, (Mon, Jan 6th)
When I teach FOR610[1], I like to use a funny quotation with my students: “Make malware happy!” What does it mean? Yes, we like malware, and we need to treat it in a friendly way. To help the malware work or detonate successfully, it's recommended that we replicate the environment where it was discovered (or at least, as much as possible). This is not always easy because we often receive a sample outside of its context.
isc.sans.edu
January 10, 2025 at 8:14 PM
My last #FOR610 run for this year! Welcome Frankfurt!
December 9, 2024 at 7:16 AM
What's new in the FOR610: Reverse-Engineering Malware Analysis course in 2017 http://crwd.fr/2oKcq1d
@sansforensics #DFIR
December 1, 2024 at 5:23 AM
Then there was 4... #SANSLondon #FOR610 #tired
December 1, 2024 at 5:03 AM
Just wrapped on FOR610 at #SANSLondon. Another fantastic SANS course. Thanks @hal_pomeranz
December 1, 2024 at 5:03 AM
Scoreboard from FOR610 at #SANSLondon (I managed to scrape into the top five)
December 1, 2024 at 5:03 AM