Required tools for analysis
After acquiring and preparing the required hardware and software to build your private sandbox, let us introduce the required tools to analyze the suspected files in the sandbox. The tools are divided into two types:
- Static analysis tools
- Dynamic analysis tools
Static analysis tools
Static analysis tools are the tools that will be used to collect and analyze information about the suspected file without execution. The static analysis tools that we will install on our private sandbox are as follows:
- YARA: YARA is a tool aimed at (but not limited to) helping malware researchers identify and classify malware samples. We will use the YARA tool to scan the suspected files for certain malware characters to identify the malware category and family if detected. Examples of malware categories are ransomware, Trojans, and InfoStealer, and examples of malware families are Redline, Ryuk, and Zeus. To download the YARA tool, follow this link...