Skip to main content

Increasing Visibility by Cracking Password-Protected Malware at Scale

Authors of malicious software seek to protect their malware from being scanned by security solutions such as anti-virus. By encrypting their files with a password, defenders cannot scan the files without first knowing or cracking the password. Defenders can use open-source password cracking tools in conjunction with file scanning utilities to gain visibility into most password-protected malware. Using open source tools, these cracking tools can scale to scan millions of files a day, maximize performance, and to be tuned according to defenders' resources.

40455 (PDF, 0.57MB)

18 Aug 2021
ByDerek Thomas
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.