Palo Alto Networks, Inc.
Efficient program deobfuscation through system API instrumentation
Last updated:
Abstract:
Techniques for efficient program deobfuscation through system application program interface (API) instrumentation are disclosed. In some embodiments, a system/process/computer program product for efficient program deobfuscation through system API instrumentation includes monitoring changes in memory after a system call event during execution of a malware sample in a computing environment; and generating a signature based on an analysis of the monitored changes in memory after the system call event during execution of the malware sample in the computing environment.
Status:
Grant
Type:
Utility
Filling date:
23 Dec 2019
Issue date:
23 Mar 2021