Cosimo Vergari
Forensic Analysis of Malware: Identification of Indicators of Compromise and Automation of the Investigative Process in Windows and Linux Environments.
Rel. Andrea Atzeni. Politecnico di Torino, Master of science program in Cybersecurity, 2025
|
Preview |
PDF (Tesi_di_laurea)
- Thesis
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (3MB) | Preview |
|
|
Archive (ZIP) (Documenti_allegati)
- Other
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (65kB) |
Abstract
Digital forensic analysis is fundamental for comprehending malware attacks and rebuilding the actions taken by attackers to compromise information systems. Modern malware frequently employs sophisticated persistence and evasion techniques that leave behind evidence, known as Indicators of Compromise (IoCs), on various artefacts, including disk, memory, and network environment. Identifying such IoCs is of prime importance for post-mortem analysis, enabling analysts to infer attacker actions and impact on the system. Nonetheless, the amount and intricacy of forensic data present significant problems, therefore rendering the process laborious and prone to oversights. This thesis examines the identification of IoCs in Windows and Linux environments and explores the combination of automation and AI to assist forensic workflows.
The study focuses on three main areas: file system and disk artifacts, memory dumps, and network traffic
Relators
Academic year
Publication type
Number of Pages
Course of studies
Classe di laurea
URI
![]() |
Modify record (reserved for operators) |
