03Reading Room

The pile on the corner of the desk.

Not a syllabus. The books I actually reopen when a sample starts living somewhere I cannot see from user-mode. Each shelf note is mine. The PDF is the book.

00PDF2019No Starch Press

Rootkits and Bootkits

Alex Matrosov, Eugene Rodionov, and Sergey Bratus

The book I hand people when they ask why the kernel still believes the firmware. Boot path, UEFI, and the malware that lives underneath the OS you thought you were analyzing.

rootkitsbootkitsuefiwindows
01PDF2012No Starch Press

Practical Malware Analysis

Michael Sikorski and Andrew Honig

The lab book everyone claims they finished. Static, dynamic, packing, and the first time a sample lies to you on purpose.

malwarereverse-engineeringlabswindows

Under Contruction (Beta) - No Bully, Please 😊