Windows Userland Reverse
Engineering (Basic Course)
Methodology, Tools and Techniques
© Jannis Kirschner ( @xorkiwi )
Windows/NT Architecture
Windows NT Architecture (Simplified)
IA32 Architecture (Simplified)
PE Files
Windows RE Methodology
Save
Hash/Name/Size/
Etc
Detect Binary
Type/Packer
Use Disassembler for
Purpose/Overview
Debug Critical Parts
Unpacking
Remove Anti
Reversing Tricks
Tools
Dissassemblers
Tools
Debuggers
Tools
PE/Packer Identifiers
Tools
PE Editors
Tools
Hex Editors
Tools
Behavioural

Windows Userland Reverse Engineering [SHC19]