App Review Malware Theory - Understanding .NET Streams and Metadata

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
struppigel

struppigel

Super Moderator
Thread author
Verified
Staff Member
Well-known
Forum Veteran
Apr 9, 2020
666
5,865
1,280
Germany
Malware analysts often need to quickly determine the context of strings they see in the hex editor. Understanding of file formats greatly helps to do that. This video discusses basic .NET headers, named streams and scratches the surface of .NET metadata. It also helps in writing hunt or detection signatures.