Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Reverse engineering certification
EH-Net
May 21, 2013, 10:20:04 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Reverse engineering certification  (Read 3069 times)
0 Members and 1 Guest are viewing this topic.
ilduce
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: March 14, 2012, 08:02:46 PM »

Hello EH,

I’m looking to get more into reverse engineering.  I have the option of taking either the Advanced Malware analysis course by the Academy of Computer Education or the Certified Reverse Engineering Analyst course by IACRB (Information Assurance Certification Review Board).  I know that both the CREA and AMA courses are hands on, but I don’t know anything about the certs.  What do you guys think would be the best course to take?  The SANS GREM is out of my reach right now due to the cost of SANS classes.

http://www.iacertification.org/crea_certified_reverse_engineering_analyst.html
http://www.trainace.com/courses/advancedmalwareanalysis/

Thanks!
Logged

OSCP CEH CCNA CISSP
dimo
Newbie
*
Offline Offline

Posts: 18



View Profile WWW
« Reply #1 on: March 27, 2012, 03:45:58 AM »

  I know that both the CREA and AMA courses are hands on, but I don’t know anything about the certs.  What do you guys think would be the best course to take?  The SANS GREM is out of my reach right now due to the cost of SANS classes.

Hi I too would like the same feedback as  ilduce if anyone can shed light on the matter? what certs do employers look for here?
Logged

C|EH C|HFI ECSA Comptia Security +
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 324


View Profile
« Reply #2 on: March 27, 2012, 09:00:46 AM »

When I type GREM into www.indeed.com, I get about 80 results. If I type in CREA, I barely get any results. As of right now, GREM is the certification you would want to get.
Logged

OSCP in progress
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #3 on: March 27, 2012, 11:12:43 AM »

When it comes to malware, experience will trump the cert so you want to get your hands dirty on this. The GREM is not that hard, but it is not an easy exam.

It is considered an advanced forensics course by some so its best to look at it as such. In order to understand malware, you will need to understand a lot (emphasis A LOT) about the system the malware is targeting. This means you need to familiarize yourself with the appropriate tools to perform the appropriate function: Watch memory, the registry, file system, honeypots, networking.

GREM as a class was a pretty cool course but experience and tinkering on your own will yield you greater results AFTER the exam. For that, I recommend labbing up REMNUX, Virtualbox over VMWare, heading to Contagiodump and learning the ropes with live samples.

If you care to see a fast paced analysis check out what I did for the RSA compromise to give you an idea.
   
http://www.infiltrated.net/rsa-comp-analysis

You seriously need to understand a lot of different topics including Assembly, Java, Debugging, Reversing using IDA/WinDBG/Olly and so forth, tool FUNCTIONS etc to pass the GREM though.

As for the work, can be really tricky. I have been working on an analysis right now for the past 6 months as part of a project. The sample I am using changes every four hours. My analysis documents and analyzes memory, registry, network connections and a heap of other things. Since it changes so much, I have had to write custom programs to keep track of what is new, what has changed and so forth. For anyone wondering the sample is part of a C&C and that's all I will say about it Wink
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.