MALWARE ANALYSIS // How to get started with John Hammond

286,055
0
Published 2021-08-30
The amazing John Hammond tells us how to get into Malware Analysis. Learn about jobs, what you need to know and much more!

Menu:
0:00 ▶️ Pretty sketchy stuff!
0:37 ▶️ Welcome John Hammond
0:53 ▶️ Don't divide cyber in your mind
2:00 ▶️ John's day job
3:17 ▶️ Hacker's crafty methods
4:02 ▶️ Will AI take jobs away?
4:55 ▶️ How do I become like you?
5:35 ▶️ Windows is very important
6:12 ▶️ Malware vs CTFs
6:32 ▶️ Is Malware mainly on Windows systems?
7:28 ▶️ Always comes back to the same thing
8:50 ▶️ Practical Example
9:29 ▶️ John's setup
11:42 ▶️ Python malware example
12:50 ▶️ Malware code
15:50 ▶️ Bad guys can sell this information
16:30 ▶️ But this is in the clear?
17:14 ▶️ Obfuscated version
18:28 ▶️ Real world? Don't want to touch disk
19:50 ▶️ How do I find this stuff
20:58 ▶️ Weird Spam SMS messages
21:30 ▶️ Real World: Finding malware
23:42 ▶️ John's real world company example
24:20 ▶️ Real world logic to find malware
25:23 ▶️ Detectors
25:48 ▶️ Hunting malware
26:25 ▶️ Use your eyes - don't trust an automated systems
27:15 ▶️ Input from other systems
27:49 ▶️ How do I become like you?
28:00 ▶️ What kind of skills would you look for in a person to get a job
29:24 ▶️ Look at malware sites
30:15 ▶️ Build out a library
30:38 ▶️ David pushes John for a job on LinkedIn
33:05 ▶️ How did John get his job?
33:30 ▶️ Use social media
34:31 ▶️ How John got his first job
35:55 ▶️ It's who you know, not what you know
36:30 ▶️ How John got his current job
38:19 ▶️ Would you hire someone with certs; or someone you know
39:50 ▶️ Windows bat script example
45:08 ▶️ Which languages does John know
45:38 ▶️ How do you know if it is good or bad code?
46:45 ▶️ Office Macros Malware Example
50:40 ▶️ Cool Linux command
51:26 ▶️ Is this a good job? Are there lots of job?
52:30 ▶️ What hours do you work?
53:31 ▶️ Any books you recommend?

John Hammond Playlist: davidbombal.wiki/johnhammond

====================
Web Sites mentioned:
====================
Use at your own risk:
vx-underground: twitter.com/vxunderground
theZoo: twitter.com/vxunderground
Malware Bazaar: bazaar.abuse.ch/
Joe Sandbox: www.joesecurity.org/
Any run: any.run/
VirusTotal: www.virustotal.com/gui/home/upload

======
Books:
======
The IDA Pro Book: amzn.to/3DtEATW
Black Hat Go: Go Programming For Hackers and Pentesters: amzn.to/3gISKa4
Black Hat Python: Python Programming for Hackers and Pentesters: amzn.to/3ta50FH
Python Pocket Reference amzn.to/3mQPME2
Linux Pocket Guide: Essential Commands: amzn.to/2UWBwya
Regular Expression Pocket Reference: amzn.to/3gJoP1f
Linux Basics for Hackers: Getting Started with Networking, Scripting, and Security in Kali: amzn.to/3Ds22Rq

================
Connect with me:
================
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: youtube.com/davidbombal

================
Connect with John:
================
YouTube: youtube.com/johnhammond010
Twitter: twitter.com/_johnhammond
LinkedIn: www.linkedin.com/in/johnhammond010

malware
malware analysis
cybersecurity
cybersecurity jobs
hacking
ethical hacking
hacking jobs
john hammond
hack the box
try hack me
htb
thm
cyber security career
cybersecurity
cybersecurity careers
ceh
oscp
ine
oscp certification
ctf for beginners
first job
cybersecurity job

Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

#malware #hacking #cybersecurity

All Comments (21)
  • @saroarahmed7764
    Yo David, just wanted to thank you for the free courses on Udemy! Being from Bangladesh 🇧🇩 it is difficult (not impossible) for us to make international transaction legitimately through a bank. So, your free courses are kinda life saver!!! So thank you very much!!!
  • @davidbombal
    Menu: 0:00 ▶ Pretty sketchy stuff! 0:37 ▶ Welcome John Hammond 0:53 ▶ Don't divide cyber in your mind 2:00 ▶ John's day job 3:17 ▶ Hacker's crafty methods 4:02 ▶ Will AI take jobs away? 4:55 ▶ How do I become like you? 5:35 ▶ Windows is very important 6:12 ▶ Malware vs CTFs 6:32 ▶ Is Malware mainly on Windows systems? 7:28 ▶ Always comes back to the same thing 8:50 ▶ Practical Example 9:29 ▶ John's setup 11:42 ▶ Python malware example 12:50 ▶ Malware code 15:50 ▶ Bad guys can sell this information 16:30 ▶ But this is in the clear? 17:14 ▶ Obfuscated version 18:28 ▶ Real world? Don't want to touch disk 19:50 ▶ How do I find this stuff 20:58 ▶ Weird Spam SMS messages 21:30 ▶ Real World: Finding malware 23:42 ▶ John's real world company example 24:20 ▶ Real world logic to find malware 25:23 ▶ Detectors 25:48 ▶ Hunting malware 26:25 ▶ Use your eyes - don't trust an automated systems 27:15 ▶ Input from other systems 27:49 ▶ How do I become like you? 28:00 ▶ What kind of skills would you look for in a person to get a job 29:24 ▶ Look at malware sites 30:15 ▶ Build out a library 30:38 ▶ David pushes John for a job on LinkedIn 33:05 ▶ How did John get his job? 33:30 ▶ Use social media 34:31 ▶ How John got his first job 35:55 ▶ It's who you know, not what you know 36:30 ▶ How John got his current job 38:19 ▶ Would you hire someone with certs; or someone you know 39:50 ▶ Windows bat script example 45:08 ▶ Which languages does John know 45:38 ▶ How do you know if it is good or bad code? 46:45 ▶ Office Macros Malware Example 50:40 ▶ Cool Linux command 51:26 ▶ Is this a good job? Are there lots of job? 52:30 ▶ What hours do you work? 53:31 ▶ Any books you recommend? John Hammond Playlist: davidbombal.wiki/johnhammond ================== Web Sites mentioned: ================== Use at your own risk: vx-underground: twitter.com/vxunderground theZoo: twitter.com/vxunderground Malware Bazaar: bazaar.abuse.ch/ Joe Sandbox: www.joesecurity.org/ Any run: any.run/ VirusTotal: www.virustotal.com/gui/home/upload ====== Books: ====== The IDA Pro Book: amzn.to/3DtEATW Black Hat Go: Go Programming For Hackers and Pentesters: amzn.to/3gISKa4 Black Hat Python: Python Programming for Hackers and Pentesters: amzn.to/3ta50FH Python Pocket Reference amzn.to/3mQPME2 Linux Pocket Guide: Essential Commands: amzn.to/2UWBwya Regular Expression Pocket Reference: amzn.to/3gJoP1f Linux Basics for Hackers: Getting Started with Networking, Scripting, and Security in Kali: amzn.to/3Ds22Rq ================ Connect with me: ================ Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: youtube.com/davidbombal ================ Connect with John: ================ YouTube: youtube.com/johnhammond010 Twitter: twitter.com/_johnhammond LinkedIn: www.linkedin.com/in/johnhammond010
  • @MisterK-YT
    I love the conciseness of this channel. Timestamps, no time wasted, doesn’t talk too much. 👌
  • @RAZREXE
    This is GOLD! I cannot thank you enough David and John, you are the best!
  • @Nicrophelia
    These “old” videos are so under utilized by people trying to get into the industry, this one is a GEM. Seeing where the people I look up to were a couple years ago is super inspiring! One of my favorite parts about both of you is your pursuit of learning, thank you for creating!
  • @SpaceOfSoul23
    Thank you so much for covering this. I’m on my own journey of getting into cyber security, and have been growing a big interest in malware analysis. I’ve asked around and no one knew what I was talking about. Was getting really discouraged, thanks!!!
  • @TylerRake141
    My two favorite IT teachers in one video ? Hell yes!! 🔥
  • @gueroloco8687
    Love John Hammond and you as well David!! Thanks so much for the help!!!
  • @aviano5
    David you are the best of best. It is hard to find someone like you, who gives amazing courses for free and all these video tutorials. As a cyber security undergraduate, I'm really thankful to you for all your efforts. Wish you best of luck Dav. ❤️💯
  • @Sparerime
    To me,this is a gold mine! Thank you guys for taking time and educate us 👌🏻👍🏻
  • @infotechyeti
    Great video and appreciate his presentation. Great to see the way how one has to comb through the script to see the malicious process being executed.
  • @keirnbug8762
    Man, everything I watch some of your stuff, I always end up going down a different rabbithole , inspireing and fun !
  • second time watching this from start to finish.. man david thank you for asking all the best questions. this was so good we need more of this !
  • @shanecoursen
    It's nice to see the new guard. Enjoying your vids, David. Thank you.
  • @halfdemon88
    Every time I have a question about something I want to know, you've got a video about it. Thx, bud
  • @mohammed9033
    Hey David. Thanks a ton for this, would request you for more such podcasts
  • @Matheus-lk9lh
    Wow, I never see a course cover this topic, thank you David
  • @jeezboi5079
    These guys are pro in their field and they are so humble and down to earth
  • @raginranga3494
    Many thanks to yourself, John and all your guests for providing Insight 🙏🇦🇺