Network Attack Investigations and Malware Analysis

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/10

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering key security tools, concepts, malware types, and forensic artifacts discussed in the lecture.

Last updated 4:35 AM on 9/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

11 Terms

1
New cards

Indicator of Compromise (IoC)

Technical artifacts such as IP addresses, file hashes, URLs, and domain names that indicate a system or network has been breached.

2
New cards

MX toolbox

An online suite of applications used for mail server analytics, email header analysis, and checking SPF or blocklist statuses.

3
New cards

ipapi.com

An IP lookup service queried by malware to determine whether the executing host is in a data center or VPS to evade honeypots and security research environments.

4
New cards

GooLoader

A malware delivery mechanism that leverages legitimate cloud services, such as Google Drive, to host and download malicious payloads.

5
New cards

Agent Tesla

A family of Remote Access Trojan (RAT) malware used to steal credentials, system metadata, and session tokens, often exfiltrating data via protocols like FTP.

6
New cards

Network Detection and Response (NDR)

A security domain and set of tools focused on analyzing network traffic and packet captures to identify and respond to malicious activities.

7
New cards

Endpoint Detection and Response (EDR)

Host-based security technology that monitors and logs host-level events, such as file creation, process execution, and system modifications.

8
New cards

Suricata

An Intrusion Detection System (IDS) that inspects incoming network traffic against defined rules and generates alerts for suspicious activity.

9
New cards

Joomla

A web content management system targeted by attackers to upload malicious scripts using built-in installer functionality.

10
New cards

agent.php

An obfuscated PHP script uploaded to a web server by attackers to conduct covert communication and exchange encoded data.

11
New cards

Thunderbird

A desktop email client from which Agent Tesla malware extracted stored passwords, OAuth tokens, and saved user contacts.