2.4 API logger

API logger tools show the sequence in which an executable calls an API. An entry for a particular API can include the parameters passed to the APIs and the values returned by it. StraceNT and apimonitor are some tools that can be used for API logging.

You can use apimonitor from the following site: http://www.rohitab.com/apimonitor/v1-5. The tool has a nice user interface and most features are self-explanatory. API logging is an important feature to understand what goes on behind the scenes in malware. Researchers can then use these APIs to debug the malware:

You can configure the tool by going to the Capture menu. You will get a drop-down API Filter. You can then select the APIs you want to log, for example Registry. You can start logging again by going to the Capture menu and clicking on Capture API Events:

Apimonitor logs

Malware analysts can use the API logs to find the internal workings of malware.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.223.196.59