data:image/s3,"s3://crabby-images/31cbf/31cbf65cc7747943a09d71fb7b1a4098899b15ec" alt="Ollydbg malware reverse"
So not wasting more time here is brief introduction to Ollydbg.Īs the name itself suggests OllyDbg is debugger and disassembler for Microsoft Windows PE(Portable Executable) files (32-bit). But i would recommend that for now you should start with ollydbg you can switch to immunity later if you want when you get comfortable with ollydbg. This tutorial will also be applicable to immunity debugger. But ollydbg is more popular because its old and have long list of plugins. Immunity is very similar to ollydbg in usage. There is one more popular debugger named immunity debugger with support for python scripting. You will be using it a lot during malware reverse engineering. First you should get familiar with Ollydbg.
data:image/s3,"s3://crabby-images/86de5/86de59f10aff49e63e66e4588bd608ffaafb5f38" alt="ollydbg malware reverse ollydbg malware reverse"
data:image/s3,"s3://crabby-images/779fc/779fcaf5d1a2b45cab72566a3e0d4306ed8a0e52" alt="ollydbg malware reverse ollydbg malware reverse"
data:image/s3,"s3://crabby-images/ab93b/ab93b00e9438ee28a3a19d859bc13f114e9cd0a1" alt="ollydbg malware reverse ollydbg malware reverse"
I will explain debugging types user mode and kernel mode debugging later. Ollydbg is the most popular user mode debugger among Malware analysts and reverse engineers. To start with malware analysis you need to know about debugging.
data:image/s3,"s3://crabby-images/31cbf/31cbf65cc7747943a09d71fb7b1a4098899b15ec" alt="Ollydbg malware reverse"