In March, I had the pleasure of attending the course “Advanced Linux Malware Reverse Engineering" with Marion Marschalek (
@pinkflawd). Since reverse engineering isn’t my main area of expertise, my brain was completely fried by the end of each evening (I’d end up lying on the hotel bed watching episode after episode of House Hunters 😂). I hadn’t been challenged like that since the EDR Evasion course, about which I wrote a summary on my blog. I’ll most likely write a summary of Marion’s course as well.
And today… I solved the ShadowMonarch challenge on HTB!
“Your mission is to fully reverse engineer this sophisticated [Linux] backdoor, understand its BPF-based evasion mechanism, reconstruct the activation protocol, and extract all indicators of compromise.”
And it was really cool. I solved the challenge using Binary Ninja (coming from an IDA background), which, even though BJ is great, still required me to switch back and forth a bit within the menu at certain points…
We learned so much during Marion’s four-day training, and as I was reverse engineering the sample, I had that “aha, I recognize this” feeling so many times. System calls, how to start the analysis, and how to figure out which functions might correspond to which parts of the malware. Really cool! And, manual reversing combined with some AI support is incredibly fast, especially when analyzing BPF bytecode.
Thank you so much, Marion, for the extremely cool course! As you can see, you’re a great teacher; I definitely learned a thing or two :)