Stack Traces in ProcMon - Filtering Events, Exploring DLL Dependencies, and Investigating Call Sites
Advanced triage often starts in Procmon, not a debugger. In this walkthrough, I show you how to use the stack traces in Procmon events to dig deeper into understanding event context. We'll also discuss how to leverage virtual addresses in a Procmon stack trace to locate the origin of an event within the binary itself. We'll explore how to track DLL dependencies and distinguish between the sample's core functionality and its external imports. In this video: Beyond Filtering: Why the Stack Trace is the most underrated feature in Procmon. Context is King: Moving from "What happened" to "Who called it." VA Mapping: Taking a Virtual Address from Procmon back to your static analysis tool like IDA Pro or Ghidra Dependency Triage: Isolating malicious logic from noisy library code. Join this channel to get access to perks: / @jstrosch Cybersecurity, reverse engineering, malware analysis and ethical hacking content! 🎓 Courses on Pluralsight 👉🏻 https://www.pluralsight.com/authors/j... 🌶️ YouTube 👉🏻 Like, Comment & Subscribe! 🙏🏻 Support my work 👉🏻 / joshstroschein 🌎 Follow me 👉🏻 / jstrosch , / joshstroschein ⚙️ Tinker with me on Github 👉🏻 https://github.com/jstrosch 🤝 Join the Discord community and more 👉🏻 https://www.thecyberyeti.com

Navigating the Binary: Data vs. Pointers | Strings & Imports | Lesson 4
![[Workshop] Saying Goodbye to the #US Stream – Analyzing String Obfuscation](https://i.ytimg.com/vi/B6lBZC6XEJo/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLA3pDRvxT-JV9dO-MNPL8-gQEpb3g)
[Workshop] Saying Goodbye to the #US Stream – Analyzing String Obfuscation

02 - Exploring the Reverse Shell Source Code and API Breakdown

I Hacked This Temu Router. What I Found Should Be Illegal.

I Think They Are Lying To You

Understanding File Descriptors in Unix/Linux
![[Workshop] Anti-Analysis Logic – Inspecting the .cctor & Anti-Debug](https://i.ytimg.com/vi/6rcUxmRGhlg/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLAKJMzXihy0WG5FoFcs_0ZuxhUqVA)
[Workshop] Anti-Analysis Logic – Inspecting the .cctor & Anti-Debug

How to Actually Learn C (2027 Edition)

Co-Creator of Haskell: Useless vs Useful Languages, Rust vs C, Functional Programming | Simon Jones

Something is jamming GPS over Europe. Here's what we found

How to Crack any Software
![[Workshop] Symbol Renaming & Namespace Flattening](https://i.ytimg.com/vi/PuJBBKxVK4k/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLCcKirYqPIa9Y-bCAueoM3zadzSWw)
[Workshop] Symbol Renaming & Namespace Flattening

01 - Basic Analysis of the Sample

Every Web Browser Explained in 20 Minutes

02 - Using SCLauncher and WinDBG to Debug Shellcode

Building the PERFECT Linux PC with Linus Torvalds

05 - Creating Position Independent Code using CALL $+5

I Gave ChatGPT a Body

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

