Visão Geral
Este curso aborda investigação de malware e desenvolvimento de mecanismos de detecção, integrando análise de arquivos, endpoints, rede, indicadores e telemetria de segurança.
Conteúdo Programatico
Module 1: Malware Investigation
- Malware investigation lifecycle
- Sample triage
- Malware classification
- Static analysis
- Dynamic analysis
- Behavioral analysis
- IOC extraction
- Threat intelligence
- Investigation documentation
- Malware investigation methodology
Module 2: Endpoint Malware Detection
- Process indicators
- File indicators
- Registry indicators
- Persistence indicators
- Suspicious execution
- EDR telemetry
- Behavioral detection
- Endpoint correlation
- Malware detection rules
- Endpoint malware investigation
Module 3: Network Malware Detection
- DNS indicators
- HTTP indicators
- HTTPS metadata
- Command and Control
- Beaconing
- Suspicious domains
- Network anomalies
- Network-based malware detection
- Traffic correlation
- Network malware investigation
Module 4: IOC Development
- IOC concepts
- File hashes
- Domains
- IP addresses
- URLs
- Registry indicators
- Process indicators
- Behavioral indicators
- IOC validation
- IOC lifecycle
Module 5: Detection Engineering
- Signature detection
- Behavioral detection
- YARA concepts
- SIEM rules
- EDR rules
- Correlation rules
- Detection tuning
- False positive management
- Detection validation
- Detection deployment
Module 6: Malware Incident Response
- Malware alert triage
- Endpoint isolation
- Evidence preservation
- Malware containment
- Persistence removal
- Credential remediation
- Network containment
- Eradication
- Recovery
- Incident documentation
Module 7: Threat Intelligence Integration
- Malware intelligence
- Threat actors
- Malware families
- Campaigns
- TTP analysis
- IOC enrichment
- MITRE ATT&CK
- Intelligence correlation
- Intelligence-driven detection
- Intelligence reporting
Module 8: Practical Malware Investigation
- Malware sample triage
- Static investigation
- Dynamic investigation
- Endpoint investigation
- Network investigation
- IOC development
- Detection development
- Incident response
- Investigation reporting
- Malware investigation case study