Curso Malware Investigation & Detection

  • Redes & Infraestrutura de TI

Curso Malware Investigation & Detection

24h
Visão Geral

Este curso aborda investigação de malware e desenvolvimento de mecanismos de detecção, integrando análise de arquivos, endpoints, rede, indicadores e telemetria de segurança.

Objetivo

Após realizar este curso, você será capaz de:

  • Investigar amostras de malware
  • Correlacionar indicadores
  • Desenvolver detecções
  • Apoiar resposta a incidentes
Publico Alvo
  • Malware Analysts
  • SOC Analysts
  • Incident Responders
  • Threat Hunters
Pre-Requisitos
  • Conhecimentos de Windows
  • Conhecimentos básicos de malware analysis
  • Familiaridade com SIEM e EDR
  • Conhecimentos de redes
  • Noções de Digital Forensics
Conteúdo Programatico

Module 1: Malware Investigation

  1. Malware investigation lifecycle
  2. Sample triage
  3. Malware classification
  4. Static analysis
  5. Dynamic analysis
  6. Behavioral analysis
  7. IOC extraction
  8. Threat intelligence
  9. Investigation documentation
  10. Malware investigation methodology

Module 2: Endpoint Malware Detection

  1. Process indicators
  2. File indicators
  3. Registry indicators
  4. Persistence indicators
  5. Suspicious execution
  6. EDR telemetry
  7. Behavioral detection
  8. Endpoint correlation
  9. Malware detection rules
  10. Endpoint malware investigation

Module 3: Network Malware Detection

  1. DNS indicators
  2. HTTP indicators
  3. HTTPS metadata
  4. Command and Control
  5. Beaconing
  6. Suspicious domains
  7. Network anomalies
  8. Network-based malware detection
  9. Traffic correlation
  10. Network malware investigation

Module 4: IOC Development

  1. IOC concepts
  2. File hashes
  3. Domains
  4. IP addresses
  5. URLs
  6. Registry indicators
  7. Process indicators
  8. Behavioral indicators
  9. IOC validation
  10. IOC lifecycle

Module 5: Detection Engineering

  1. Signature detection
  2. Behavioral detection
  3. YARA concepts
  4. SIEM rules
  5. EDR rules
  6. Correlation rules
  7. Detection tuning
  8. False positive management
  9. Detection validation
  10. Detection deployment

Module 6: Malware Incident Response

  1. Malware alert triage
  2. Endpoint isolation
  3. Evidence preservation
  4. Malware containment
  5. Persistence removal
  6. Credential remediation
  7. Network containment
  8. Eradication
  9. Recovery
  10. Incident documentation

Module 7: Threat Intelligence Integration

  1. Malware intelligence
  2. Threat actors
  3. Malware families
  4. Campaigns
  5. TTP analysis
  6. IOC enrichment
  7. MITRE ATT&CK
  8. Intelligence correlation
  9. Intelligence-driven detection
  10. Intelligence reporting

Module 8: Practical Malware Investigation

  1. Malware sample triage
  2. Static investigation
  3. Dynamic investigation
  4. Endpoint investigation
  5. Network investigation
  6. IOC development
  7. Detection development
  8. Incident response
  9. Investigation reporting
  10. Malware investigation case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas