Curso Windows Malware Analysis

  • Redes & Infraestrutura de TI

Curso Windows Malware Analysis

32h
Visão Geral

Este curso aprofunda a análise de malware em ambientes Windows, abordando executáveis, processos, memória, registro, persistência, APIs, rede e técnicas de detecção.

Objetivo

Após realizar este curso, você será capaz de:

  • Analisar malware para Windows
  • Investigar comportamento de executáveis
  • Identificar persistência e comunicação
  • Desenvolver indicadores de detecção
Publico Alvo
  • Malware Analysts
  • DFIR Professionals
  • Threat Hunters
  • Incident Responders
Pre-Requisitos
  • Conhecimentos avançados de Windows
  • Conhecimentos de processos e memória
  • Familiaridade com redes
  • Noções de programação
  • Conhecimentos de malware analysis
Conteúdo Programatico

Module 1: Windows Malware Analysis Environment

  1. Malware analysis laboratory
  2. Isolated analysis environments
  3. Windows internals overview
  4. Analysis tools
  5. Sample handling
  6. Evidence preservation
  7. Static and dynamic workflows
  8. Analysis safety
  9. Malware documentation
  10. Laboratory design

Module 2: Windows Executable Analysis

  1. PE file format
  2. Headers
  3. Sections
  4. Imports
  5. Exports
  6. Resources
  7. Strings
  8. Metadata
  9. Suspicious executable characteristics
  10. PE analysis

Module 3: Static Malware Analysis

  1. Hash analysis
  2. String analysis
  3. Import analysis
  4. API analysis
  5. Control flow concepts
  6. Code structure
  7. Embedded resources
  8. Obfuscation indicators
  9. Static IOC extraction
  10. Static malware analysis

Module 4: Dynamic Malware Analysis

  1. Process execution
  2. File system activity
  3. Registry activity
  4. Process creation
  5. Service creation
  6. Scheduled Tasks
  7. Network connections
  8. Runtime behavior
  9. Sandbox analysis
  10. Dynamic malware analysis

Module 5: Windows Internals for Malware Analysis

  1. Processes
  2. Threads
  3. Handles
  4. DLLs
  5. Windows APIs
  6. Memory management
  7. Tokens
  8. Services
  9. Kernel concepts
  10. Malware interaction with Windows

Module 6: Persistence and Defense Evasion

  1. Registry persistence
  2. Services
  3. Scheduled Tasks
  4. WMI
  5. Startup mechanisms
  6. Process injection concepts
  7. Defense Evasion
  8. Anti-analysis techniques
  9. Persistence detection
  10. Evasion analysis

Module 7: Network and Command and Control Analysis

  1. DNS behavior
  2. HTTP communication
  3. HTTPS metadata
  4. Command and Control
  5. Beaconing
  6. Network indicators
  7. Traffic analysis
  8. C2 infrastructure indicators
  9. Network detection
  10. C2 investigation

Module 8: Practical Windows Malware Analysis

  1. Sample triage
  2. PE analysis
  3. Static analysis
  4. Dynamic analysis
  5. Process investigation
  6. Persistence investigation
  7. Network investigation
  8. IOC extraction
  9. Detection development
  10. Windows malware analysis case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas