This course is already delivered, please contact us for the next available session tel:+357 22 44 14 92
Overview:
On this 3 day practical training course, extend your knowledge beyond conventional static computer forensics analysis. You will be guided through the process of conducting malware analysis, from the principles surrounding the different analysis environments and 7Safe's malware investigation methodology to investigating network activity stemming from malicious software infection. Delegates who successfully complete the exam included at the end of the training course will be awarded the Certified Malware Investigator (CMI) qualification.
Who Should Attend:
•Forensic & Network Investigators
•Information Security Professionals
•IT Security Officers
•Law Enforcement Officials
•Computer Auditors
•Crime Prevention Officers
At Course Completion:
•How to analyse and interpret malicious software and associated forensic artefacts including Trojan horses, viruses and worms
•Malware fundamentals in contrast to traditional definitions of malicious software
•How to approach malware investigation from • mounted, booted and network perspectives
•Practical exercises include conversion of EOI- style images to bootable virtual machine disks, contrasting Malware scans in Linux and Windows-based analysis and behavioral observation of Malware in lab environments
Outline:
MALICIOUS SOFTWARE
•How malicious software impacts computer users
•The operation of viruses, worms, Trojan horses, backdoors and rootkits
•How to examine for signs of infection
•How Trojan payloads can be used to bypass antivirus software, personal and corporate firewalls
THE WINDOWS REGISTRY
•Function, structure and operation of the Windows registry
•Investigation of malicious software locations in the registry and file system
CASE SCENARIOS
•Practical application of course content using case scenarios. Delegates will:
•Gain a practical understanding of modern malware beyond the often quoted traditional principles
•Mount forensic images for analysis
•Build virtual machines for analysis
•Build a network environment to carry out network forensic analysis
SIMPLIFYING COMPLEX EVIDENCE
•Collating and reporting results
•Presenting complex oral evidence