• Classroom

Learning Objectives

  • Understand the major components in the Windows Kernel and the functionality they provide
  • Understand the key principles behind the design and implementation of the Windows kernel
  • Understand the internal workings of the kernel and how to peer into it using the debugger
  • Be able to investigate system data structure using kernel debugger extension commands
  • Be able to interpret the output of debugger commands and correlate them to the state of the system
  • Be able to navigate between different data structures in the kernel, using debugger commands
  • Be able to locate indicators of compromise while hunting for kernel mode malware
  • Understand how kernel mode rootkits and commercial anti-malware interact with the system

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Technology R&D

Specialty Areas have been removed from the NICE Framework. With the recent release of the new NICE Framework data, updates to courses are underway. Until this course can be updated, this historical information is provided to give better context as to how it can help you with your cybersecurity goals.