Kovter has a long history, evolving from a click fraud malware to a fileless malware, making it near impossible to detect. Attackers using Kovter often evade detection and avoid traditional endpoint file scanning and sandboxing technologies. Learn to use your provided EDR platform to investigate a machine infected with Kovter as you map out the attack path and uncover attacker objectives.
Learning Objectives
Learn to use your provided EDR platform to investigate a machine infected with Kovter as you map out the attack path and uncover attacker objectives.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Cyber Defense Analysis
- Cyber Defense Infrastructure Support
- Cyber Investigation
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.