• Online, Instructor-Led
  • Online, Self-Paced
Course Description

Kovter has a long history, evolving from a click fraud malware to a fileless malware, making it near impossible to detect. Attackers using Kovter often evade detection and avoid traditional endpoint file scanning and sandboxing technologies. Learn to use your provided EDR platform to investigate a machine infected with Kovter as you map out the attack path and uncover attacker objectives.

Learning Objectives

Learn to use your provided EDR platform to investigate a machine infected with Kovter as you map out the attack path and uncover attacker objectives.

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Cyber Defense Analysis
  • Cyber Defense Infrastructure Support
  • Cyber Investigation


If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.