Course Overview
Learning Objectives
After completing the course, learners should be able to: • Quickly perform malware triage using a variety of techniques and tools without running the malware • Analyze running malware by observing file system changes, function calls, network communications and other indicators • Learn about code compilation and how to interpret decompiled Windows code • Analyze basic .NET and PowerShell malware and interpret WMI commands • Use Ghidra, the open-source disassembler/decompiler
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Exploitation Analysis