Windows Malware Analysis for Hedgehogs - Beginner Training

所在平台: Udemy

课程主页: https://www.udemy.com/course/windows-malware-analysis-for-hedgehogs-beginner-training/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Windows恶意软件分析 - 初学者培训 课程概述:本课程超越了逆向工程的范畴,作为一名恶意软件分析师,您需要掌握多种技能。您将学习如何将样本分类为不同类型的恶意软件,识别恶意软件家族,并确定文件状态(如干净、恶性、潜在不需要程序、垃圾、灰色软件或损坏)。此外,您将了解恶意软件如何持久化、如何识别恶意自启动项以及如何清理受感染的系统。本课程旨在打破常见的误区,如“检测名称中带有trojan就意味着该文件是木马”或“杀毒软件的检测名称是恶意软件的分类”。 讲师自2015年以来在一家杀毒公司工作并拥有丰富的实际经验,曾多次培训初学者,了解新手在学习过程中的通常误区和需要掌握的概念。课程注重建立坚实的基础,使学员能够灵活应对新兴的恶意软件,而不是提供一步一步的快捷方式。 您将学习如何区分不同类型的文件,包括安装程序、包装文件、压缩文件、非压缩文件、混合文件和原生编译文件。课程将教授您在不同情况下应用哪些工具以及如何高效分析样本,提供适用于大多数情况的示例方法。 课程适合具备一定IT背景的人士,如业余或专业程序员、计算机爱好者、系统管理员、计算机科学学生或对软件或IT安全有兴趣的游戏玩家。如果您对该主题有浓厚的兴趣但缺乏必要的IT背景,建议您先学习编程。 课程使用的工具和网络服务均为免费工具,包括Ghidra、x64dbg、VirtualBox、SysInternals Suite、VirusTotal等。 课程要求:您需要对至少一种编程语言(如Python、C、C++、Java或C#)有深入理解。这是参与课程的关键要求,除了课程中会创建小脚本外,逆向工程也需要扎实的编程基础。您还需能够阅读(而非编写)x86汇编,以便理解本课程的内容。 本课程将涵盖多种执行环境的样本,包括x86、x64汇编、.NET、批处理、PowerShell等,但不要求您掌握所有这些语言。分析师在工作时会遇到新语言,因此您的技能组合应该在于如何使用现有文档和手册。 课程范围外的主题包括汇编语言、编程、计算机工作原理、URL和网站分析、网络分析、非Windows平台恶意软件分析、移动恶意软件、物联网恶意软件等,这些内容需要独立的课程进行教授。

课程评论(0条)

课程详情

This course teaches more than just reverse engineering because as a malware analyst you need a variety of other skills. You will learn how to classify samples into malware types, how to identify malware families and how to determine file verdicts like clean, malicious, potentially unwanted programs, junk, grayware, or corrupt. Additionally, you will learn how malware persists, how to identify malicious autostart entries and clean infected systems.The course aims to dispel common myths such as "trojan in a detection name means the file is a trojan horse" or "antivirus detection names are a malware classification".As a malware analyst with experience working at an antivirus company since 2015, I have trained many beginners in the field. I understand the usual pitfalls and the concepts that you need to grasp to become proficient. I focus on building strong foundations that make you flexible in the face of new malware advancements, rather than providing shortcuts with step-by-step recipes.I will teach you how to differentiate between different types of files, including installers, wrappers, packed files, non-packed files, hybrid, and native compiled files. You will learn which tools to apply in which situations and how to analyse samples efficiently. To do that I give you example approaches that work for most situations.This course is ideal for you if you already have some IT background, such as hobby or professional programmers, computer enthusiasts, administrators, computer science students, or gamers with an interest in the inner workings of software or IT security.If you have a strong interest in the topic but lack the necessary IT background, I recommend that you learn programming first. Please refer to the course requirements for more information.ToolsAll the tools and web services that we use during the course are free:Ghidrax64dbgVirtualBoxSysInternals SuitePortexAnalyzer CLI and GUIVirusTotal (without account)Speakeasy by MandiantAPI MonitorCyberChefEXIFToolMeldVBinDiffAnalyzePESigDnSpyC# Online Compiler programwizTriDDetect-it-EasyReNamer7zipNotepad++HxDMalpedialnk_parserRequirements You should have a strong understanding of at least one programming language, such as Python, C, C++, Java, or C#. This is a crucial requirement for the course, not only because we create small scripts during the course but because reverse engineering needs an understanding of software as foundation. The specific language does not matter, as you cannot learn every language you may encounter during analysis anyways. The concepts of programming must be clear, though.If you are not there yet, you should not buy this course and start learning C instead. C is great because it is low-level and will integrate well with x86 assembly language.Additionally, you must be able to read (not write) x86 assembly to understand everything in the course. Without assembly you will only be able to understand two-thirds of the content. So if you consider starting this course right away and learning assembly alongside it, that should work fine.During this course we look at samples that use the following execution environments:x86, x64 assembly.NETBatchPowerShellNullsoft scriptsHowever, you do not need to learn all of these languages. Because an analyst encounters new languages all the time, your skillset is rather in using the available documentation, manuals and help provided for those environments and languages. I also show you during the course how to use the documentation for ,e.g., PowerShell.Out of scopeMalware analysis is a broad field, so there are inevitably topics that I will not teach during this course because they would rather require their own course. Some of these topics are: assembly language, programming, how computers work, URL and website analysis, networks, analysis of malware for other platforms than Windows, mobile malware, IoT malware.

课程标签

0人关注该课程

主题相关的课程