The course
On this 3 day practical training course, extend your knowledge beyond conventional static computer forensics analysis. You will be guided through the process of conducting malware analysis, from the principles surrounding the different analysis environments and 7Safe's malware investigation methodology to investigating network activity stemming from malicious software infection. Delegates who successfully complete the exam included at the end of the training course will be awarded the Certified Malware Investigator (CMI) qualification.
Course Content 
- Analysis Environments
- Identify and define the five analysis environments
- Identify situations in which each of the investigation environments could be used effectively
- Identify their respective levels of risk both to the original data as well as other systems
- Malicious Software
- Define the term "malicious software"
- Identify and define different types of malicious software
- Identify similarities and differences between different types of malicious software
- Malware Investigation
- Identify the stages of malware investigation
- Critically assess the capabilities and limitations of anti-malware tools
- Identify the different means of running software at system start-up
- Methods of Deception
- Identify mechanisms of malware delivery
- Identify mechanisms of disguise
- Identify client security circumvention
- Mounted Analysis
- Mounting forensic images as logical drives
- Using malware scanners against the mounted image
- Documenting the results of malware scans
- Using online scanners for further clarification
- Booted Analysis
- Identify approaches to creating a booted analysis environment
- Experiment with making a Virtual Machine
- Identifying password implications
- Identifying and explaining the potential differences between mounted and booted analysis results
- Network Analysis
- Identify key reasons for network analysis
- Methods of building a network for analysis
- Explaining network communication protocols
- Using traffic analysis tools for network analysis
- External Port Analysis
- Identifying and explaining the potential differences between network and other analysis results
- Virtualisation Malware
- Explain how hardware Hypervisor support allows for virtualisation malware
- Define Type I, Type II and Type III malware
- Simplifying Complex Evidence
- Aiming the report at a subject knowledge level fitting the target audience
- Discuss a sample report outline
Highlights 
- Includes the CMI qualification
- Analysing and interpreting malicious software
- Understanding the Windows Registry
- Investigating network activity initiated by malicious software infection
- Simplifying complex evidence
- Collating and reporting results

Download
PDF
|
Course outline
Read the Malware Investigation: Hands-On course outline to find out more about the many topics covered in CMI Malware Investigation Training |
Frequently Asked Questions (FAQ)