Aug 06, 2026  
2026-2027 Course Catalog 
    
2026-2027 Course Catalog
Add to Portfolio (opens a new window)

CFI 2202 - Malicious Documents and Memory Forensics

Credits: 3
Hours/Week: Lecture 2 Lab 2
Course Description: This course explores several techniques malware authors commonly employ to protect malicious Windows executables from being analyzed, often with the help of packers. Course topics address bypassing analysis defenses, including structured error handling for execution flow, PE header corruption, fake memory breakpoints, tool detection, integrity checks, and timing controls. The course touches on Web browser malware and the use of additional tools and approaches for analyzing more complex malicious scripts written in VBScript and JavaScript by exploring common patterns of assembly instructions
MnTC Goals
None

Prerequisite(s): CFI 1065  with a grade of C or higher or instructor consent. 
Corequisite(s): None
Recommendation: None

Major Content
  1. Data Structures
  2. The Volatility Framework
  3. Memory Acquisition
  4. Acquiring & Analyzing Memory
  5. Windows Objects and Pool Allocations
  6. Processes, Handles and Tokens
  7. Process Memory Internals
  8. Hunting Malware in Process Memory
  9. Event Logs
  10. Registry in Memory
  11. Windows Services
  12. Kernel Forensics and Rootkits

Learning Outcomes
At the end of this course, students will be able to:

  1. describe IDA Plug-in architecture and setup.
  2. explain the Kernel API used by malware authors.
  3. use IDA configuration for programmatic reversing and script writing.
  4. describe common rootkit technologies.
  5. use WinDBG for kernel debugging.
  6. explain PE Anti-reversing techniques: De-obfuscating executables for IDA.
  7. explain user-mode obfuscation methods.
  8. demonstrate Anti-RE Techniques: Detecting debuggers, virtual machines, and other tricks.
  9. describe kernel assisted obfuscation.
  10. describe rootkit process / DLL injection.
  11. explain rootkit process / DLL injection.
  12. analyze reverse kernel-mode botnet bots.
  13. describe Metasploit’s Shikata-ga-nai.
  14. utilize Saffron and Ether during malware analysis.
  15. analyze physical memory with memorize.
  16. identify common algorithms inside worms.
  17. analyze Virtual Machine based packers.
  18. describe reverse Themida and other VM packers.
  19. demonstrate reverse storm’s C&C protocol.
  20. demonstrate reverse .NET byte code.

Minnesota Transfer Curriculum (MnTC): Goals and Competencies
Competency Goals (MnTC Goals 1-6)
None
Theme Goals (MnTC Goals 7-10)
None

Practicum hours per week: 0


Courses and Registration



Add to Portfolio (opens a new window)