| |
Aug 06, 2026
|
|
|
|
|
CFI 2202 - Malicious Documents and Memory Forensics Credits: 3 Hours/Week: Lecture 2 Lab 2 Course Description: This course explores several techniques malware authors commonly employ to protect malicious Windows executables from being analyzed, often with the help of packers. Course topics address bypassing analysis defenses, including structured error handling for execution flow, PE header corruption, fake memory breakpoints, tool detection, integrity checks, and timing controls. The course touches on Web browser malware and the use of additional tools and approaches for analyzing more complex malicious scripts written in VBScript and JavaScript by exploring common patterns of assembly instructions MnTC Goals None
Prerequisite(s): CFI 1065 with a grade of C or higher or instructor consent. Corequisite(s): None Recommendation: None
Major Content
- Data Structures
- The Volatility Framework
- Memory Acquisition
- Acquiring & Analyzing Memory
- Windows Objects and Pool Allocations
- Processes, Handles and Tokens
- Process Memory Internals
- Hunting Malware in Process Memory
- Event Logs
- Registry in Memory
- Windows Services
- Kernel Forensics and Rootkits
Learning Outcomes At the end of this course, students will be able to:
- describe IDA Plug-in architecture and setup.
- explain the Kernel API used by malware authors.
- use IDA configuration for programmatic reversing and script writing.
- describe common rootkit technologies.
- use WinDBG for kernel debugging.
- explain PE Anti-reversing techniques: De-obfuscating executables for IDA.
- explain user-mode obfuscation methods.
- demonstrate Anti-RE Techniques: Detecting debuggers, virtual machines, and other tricks.
- describe kernel assisted obfuscation.
- describe rootkit process / DLL injection.
- explain rootkit process / DLL injection.
- analyze reverse kernel-mode botnet bots.
- describe Metasploit’s Shikata-ga-nai.
- utilize Saffron and Ether during malware analysis.
- analyze physical memory with memorize.
- identify common algorithms inside worms.
- analyze Virtual Machine based packers.
- describe reverse Themida and other VM packers.
- demonstrate reverse storm’s C&C protocol.
- demonstrate reverse .NET byte code.
Minnesota Transfer Curriculum (MnTC): Goals and Competencies Competency Goals (MnTC Goals 1-6) None Theme Goals (MnTC Goals 7-10) None
Practicum hours per week: 0 Courses and Registration
Add to Portfolio (opens a new window)
|
|