Datasheet | Hands-on Threat Hunting: Memory Forensics, Endpoint Telemetry, and AI-Driven A | Check Point Software
Datasheet | Hands-on Threat Hunting: Memory Forensics, Endpoint Telemetry, and AI-Driven A
This hands-on training dives deep into Memory Forensics and Event Triaging—essential skills for modern threat hunters and incident responders. Participants will analyze real-world Windows memory dumps to uncover advanced malware and rootkits. Leveraging tools like Volatility and Garuda, attendees learn to identify hidden threats, investigate suspicious processes, and triage endpoint events effectively. The course also demonstrates AI-driven autonomous threat hunting for faster detection of stealthy attacks using tools like Garuda.
Recommended For
- Forensic practitioners.
- Incident responders.
- Cyber security investigators.
- Security researchers.
- Threat Hunters.
- Malware analysts.
- System administrators.
- Software developers.
- Students and anyone interested in learning malware analysis to expand their skills.
Key Features
- Hands-on Memory Forensics Labs: Scenario-based exercises analyzing real-world memory dumps containing crimeware, APT malware, and stealthy rootkits.
- Advanced Volatility Framework Usage: Extensive practical training using the industry-leading open-source Volatility framework for deep memory investigation.
- Endpoint Event Triaging with Sysmon: Learn practical event analysis techniques to uncover adversary tactics through detailed endpoint telemetry.
- Garuda Threat Hunting Framework: Master the powerful Garuda platform for filtering, correlating, and analyzing Sysmon events efficiently.
- Real-World Case Studies & Demonstrations: Practical examples and live demos illustrating rootkit detection, malware persistence, and fileless malware investigations.
- AI-Enhanced Threat Detection: Leverage integrated AI capabilities for autonomous threat hunting and intelligent event correlation.
Outcomes & Impact
- Gain practical expertise in advanced memory forensic techniques and event triaging to detect sophisticated cyber threats.
- Develop critical skills to analyze, identify, and respond rapidly to advanced malware, rootkits, and stealth attacks.
- Master the use of industry-leading tools like Volatility and Garuda, enhancing effectiveness in real-world threat-hunting scenarios.
- Strengthen career prospects by acquiring high-demand skills suitable for roles in cyber security investigations, threat hunting, and incident response.
Prerequisites
- Basic knowledge of Windows operating system internals.
- Familiarity with cybersecurity fundamentals, including malware analysis and incident response concepts.
- Basic proficiency with command-line tools and scripting.
- Experience or familiarity with forensic tools is beneficial but not mandatory.
- General understanding of networking concepts (TCP/IP, sockets, ports).
Course Outline
Introduction to Memory Forensics
- What is Memory Forensics.
- Why Memory Forensics.
- Steps in Memory Forensics.
- Memory acquisition and tools.
- Acquiring memory from physical machine.
- Acquiring memory from the virtual machine.
- Hands-on exercise involves acquiring the memory.
Volatility Overview
- Introduction to Volatility Advanced Memory Forensics Framework.
- Volatility Installation.
- Volatility basic commands.
- Determining the profile.
- Volatility help options.
- Running the plugin.
Investigating Process
- Understanding Process Internals.
- Process (EPROCESS) Structure.
- Process organization.
- Process Enumeration by walking the double linked list.
- Process relationship (parent-child relationship).
- Understanding DKOM attacks.
- Process Enumeration using pool tag scanning.
- Volatility plugins to enumerate processes.
- Identifying malware process.
- Hands-on lab exercise (scenario-based) involves investigating malware infected memory.
Investigating Process handles & Registry
- Objects and handles overview.
- Enumerating process handles using Volatility.
- Understanding Mutex.
- Detecting malware presence using mutex.
- Understanding the Registry.
- Investigating common registry keys using Volatility.
- Detecting malware persistence.
- Hands-on lab exercise (scenario-based) involves investigating malware infected memory.
Investigating Network Activities
- Understanding malware network activities.
- Volatility Network Plugins.
- Investigating Network connections.
- Investigating Sockets.
- Hands-on lab exercise (scenario-based) involves investigating malware infected memory.
Investigation Process Memory
- Process memory Internals.
- Listing DLLs using Volatility.
- Identifying hidden DLLs.
- Dumping malicious executable from memory.
- Dumping Dll's from memory.
- Scanning the memory for patterns (yarascan).
- Hands-on lab exercise (scenario-based) involves investigating malware infected memory.
Investigating User-Mode Rootkits & Fileless Malwares
- Code Injection.
- Types of Code injection.
- Remote DLL injection.
- Remote Code injection.
- Reflective DLL injection.
- Hollow process injection.
- Demo - Case Study.
- Hands-on lab exercise (scenario-based) involves investigating malware infected memory.
Investigating Kernel-Mode Rootkits
- Understanding Rootkits.
- Understanding Functional call traversal in Windows.
- Level of Hooking/Modification on Windows.
- Kernel Volatility plugins.
Threat Hunting Using Event Triaging
- Introduction to Sysmon.
- Understanding Sysmon Events.
- Introduction to Garuda Threat Hunting Framework.
- Filtering Sysmon events using Garuda.
- Living of the Land attacks.
- Hunting LoLbins (Living of the land binary) attacks.
- Demo: AI-Powered Autonomous Threat Hunting using Garuda.
AI-Powered Threat Hunting
- Introduction to AI in threat detection & hunting.
- Introduction to MCP (Model Context Protocol).
- Exposing Tools to the LLM.
- Integrating Garuda Framework with AI application.
- How Garuda + AI can triage events, identify IOCs, and Map events to ATT&CK Techniques.
- Demo: AI-powered autonomous Threat hunting to hunt for complex attack patterns.