Module 1
Ransomware Forensics (W30)
Explore ransomware analysis through forensic and reverse-engineering concepts. Connect memory analysis, program behavior, networking, and cryptographic foundations. This is an earlier course edition; examples reflect the tools and versions used when it was recorded.
Instructor · Dr. Paulo Henrique
- Modules:
- 6
- Lessons:
- 13
eForensics learning
Practical skills.
Verified progress.
What you'll learn
- Investigate ransomware-affected systems in a virtual lab.
- Analyze memory dumps using the tools introduced in the course.
- Connect program, network, and cryptographic behavior with forensic findings.
Prerequisites
This course requires Volatility and Rekall usage knowledge. This course requires C and C++ programming knowledge. Basic assembly knowledge. Registers, CPU, looping Network TCP protocol. Cryptographic basic knowledge. Your intructor: Paulo Henrique Pereira, PhD I was born in São Paulo, the big, boring and bestial industrial city of my country, Brazil. I obtained my PhD at São Paulo University (USP) in analytical induction, a math, logic, statistical and philosophic area. I never work in this area...but, one day, walking on a Sunday morning, I discovered that I could use my statistical skills to analyze malware behavior, like a math model. So, I invested my time in this area since 1989. Nowadays, I teach forensics at the University Nove de Julho (UNINOVE) and I work with forensic analysis and malware analysis (reverse engineering of malware) as a free consultant. To escape from reality, in my spare time, I go to some place to practice fly fishing in the rivers that cut through the mountains and I keep going to programming in C and Python my own pieces of software. Equipment and software: This course requires a Linux environment to analyze the artifacts. I will use Kali Linux running on ASUS notebook (RAM: 8 GB & 1 TB HD). In my case, I am using my own notebook to perform the analysis (but you can use Kali Linux in a virtual machine). My notebook runs UBUNTU 1604 LTS. I just install the tools that I need. Assembly knowledge. C and C++ knowledge basic programming security safety practices (PSSP).
Module 2
Before the course
Module 3
Module 1
Assessments
(W30A01) Module 1 Lab 1 - Basic
(W30A02) Module 1 Lab 2 - Advanced
Module 4
Module 2
Assessments
(W30A03) Module 2 Lab 1
(W30A04) Module 2 Lab 2 - Tor Forensics Network Packet Analysis
(W30A05) Module 2 Lab 3
Module 5
Module 3
Assessments
(W30A06) Module 3 Lab 1
(W30A07) Module 3 Lab 2
Module 6
Module 4
Assessments
(W30A08) Module 4 Lab 1
(W30A09) Module 4 Lab 2
(W30Q01) Final Test
Course access
Unlock Ransomware Forensics (W30).
Enter your email. We’ll send a sign-in code here without taking you away from this course.