本课程专为零基础设计,通过REMnux与FlareVM双环境,深入解析PE文件、x86/x64汇编、IDA Pro及x64dbg调试,覆盖恶意软件分析核心技术。结合内存取证与Cobalt Strike真实案例,助你掌握从样本分析到YARA规则编写的实战能力。

原始标题:GREM: Complete Malware Analysis & Reverse Engineering

GREM: Complete Malware Analysis & Reverse Engineering

本课程专为零基础学员设计,通过REMnux与FlareVM双环境,深入解析PE文件、x86/x64汇编、IDA Pro/Ghidra静态与x64dbg动态调试,全面覆盖恶意软件分析核心技术。通过结合内存取证与网络审计,结合Cobalt Strike等真实案例,学员将系统掌握从样本分析到YARA规则编写的实战能力,实现向高级威胁猎人的跨越。

Published 7/2026
Created by Armaan Sidana
MP4 | Video: h264, 1920×1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: All Levels | Genre: eLearning | Language: English | Duration: 13 Lectures ( 6h 2m ) | Size: 3.7 GB

Master PE analysis, x64dbg debugging, Volatility 3 memory forensics & malware family recognition for GIAC GREM

Description
Malware analysis is one of the most in-demand and least-taught skills in cybersecurity.

This course gives you the complete methodology, toolset, and hands-on technique to

analyze real malware samples from triage to full reverse engineering.

The course is structured around the GIAC GREM exam domains and covers everything

you need to identify, characterize, and write detections for modern malware threats.

YOU WILL START with the PE file format. Every byte of the structure matters: the

DOS header, Optional Header, section table, Import Address Table, and how each field

reveals capability. You will learn to spot packed binaries through entropy analysis,

unpack them with x64dbg ud reconstruct IATs with

Scylla.

FROM THERE you move into assembly. x86 and x64 registers, calling conventions,

stack mechanics, XOR decryption loops, shellcode PEB walks, and API

ROR-13. You will learn to read disassembly in IDA Pro and Ghidra without writing a single line of code you

THE STATIC ANALYSIS MODULE covers FLIRT signatures, encrypted string table

decryption with IDAPython, API hash resolution using HashDB, crypto identification

with FindCrypt (AES, RC4, SHA-256, ChaCha20), and full config extraction workflows

using pefile and PyCrypto

DYNAMIC ANALYSIS walks through the correct tool startup order, ProcMon filter

strategy, Process Hacker RWX memory detection, Regshot diff interpretation,

FakeNet-NG C2 simulation,acing. You will perform a

complete RAT behavioral ato IOC report.

THE DEBUGGING MODULE covers all four breakpoint types in x64dbg, ScyllaHide

anti-debug bypass, OEP hu capture from WindowsCrypto

and BCrypt APIs, logging breakpoints for automated injection tracing, and

runtime

patching to bypass anti-analysis checks.

WINDOWS INTERNALS covers structure at exact

offsets,

the VAD tree, and six process injection techniques with full API sequences: DLL

injection, shellcode injection, process hollowing, process doppelganging,

reflective

DLL loading, and APC injeASS credential theft, COM

hijacking, WMI persistench detection methods foreach.

ANTI-ANALYSIS covers contredicates, VM-based

obfuscation with Themida chniques, ETW tampering,

fileless malware executiog certutil, mshta, and

regsvr32 Squiblydoo.

4.0 XLM macros with xlmdescation layer by layer,

.NET malware with de4dot and dnSpy, Python/PyInstaller extraction with pyinstxtractor,

PDF analysis with pdfid.p rtfobj py, and LNK files

with lnkparse.

NETWORK ANALYSIS covers Wireshark display filters for malware traffic, JA3 and

JA3S fingerprinting, DGA detection, DNS tunneling, Zeek structured log analysis,

Suricata rule writing, anrotocol.

MEMORY FORENSICS covers the full Volatility 3 plugin suite: pslist vs psscan for

DKOM-hidden process detecellcode and PEidentification,

ldrmodules for reflective DLL detection, modscan for hidden kernel drivers,

windows.ssdt

for syscall hook detection, and artifact extraction with procdump, memdump, and dumpfiles.

THE FINAL MODULES cover recognition fingerprints for 20+ malware families including

Emotet, TrickBot, LockBitT, RedLine Stealer, Cobalt

Strike, Meterpreter, Bumblebee, and GuLoader, with complete MITRE ATT&CK mapping

and threat intelligence I

TOOLS COVERED INCLUDE: IDA Pro, Ghidra, x64dbg, ScyllaHide, Scylla, pestudio,

CFF Explorer, Detect-It-Eacker, ProcMon, Regshot,

FakeNet-NG, Wireshark, API Monitor, PE-Sieve, HollowsHunter, Volatility 3, dnSpy,

This course prepares you for both the GIAC GREM certification and real-world

malware analysis engageme a practice scenariomodeled

on exam-style questions.

隐藏内容

百度网盘下载:

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注