Understanding malware: detection, prevention and response
When facing malware, understanding how the threat works helps you choose a response. Develop your ability to identify suspicious behaviour, examine evidence and connect findings to defensive measures. Bring greater structure to your detection and prevention activities.
- Duration
- 2 days 14 hours
- Code
- SSR001FR Code
Presentation
Malware, or malicious software, is a major and constantly evolving IT threat, making an understanding of it essential for every organisation. This course offers a detailed analysis of malware: how it works, its various classifications (viruses, ransomware, Trojans, etc.) and its infiltration methods. You will develop a clear perspective on the current IT security challenges posed by these persistent threats.
This 2-day programme guides you through malware types, from traditional viruses to ransomware and IoT malware. You will analyse infection vectors, from social engineering to vulnerability exploitation. The course emphasises detection and analysis strategies, examining tools such as antivirus software, EDR and online analysis platforms. Hands-on workshops will enable you to analyse simple malware and simulate incidents to strengthen your operational understanding.
By the end of the course, you will be able to implement effective malware prevention and detection measures. You will master best practices for securing systems and raising user awareness. Most importantly, you will know how to respond effectively to an incident, from containment through eradication and system restoration, including incident report writing.
Objectives
By the end of this malware course, you will be able to:
- identify different malware families and their specific characteristics;
- understand the infection vectors and evasion techniques used by malicious software;
- analyse the potential impacts of a malware attack on systems and data;
- implement effective threat prevention and detection measures;
- respond effectively to a malware-related security incident.
Program
Module 1: introduction to malware
- The definition and history of malicious software.
- Cyberattackers' objectives (espionage, sabotage, ransom demands and data theft).
- Overview of current malware threats.
Module 2: identify malware types
- Different malware types (viruses, worms and Trojans).
- Operation, encryption techniques and ransom processes used by ransomware.
- Spyware, adware and keyloggers.
- Rootkits and bootkits.
- Malware specifically designed for mobile platforms and IoT.
Module 3: analyse infection vectors
- Phishing and social engineering as infection vectors.
- Vulnerability exploitation (exploits, zero-days).
- Physical and digital entry points: USB drives, malicious downloads and booby-trapped websites.
Practical exercises:
- Analyse a suspicious file to determine whether it is malicious.
- Conduct behavioural analysis using a sandbox.
- Identify indicators of compromise (IoCs).
Module 4: detect and analyse malware
- Advanced detection tools: antivirus, anti-malware and EDR (Endpoint Detection and Response).
- The distinction between static and dynamic malware analysis.
- Using specialised online analysis tools such as VirusTotal, Any.Run and Hybrid Analysis.
Module 5: implement prevention and best practices
- Regular system updates and security patching.
- Securing access and managing user privileges.
- Raising user awareness of risks and IT security best practices.
Module 6: manage malware incident response
- Containment steps (isolating the infected workstation) during an incident.
- Procedures for eradicating malware and restoring affected systems.
- Post-incident communication and lessons learned for continuous improvement.
Practical exercises:
- Simulate ransomware detection in a realistic scenario.
- Develop an incident response action plan.
- Write a comprehensive incident report.
Audience
This course is intended for:
- System technicians and administrators seeking to strengthen their malware security skills.
- SOC and cybersecurity analysts who want to deepen their understanding of malware operation, detection and response.
- IT security students seeking an in-depth understanding of malicious threats and their mechanisms.
- IT managers and new CISOs who want to understand malware challenges to better protect their infrastructure.
- IT recruiters seeking a clearer understanding of cybersecurity roles and malware management skills.
Prerequisites
This course requires the following prerequisites:
- Knowledge of IT and system security: understanding of IT basics and fundamental system security concepts is required.
- Confidence with Windows or Linux environments: familiarity with using and navigating one of these operating systems is necessary.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- In-depth threat analysis: explore how malicious software works, examine different types (viruses, ransomware, Trojans) and identify their infiltration methods.
- A practical, hands-on approach: develop immediately applicable skills through interactive demonstrations, real-world case studies and practical workshops dedicated to detection, prevention and incident response.
- Master defensive strategies: acquire expertise in identifying malware families, understanding evasion techniques, analysing their impact and implementing effective prevention and detection measures.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en