Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

Investigating Malware with Falcon MalQuery

( Duration: 1 Day )

This Investigating Malware with Falcon MalQuery training course covers all angles of MalQuery's use, from beginner searches through advanced malware hunting with YARA.

By attending Investigating Malware with Falcon MalQuery workshop, delegates will learn to:

  • Use MalQuery Search, Hunt, and Monitor to categorize malware
    • Apply tools to known or suspected malware samples to extract potential functions
    • Differentiate use cases between MalQuery Search and Hunt
  • Research malware samples to determine family relationships and other indicators
    • Determine if sample is malware, and if so, to which family it belongs
    • Analyze findings to determine possible actor attribution
  • Utilize proper YARA rule-writing techniques to enable hunting
    • Create new YARA rules based on retrieved indicators
    • Apply intelligence analysis concepts to better use malware research techniques

  • Knowledge of Falcon Platform (or experience using CrowdStrike Falcon)
  • Intermediate knowledge of cybersecurity incident investigation and incident lifecycle

COURSE AGENDA

1

Malquery Overview

  • The Falcon search engine
  • Introduction to MalQuery
  • Key benefits of using MalQuery
  • MalQuery technical specifications
  • How MalQuery fits in with other Falcon applications
2

Malquery Search

  • Search basics
  • Search the MalQuery database based on retrieved indicators
  • Finding search parameters
3

Introduction To Yara

  • Introduction to YARA
  • Rule structure
  • Rule writing and implementation
  • Modules, includes and extensions
4

Malquery Hunt

  • Hunt basics
  • Hunt the MalQuery database with YARA based on retrieved indicators
  • Reading hunt results
5

Advanced Hunting

  • Advanced rule types
  • Stacking rules
  • Advanced conditions
  • Special string constructors
6

Malquery Monitor

  • Monitoring overview
  • Using MalQuery Monitor to enable prospective hunting capabilities
  • New results

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X