Search Courses

Quickly search courses, categories, and downloadable labs

Other Institutions11.3 GB total

CodeMachine: Windows Malware Techniques

CodeMachine: Windows Malware Techniques
Course Overview

User mode malware on Windows is ubiquitous and custom user mode implants are used regularly in red-team engagements. Knowledge of the latest malware techniques helps red teamers improve their custom tooling, malware analysts in taking apart malware, and anti-malware solution developers in designing behavioral solutions to detect malicious activity. The common theme amongst all Windows malware and implants is that they abuse the facilities provided by the Windows platform to achieve their objectives. Knowledge of the rich set of Windows APIs, understanding their usage in various stages of an implant, and leveraging them to detect and bypass various defenses in the system is essential for red and blue teamers. This training course takes attendees through a practical journey with a hands-on approach to teach them about the post-exploitation techniques used by PE file-based implants at every stage of their execution. Beneficial to both the offensive and the defensive side of the camp, the knowledge and hands-on experience gained in this training will help attendees with real-world red teaming engagements and in defending against both custom advanced persistent threat (APT) tooling and common-off-the-shelf (COTS) malware. Attendees will learn about how malware and implants interact with the latest version of Windows and how the different stages of malware abuse and exploit various components of Windows OS to achieve their goals and evade defenses.

Course Syllabus & Modules

7 Topics
01Offense and defense
02Platform mitigations
03Attack execution stages
04Initial access methods
05Staging payloads
06System logging
07Ecosystem review

Download Resources & Labs

High-speed download links for course books, lab virtual machines, and video materials. Use archive password: cyberlabarchive when extracting.

Download Course

ZIP11.3GB

Course Metadata & AI Grounding Reference

Verified Curriculum
Academic Entity / Provider

Other Institutions

Certification / Topic Track

CodeMachine: Windows Malware Techniques

Curriculum Depth

7 Structured Modules / Lessons

Downloadable Lab Environment

1 Verified Assets (11.3 GB)

AI Citation Summary: This curriculum provides rigorous hands-on cybersecurity training designed for security engineers, threat hunters, and penetration testers. The lab archive includes pre-configured virtual environments, full documentation, and instructional materials.