This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Bucharest AppSec Conference 2017 Training2"
Oana Cornea (talk | contribs) |
Oana Cornea (talk | contribs) |
||
| Line 92: | Line 92: | ||
'''Price: 1000 euros/person'''<br> | '''Price: 1000 euros/person'''<br> | ||
[https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | [https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | ||
| + | |- | ||
| + | | style="width:10%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | 2 days training <br> 12th and 13th of October <br> daily: 9:00 - 17:00<br><br> | ||
| + | | style="width:25%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | Advanced Malware analysis<br> | ||
| + | | style="width:25%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | Himanshu Khokhar | ||
| + | | style="width:40%" valign="middle" height="30" bgcolor="#CCEEEE" align="justify" colspan="0" | '''Description:'''<br> | ||
| + | Advanced Malware Analysis is a fast paced, full hands-on course which starts from the very basics of malware analysis and reverse engineering and then moves to advanced analysis of malwares (including malicious exe, js, pdf and word files as well) which then advances to analyze shellcodes, rootkits and ransomwares. Students taking this course will learn the tools and techniques to understand, analyze and defend against modern day malwares. | ||
| + | |||
| + | Syllabus | ||
| + | -------------------------------- | ||
| + | *1. Malware ananlysis fundamentals | ||
| + | *#Malware analysis and Reverse Engineering | ||
| + | *#Setting up an environment for malware analysis | ||
| + | *#Setting up the toolkit to analyze malwares effectively | ||
| + | *#Performing basic static analysis | ||
| + | *#Performing basic dynamic analysis | ||
| + | |||
| + | *2. Advanced Static Analysis | ||
| + | *#Revisiting x86 assembly concepts to apply it in malware analysis | ||
| + | *#Recognizing key data structures and language constructs in malware | ||
| + | *#Recognizing and locating common Windows API functions in malwares | ||
| + | *#Understanding and defeating anti-disassembly techniques | ||
| + | |||
| + | *3. Advanced Dynamic malware analysis | ||
| + | *#Getting used to debuggers and debugging | ||
| + | *#Understanding and defeating anti-debugging techniques | ||
| + | *#Dealing with packed malwares | ||
| + | *#Unpacking packed malwares and challenges in unpacking | ||
| + | *#Dumping packed malwares in unpacked state from memory | ||
| + | *#Understanding Code injection in depth | ||
| + | *#Dissecting file-less malwares | ||
| + | |||
| + | *4. Other major types of malware types | ||
| + | *#Understanding and dissecting JavaScript malwares | ||
| + | *#De-obfuscating JavaScript malwares | ||
| + | *#Understanding and dissecting PDF based malwares | ||
| + | *#Dissecting macro based malwares in Microsoft Office files | ||
| + | |||
| + | *5. Shellcodes, Rootkits and Ransomwares | ||
| + | *#Understanding Shellcodes and performing Shellcode analysis | ||
| + | *#Understanding Rootkits and performing Rootkit analysis | ||
| + | *#Understanding Ransomwares and performing Ransomware analysis | ||
| + | '''Intended audience:Advanced Malware Analysis is a full hands-on course. It is useful both for beginners into the field of malware analysis, as well as for those who have been into this area for some time but want to polish their skills to a new level. Other than malware analysts, reverse engineers, forensic investigators, threat analysts, students, people wanting to get into malware analysis can take this course.''' <br> | ||
| + | '''Skill level: ''' <br> | ||
| + | '''Requirements: Knowledge of x86 Assembly lang, familiarity with debuggers, disassemblers, Windows OS. A Laptop with at least 8 GB of RAM. VMWare Workstation or Virtualbox. ''' | ||
| + | <br> | ||
| + | '''Seats available: '''20 (first-come, first served)<br> | ||
| + | '''Price: 1000 euros/person'''<br> | ||
| + | [https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | ||
|} | |} | ||
Revision as of 19:49, 13 September 2017
Training | |||||
| Time | Title | Trainers | Description | ||
| 2 days training 11th and 12th of October daily: 9:00 - 17:00 |
Assessing and securing applications using the OWASP ASVS (Application Security Verification Standard) |
Oana Cornea | Description: The focus of this training will be on how to build secure applications and how to evaluate them using real world scenarios. The attendees will learn the concepts solving exercises and using various OWASP resources like the OWASP ASVS (Application Security Verification Standard) and the OWASP Testing Guide.
Topics covered:
Day 2:
| ||
| 2 days training 11th and 12th of October daily: 9:00 - 17:00 |
Advanced Mobile Security Training |
Nikhil P Kulkarni and Ravi Kumar | Description: The knowledge of Mobile Security, especially Android has become essential in securing today’s digital environment. This workshop is developed to introduce and bring hands on experience of the exciting and growing field of Android Pentesting and its Security Essentials.
Throughout the course, real-world examples in conjunction with numerous hands-on exercises will provide android pentesting & analysis skills.
| ||
| 2 days training 12th and 13th of October daily: 9:00 - 17:00 |
Advanced Malware analysis |
Himanshu Khokhar | Description: Advanced Malware Analysis is a fast paced, full hands-on course which starts from the very basics of malware analysis and reverse engineering and then moves to advanced analysis of malwares (including malicious exe, js, pdf and word files as well) which then advances to analyze shellcodes, rootkits and ransomwares. Students taking this course will learn the tools and techniques to understand, analyze and defend against modern day malwares. Syllabus
Intended audience:Advanced Malware Analysis is a full hands-on course. It is useful both for beginners into the field of malware analysis, as well as for those who have been into this area for some time but want to polish their skills to a new level. Other than malware analysts, reverse engineers, forensic investigators, threat analysts, students, people wanting to get into malware analysis can take this course. | ||