20 seats left.
Register by Monday, March 24, 2025.

Event details

Mandiant Academy Training Event

  • Course: Malicious Documents Analysis
  • Date: Monday, March 31, 2025 – Thursday, April 3, 2025
  • Time: 8:00 AM–12:30 PM, daily
  • Time Zone: (UTC-05:00) Eastern Time (US & Canada)
  • Cost: $3,000 USD or 3 EOD units
  • Delivery Method: Instructor-led, virtual delivery
  • Location: Google Meet

At a glance

This course provides an introduction to the file formats, tools, and methodologies used to perform malware analysis on malicious documents using a practical hands-on approach. Students can learn to pinpoint and analyze suspicious document components and how to extract host and network-based indicators from them. This course includes demonstrations and hands-on labs that contain real malware.

Prerequisites: General knowledge of computer and operating system fundamentals. Exposure to programming fundamentals is recommended.

Course goals

After completing this course, learners should be able to:

  • Dissect and analyze malicious document formats
  • Extract network and host-based indicators
  • Extract noteworthy components that require further isolated analysis
  • Detect suspicious patterns and common exploitation techniques
  • Utilize modern analysis tools including OffVis and 010 editor
  • Create and automate custom tools for your specific organization

Who this course helps

Malware researchers, software developers, information security professionals, incident responders, computer security researchers, corporate investigators, and others who need to understand how malware operates and the processes involved in performing malware analysis.

What to bring

Students are required to bring their own laptop that meets the following specs:

  • VirtualBox 7+
  • At least 30 GB of free HDD space

Course materials

Students will receive a lab book and access to all required class materials and tools.