{"product_id":"a-practical-malware-analysis-threat-hunting-with-memory-forensics-endpoint-telemetry-ai-driven-hunting","title":"A Practical Malware Analysis \u0026 Threat Hunting with Memory Forensics, Endpoint Telemetry, \u0026 AI-Driven Hunting","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e A Practical Malware Analysis \u0026amp; Threat Hunting with Memory Forensics, Endpoint Telemetry, \u0026amp; AI-Driven Hunting\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Monnappa, Sajan Shetty\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis hands-on training covers malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting. It also introduces AI-powered hunting with the Garuda Framework to triage events, extract IOCs, and detect unknown attacks without relying on signatures or patterns.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis intensive, hands-on training teaches the concepts, tools, and techniques required to analyze, investigate, and hunt malware by combining four powerful approaches: malware analysis, reverse engineering, memory forensics, and endpoint telemetry-based threat hunting.\u003c\/p\u003e\n\u003cp\u003eThe course begins with the foundations of malware analysis, Windows internals, and memory forensics, before moving into advanced concepts of malware investigation and hunting adversary techniques.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Introduction to Malware Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e What is Malware\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e What they do\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Why malware analysis\u003cbr\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Types of malware analysis\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Setting up an isolated lab environment\u003c\/p\u003e\n\u003ch3\u003e3.2 Static Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Fingerprinting the malware\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Extracting strings\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Determining File obfuscation\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Pattern matching using YARA\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Fuzzing hashing \u0026amp; comparison\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Understanding PE File characteristics\u003cbr\u003e\u003cstrong\u003e3.2.7\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003e3.3 Dynamic Analysis \/ Behavioural Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Dynamic Analysis Steps\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Understanding Dynamic Analysis tools\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Simulating services\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Performing Dynamic Analysis\u003cbr\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e Monitoring process, filesystem, registry, and network activity\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e Determining the Indicators of compromise (host and network indicators)\u003cbr\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e Demo - Showing the static \u0026amp; dynamic analysis of real malware sample\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003e3.4 Automating Malware Analysis (Sandbox)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Custom Sandbox Overview\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Working of Sandbox\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Sandbox Features\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Demo - Analyzing malware in the custom sandbox\u003c\/p\u003e\n\u003ch3\u003e3.5 Malware Persistence Methods\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Run registry key\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Scheduled Tasks\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Startup Folder\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Service\u003cbr\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Winlogon registry entries\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Image File Execution Options (IFEO)\u003cbr\u003e\u003cstrong\u003e3.5.7\u003c\/strong\u003e Accessibility programs\u003cbr\u003e\u003cstrong\u003e3.5.8\u003c\/strong\u003e AppInit_DLLs\u003cbr\u003e\u003cstrong\u003e3.5.9\u003c\/strong\u003e DLL Search order hijacking\u003cbr\u003e\u003cstrong\u003e3.5.10\u003c\/strong\u003e Hands-on lab exercise involves analyzing real malware sample\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.6 Code Analysis\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Code Analysis Overview\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Disassembler \u0026amp; Debuggers\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Code Analysis Tools\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Basics of IDA Pro\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Basics of x64dbg\u003cbr\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Understanding API Calls\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Cross References using IDA\u003cbr\u003e\u003cstrong\u003e3.6.8\u003c\/strong\u003e Cross References using x64dbg\u003c\/p\u003e\n\u003ch3\u003e3.7 Reversing Malware Functionalities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Downloader\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Dropper\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Keylogger\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Code injection (Fileless malware)\u003cbr\u003e\u003cstrong\u003e3.7.5\u003c\/strong\u003e Malware replication via removable media\u003cbr\u003e\u003cstrong\u003e3.7.6\u003c\/strong\u003e Malware Command \u0026amp; Control (C2)\u003c\/p\u003e\n\u003ch3\u003e3.8 Introduction to Memory Forensics\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e What is Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Why Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Steps in Memory Forensics\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Memory acquisition and tools\u003cbr\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Acquiring memory From physical machine\u003cbr\u003e\u003cstrong\u003e3.8.6\u003c\/strong\u003e Acquiring memory from virtual machine\u003cbr\u003e\u003cstrong\u003e3.8.7\u003c\/strong\u003e The hands-on exercise involves acquiring the memory\u003c\/p\u003e\n\u003ch3\u003e3.9 Volatility Overview\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e Introduction to Volatility Advanced Memory Forensics Framework\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e Volatility Installation\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e Volatility basic commands\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Determining the profile\u003cbr\u003e\u003cstrong\u003e3.9.5\u003c\/strong\u003e Volatility help options\u003cbr\u003e\u003cstrong\u003e3.9.6\u003c\/strong\u003e Running the plugin\u003c\/p\u003e\n\u003ch3\u003e3.10 Investigating Process\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Understanding Process Internals\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Process (EPROCESS) Structure\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Process organization\u003cbr\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Process Enumeration by walking the double linked list\u003cbr\u003e\u003cstrong\u003e3.10.5\u003c\/strong\u003e Process relationship (parent-child relationship)\u003cbr\u003e\u003cstrong\u003e3.10.6\u003c\/strong\u003e Understanding DKOM attacks\u003cbr\u003e\u003cstrong\u003e3.10.7\u003c\/strong\u003e Process Enumeration using pool tag scanning\u003cbr\u003e\u003cstrong\u003e3.10.8\u003c\/strong\u003e Volatility plugins to enumerate processes\u003cbr\u003e\u003cstrong\u003e3.10.9\u003c\/strong\u003e Identifying malware process\u003cbr\u003e\u003cstrong\u003e3.10.10\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.11 Investigating Process Handles \u0026amp; Registry\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Objects and handles overview\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e Enumerating process handles using Volatility\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Understanding Mutex\u003cbr\u003e\u003cstrong\u003e3.11.4\u003c\/strong\u003e Detecting malware presence using the mutex\u003cbr\u003e\u003cstrong\u003e3.11.5\u003c\/strong\u003e Understanding the Registry\u003cbr\u003e\u003cstrong\u003e3.11.6\u003c\/strong\u003e Investigating common registry keys using Volatility\u003cbr\u003e\u003cstrong\u003e3.11.7\u003c\/strong\u003e Detecting malware persistence\u003cbr\u003e\u003cstrong\u003e3.11.8\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.12 Investigating Network Activities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e Understanding malware network activities\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e Volatility Network Plugins\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e Investigating Network connections\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Investigating Sockets\u003cbr\u003e\u003cstrong\u003e3.12.5\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.13 Investigation Process Memory\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.13.1\u003c\/strong\u003e Process memory Internals\u003cbr\u003e\u003cstrong\u003e3.13.2\u003c\/strong\u003e Listing DLLs using Volatility\u003cbr\u003e\u003cstrong\u003e3.13.3\u003c\/strong\u003e Identifying hidden DLLs\u003cbr\u003e\u003cstrong\u003e3.13.4\u003c\/strong\u003e Dumping malicious executable from memory\u003cbr\u003e\u003cstrong\u003e3.13.5\u003c\/strong\u003e Dumping Dll's from memory\u003cbr\u003e\u003cstrong\u003e3.13.6\u003c\/strong\u003e Scanning the memory for patterns (yarascan)\u003cbr\u003e\u003cstrong\u003e3.13.7\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003ch3\u003e3.14 Investigating User-Mode Rootkits \u0026amp; Fileless Malwares\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e Code Injection\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Types of Code injection\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e Remote DLL injection\u003cbr\u003e\u003cstrong\u003e3.14.4\u003c\/strong\u003e Remote Code injection\u003cbr\u003e\u003cstrong\u003e3.14.5\u003c\/strong\u003e Reflective DLL injection\u003cbr\u003e\u003cstrong\u003e3.14.6\u003c\/strong\u003e Hollow process injection\u003cbr\u003e\u003cstrong\u003e3.14.7\u003c\/strong\u003e Demo - Case Study\u003cbr\u003e\u003cstrong\u003e3.14.8\u003c\/strong\u003e Hands-on lab exercise (scenario based) involves investigating malware infected memory\u003c\/p\u003e\n\u003ch3\u003e3.15 Investigating Kernel-Mode Rootkits\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Understanding Rootkits\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Understanding Functional call traversal in Windows\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e Level of Hooking\/Modification on Windows\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Kernel Volatility plugins\u003cbr\u003e\u003cstrong\u003e3.15.5\u003c\/strong\u003e Hands-on lab exercise (scenario-based) involves investigating malware infected memory\u003cbr\u003e\u003cstrong\u003e3.15.6\u003c\/strong\u003e Demo - Rootkit Investigation\u003c\/p\u003e\n\u003ch3\u003e3.16 Threat Hunting Using Endpoint Telemetry\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e Introduction to Sysmon\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Understanding Sysmon Events\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Introduction to Garuda Threat Hunting Framework\u003cbr\u003e\u003cstrong\u003e3.16.4\u003c\/strong\u003e Filtering Sysmon events using Garuda\u003cbr\u003e\u003cstrong\u003e3.16.5\u003c\/strong\u003e Living off the Land attacks\u003cbr\u003e\u003cstrong\u003e3.16.6\u003c\/strong\u003e Demo: Hunting LoLbins (Living of the land binary) and multi-staged attacks\u003c\/p\u003e\n\u003ch3\u003e3.17 AI-Powered Threat Hunting\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Introduction to AI in threat detection \u0026amp; hunting\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e Introduction to MCP (Model Context Protocol)\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Exposing Tools to the LLM\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Integrating Garuda Framework with AI application\u003cbr\u003e\u003cstrong\u003e3.17.5\u003c\/strong\u003e How Garuda + AI can triage events, identify IOCs, and Map events to ATT\u0026amp;CK Techniques\u003cbr\u003e\u003cstrong\u003e3.17.6\u003c\/strong\u003e Demo: AI-powered autonomous Threat hunting to hunt for complex attack patterns\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdvanced\u003c\/strong\u003e - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eExpert or Specialized\u003c\/strong\u003e - The student has a solid understanding of the topic at hand, usually with knowledge of relevant standards, tactics, tools, and years of relevant hands-on experience. Students should expect to use these skills with agility to solve problems in novel ways.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should be familiar with using Windows\/Linux.\u003c\/li\u003e\n\u003cli\u003eStudents should have an understanding of basic programming concepts, while programming experience is not mandatory.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop with a minimum of 8GB RAM and 60GB free hard disk space\u003c\/li\u003e\n\u003cli\u003eLaptop with USB ports - lab samples and custom Linux VM will be shared via USB sticks\u003c\/li\u003e\n\u003cli\u003eVMware Workstation or VMware Fusion (even trial versions can be used)\u003c\/li\u003e\n\u003cli\u003eWindows Operating system (preferably 64-bit versions of Windows 11 or Windows 10) installed inside the VMware Workstation\/Fusion. Students must have full administrator access to the Windows operating system installed inside the VMware Workstation\/Fusion.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c\/strong\u003e VMware Player or VirtualBox is not suitable for this training. Apple systems using the M1 processor line cannot perform the necessary virtualization functionality; therefore, they are not suitable for this course.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e7.1\u003c\/strong\u003e Course material (pdf copy)\u003cbr\u003e\u003cstrong\u003e7.2\u003c\/strong\u003e Lab solution material\u003cbr\u003e\u003cstrong\u003e7.3\u003c\/strong\u003e Videos used in the course\u003cbr\u003e\u003cstrong\u003e7.4\u003c\/strong\u003e Malware samples used in the course\/labs\u003cbr\u003e\u003cstrong\u003e7.5\u003c\/strong\u003e Memory Images used in the course\/labs\u003cbr\u003e\u003cstrong\u003e7.6\u003c\/strong\u003e Linux VM (to be opened with VMware Workstation\/Fusion) containing necessary tools and samples\u003cbr\u003e\u003cstrong\u003e7.7\u003c\/strong\u003e Custom tools\u003c\/p\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eMonnappa K A\u003c\/h3\u003e\n\u003cp\u003eMonnappa K A is a Security Professional with over 17 years of experience in incident response, investigation, and threat hunting. He previously worked for Microsoft and Cisco as a threat hunter, mainly focusing on the investigation and research of advanced cyberattacks. He is the author of the best-selling book Learning Malware Analysis, and serves on the review board for Black Hat Asia, Black Hat USA, and Black Hat Europe.\u003c\/p\u003e\n\u003cp\u003eHe is the creator of the Garuda Threat Hunting Framework, Limon Linux sandbox, and the winner of the Volatility Plugin Contest 2016. He co-founded the cybersecurity research community Cysinfo (\u003ca href=\"https:\/\/www.cysinfo.com\"\u003ehttps:\/\/www.cysinfo.com\u003c\/a\u003e).\u003c\/p\u003e\n\u003cp\u003eMonnappa has trained thousands of security professionals globally through his highly acclaimed hands-on training sessions on malware analysis, reverse engineering, memory forensics, and threat hunting at major conferences such as Black Hat (USA, Europe, Asia, MEA), DEFCON, BruCON, HITB, FIRST (Forum of Incident Response and Security Teams), SEC-T, OPCDE, and 4SICS-SCADA\/ICS cybersecurity summit.\u003c\/p\u003e\n\u003cp\u003eHe has also presented at numerous security conferences, including Black Hat, DEFCON, FIRST, DSCI, National Cyber Defence Summit, Bharat NCX, and Cysinfo meetings, covering topics related to threat hunting, memory forensics, malware analysis, and reverse engineering.\u003c\/p\u003e\n\u003cp\u003eIn addition, he has authored articles for eForensics and Hakin9 magazines. You can find some of his contributions to the community on his YouTube channel (\u003ca href=\"http:\/\/www.youtube.com\/c\/MonnappaKA\"\u003ehttp:\/\/www.youtube.com\/c\/MonnappaKA\u003c\/a\u003e), and you can read his blog posts at \u003ca href=\"https:\/\/cysinfo.com\"\u003ehttps:\/\/cysinfo.com\u003c\/a\u003e.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTwitter:\u003c\/strong\u003e @monnappa22\u003c\/p\u003e\n\u003ch3\u003eSajan Shetty\u003c\/h3\u003e\n\u003cp\u003eSajan Shetty is a Cyber Security enthusiast. He is an active member of Cysinfo, an open Cyber Security Community (\u003ca href=\"https:\/\/www.cysinfo.com\"\u003ehttps:\/\/www.cysinfo.com\u003c\/a\u003e) committed to educating, empowering, inspiring, and equipping cyber security professionals and students to better fight and defend against cyber threats.\u003c\/p\u003e\n\u003cp\u003eHe has conducted training sessions at Black Hat, DEFCON, BRUCON and HITB, and his primary fields of interest include machine learning, malware analysis, and memory forensics. He has various certifications in machine learning and is passionate about applying machine learning techniques to solve cybersecurity problems.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942323658995,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Monnappa_updated_image.webp?v=1786560120","url":"https:\/\/me.shop.defcon.org\/products\/a-practical-malware-analysis-threat-hunting-with-memory-forensics-endpoint-telemetry-ai-driven-hunting","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}