> learning path
Learn Malware Analysis
A structured path from how a binary works to automated analysis. Every lesson ends with a safe lab built on programs you compile yourself.
Module 01 · 4 lessons · ~120 min
Foundations
Why we reverse malware, how to do it safely, and what a binary actually is — from source code to a running process.
- 1.1What Is Malware Analysis?Why defenders reverse engineer malicious binaries, what questions analysis answers, and how triage, static and dynamic analysis fit together.20 min
- 1.2Building a Safe Analysis LabSet up isolated Windows and Linux analysis VMs with simulated networking, snapshots and safe sample-handling habits before touching any malware.35 min
- 1.3From Source Code to BinaryFollow a C program through preprocessing, compilation, assembly and linking, and learn what symbols, relocations and debug info leave behind.30 min
- 1.4How a Binary Is Loaded and RunWhat happens between double-clicking an executable and main(): process creation, memory mapping, the loader, imports, ASLR, CRT startup and TLS callbacks.35 min
Module 02 · 5 lessons · ~195 min
Binary Formats
The PE format in depth — headers, sections, imports, exports and resources — plus the ELF essentials for Linux malware.
- 2.1PE Headers: DOS, NT and Optional HeaderWalk the headers at the start of every Windows executable, byte by byte, and learn which fields analysts trust, which they doubt and which malware abuses.40 min
- 2.2PE Sections and Memory LayoutHow the section table maps a PE file into memory, how to convert RVAs to file offsets, and which section anomalies betray packers and loaders.40 min
- 2.3Imports, Exports and the IATHow PE files declare the API functions they use and provide, how the loader fills the IAT, and how malware hides its imports from you.45 min
- 2.4Resources, Overlays and Other Hiding PlacesWhere PE files carry data outside their code: the resource tree, version info, overlays, Authenticode signatures, and the .NET and TLS directories.35 min
- 2.5ELF for Malware AnalystsThe ELF essentials for Linux malware: headers, sections versus segments, dynamic linking, and why stripped, static and header-less binaries still run.35 min
Module 03 · 6 lessons · ~250 min
Static Triage
Answering the first questions about a sample in minutes, without running it — and turning what you find into detections.
- 3.1Identifying and Hashing FilesIdentify a file by its magic bytes rather than its name, then fingerprint it with cryptographic, import, fuzzy and Rich header hashes.40 min
- 3.2Strings and Obfuscated StringsExtract ASCII and UTF-16 strings, separate indicators from runtime noise, and recover stack, XOR and decoded strings with FLOSS and CyberChef.45 min
- 3.3Reading Capabilities from ImportsTurn a PE import table into a capability hypothesis: group APIs by behaviour, spot suspicious combinations, and use capa to confirm with code evidence.35 min
- 3.4Detecting Packers and EntropyRecognise packed and encrypted executables with entropy, section anomalies, import tables and signatures — and avoid the classic false positives.35 min
- 3.5Writing Your First YARA RulesTurn triage findings into YARA rules: strings, hex patterns, the pe and math modules, performance, and testing against goodware and variants.50 min
- 3.6Writing a Triage ReportTurn static triage into a report people can act on: verdict and confidence, ATT&CK-mapped capabilities, defanged IOCs, detections and next steps.45 min
Module 04 · 5 lessons · ~245 min
Disassembly & Code Analysis
How disassemblers recover code, how to read compiler output, and how control-flow and data-flow analysis guide you.
- 4.1Linear vs Recursive DisassemblyHow disassemblers decide which bytes are code, why linear sweep and recursive descent fail in different ways, and how to build a tiny recursive disassembler.45 min
- 4.2Functions and Control-Flow GraphsSplit code into basic blocks, read the CFG shapes of ifs, loops and switches, find x64 Windows function boundaries, and build a CFG with Capstone.50 min
- 4.3Recognising Compiler IdiomsMap optimised x86-64 compiler output back to C: frames, magic-number division, branchless code, loops, jump tables, structs and vtables.50 min
- 4.4Decompilers and Their LimitsHow decompilers turn machine code into C-like pseudocode, where that output misleads you, and how to repair it with types, names and signatures.50 min
- 4.5Cross-References and Data FlowUse cross-references to pivot from strings and imports to the code that uses them, trace values backwards, and restore xrefs lost to indirect calls.50 min
Module 05 · 5 lessons · ~40 min
Windows Internals for Analysts
The Windows concepts malware leans on — the API and native API, processes, threads, DLLs, mutexes, services, the registry and the user/kernel boundary.
- 5.1The Windows API for AnalystsComing soon
- 5.2Processes, Threads and DLLsWhat processes, threads and DLLs look like to an observer — PEB, TEB, tokens, handles, process trees and module lists — and how to read them as evidence.40 min
- 5.3The Registry, Services and Scheduled TasksComing soon
- 5.4Mutexes, Events and Inter-Process CommunicationComing soon
- 5.5User Mode, Kernel Mode and the Native APIComing soon
Module 06 · 5 lessons · ~220 min
Dynamic Analysis
Running samples under observation — behavioural monitoring, network simulation, debugging, API tracing and memory dumping.
- 6.1Behavioural MonitoringRun a sample through a repeatable detonation routine with Process Monitor, Sysmon, registry diffs and Autoruns, then turn what you see into host IOCs.40 min
- 6.2Simulating and Capturing Network TrafficKeep a sample's traffic inside the lab with INetSim and FakeNet-NG, capture it, and read DNS, HTTP, beacon timing and TLS fingerprints as network IOCs.40 min
- 6.3Debugging Malware with x64dbgHow debuggers stop and step a process, how to drive x64dbg around a sample, and the analyst loop: break on an API, read its arguments, flip a branch.50 min
- 6.4Tracing API and System CallsRecord a sample's API and system calls instead of stepping through them, cut the noise, read the trace as behaviour, and know where tracing goes blind.45 min
- 6.5Dumping Memory and Extracting PayloadsCapture process and system memory, find the region that holds the real payload, and turn a memory-layout PE back into a file your tools can parse.45 min
Module 07 · 6 lessons
Malware Behaviours
What malware actually does and how each behaviour looks in code and telemetry — persistence, command and control, credential theft, injection and stealth.
- 7.1Loaders, Droppers and DownloadersComing soon
- 7.2Persistence MechanismsComing soon
- 7.3Command and ControlComing soon
- 7.4Credential Theft and KeyloggingComing soon
- 7.5Understanding Process InjectionComing soon
- 7.6Hooking and User-Mode RootkitsComing soon
Module 08 · 5 lessons · ~255 min
Encoding, Crypto & Signatures
Recognising encodings and cryptography, extracting configurations, and turning what you decode into network and host signatures.
- 8.1Recognising XOR, Base64 and Custom EncodingsSpot XOR, rolling-key and custom Base64 encodings in data and in code, recover their keys with key-length tests and known plaintext, and decode them.45 min
- 8.2Identifying Cryptographic AlgorithmsTell encryption from encoding, identify AES, RC4, ChaCha20, TEA, hashes and CRC32 from constants, loops and imports, then locate the key and IV to report.50 min
- 8.3Scripting String DecryptionRecover hundreds of encrypted strings at once by finding the decrypt routine, recovering each call's arguments statically, and scripting the algorithm.55 min
- 8.4Extracting Malware ConfigurationsTurn a sample's embedded configuration into normalised JSON with a locate-decode-parse-output extractor, and share the results responsibly.55 min
- 8.5Writing Network SignaturesTurn a sample's network code and captured traffic into Suricata rules that target durable protocol structure, then test them against pcaps.50 min
Module 09 · 6 lessons · ~185 min
Evasion & Unpacking
Defeating the tricks that waste analysts' time — anti-disassembly, anti-debugging, sandbox detection and packing — by patching, hooking and unpacking.
- 9.1Anti-DisassemblyRecognising the tricks that make a disassembler lie — constant-condition jumps, overlapping instructions, rogue bytes — and repairing the listing.45 min
- 9.2Anti-DebuggingThe families of debugger detection — API calls, PEB and heap flags, timing and hardware checks — how to spot each in a sample and get past it.50 min
- 9.3Anti-VM and Sandbox EvasionComing soon
- 9.4Patching Binaries to Defeat ChecksUse patching as an analysis tool: flip a jump, NOP a check or force a return so a sample reveals what it hides, in memory or on the file.45 min
- 9.5How Packers WorkWhat a packer's unpacking stub does step by step — decompress, rebuild imports, relocate, jump to the OEP — and what it means for unpacking.45 min
- 9.6Manual Unpacking to the OEPComing soon
Module 10 · 4 lessons · ~180 min
Beyond the EXE
Malware that is not a native executable — shellcode, .NET assemblies, scripts and malicious documents — and the tools each one needs.
- 10.1Shellcode AnalysisHow to recognise raw shellcode without headers, follow its get-PC and API-resolution idioms, and disassemble, emulate and extract IOCs from it safely.45 min
- 10.2Analysing .NET MalwareHow to recognise a .NET assembly, read its metadata and IL, pick the right decompiler, and get past obfuscators and in-memory stages.45 min
- 10.3PowerShell, JavaScript and VBScript MalwareDeobfuscate malicious PowerShell, JavaScript and VBScript without running them: neutralise eval sinks, decode layers, read script logs, extract IOCs.45 min
- 10.4Malicious Documents and ArchivesTriage malicious Office files, RTF, PDF, archives, disk images and LNK shortcuts without opening them, and pull out the next stage and its IOCs.45 min
Module 11 · 5 lessons · ~205 min
Automated & Advanced Analysis
Letting tools do the heavy lifting — instrumentation, emulation, taint analysis, symbolic execution and analysis pipelines.
- 11.1Dynamic Binary InstrumentationHow DBI engines like Pin, DynamoRIO, Frida and TinyInst inject analysis code into a running sample to log API calls, map coverage and catch unpacking.50 min
- 11.2Emulating Code with Unicorn and SpeakeasyWhy analysts emulate instead of run, CPU vs OS-level emulators, and how to call a sample's own decryption routine with stubbed APIs.55 min
- 11.3Dynamic Taint AnalysisHow taint tracking follows data from sources to sinks, the design choices that cause over- and under-tainting, and how analysts use it on malware.50 min
- 11.4Symbolic Execution with angrComing soon
- 11.5Building an Analysis PipelineTurn manual triage into a repeatable pipeline: deduplication, file-type routing, static enrichment, scoring, safe isolation and reproducible reports.50 min