Skip to content

> learning path

Learn Malware Analysis

A structured path from how a binary works to automated analysis. Every lesson ends with a safe lab built on programs you compile yourself.

Start the path →
0 / 43 completed
  1. Module 05 · 5 lessons · ~40 min

    Windows Internals for Analysts

    The Windows concepts malware leans on — the API and native API, processes, threads, DLLs, mutexes, services, the registry and the user/kernel boundary.

    1. 5.1The Windows API for AnalystsComing soon
    2. 5.2Processes, Threads and DLLsWhat processes, threads and DLLs look like to an observer — PEB, TEB, tokens, handles, process trees and module lists — and how to read them as evidence.
    3. 5.3The Registry, Services and Scheduled TasksComing soon
    4. 5.4Mutexes, Events and Inter-Process CommunicationComing soon
    5. 5.5User Mode, Kernel Mode and the Native APIComing soon
  2. Module 07 · 6 lessons

    Malware Behaviours

    What malware actually does and how each behaviour looks in code and telemetry — persistence, command and control, credential theft, injection and stealth.

    1. 7.1Loaders, Droppers and DownloadersComing soon
    2. 7.2Persistence MechanismsComing soon
    3. 7.3Command and ControlComing soon
    4. 7.4Credential Theft and KeyloggingComing soon
    5. 7.5Understanding Process InjectionComing soon
    6. 7.6Hooking and User-Mode RootkitsComing soon