All Modules MALWARE ANALYSIS

Malware Analysis · Complete Guide

Eight chapters covering malware analysis from first-pass triage through applied detection engineering: static and dynamic analysis techniques, unpacking and deobfuscation with a memory forensics tie-in, the persistence, process injection, and C2 tradecraft malware actually uses, YARA and Sigma rule writing, and the documented threat actor campaigns and evasion techniques that tie the whole module together. Built for SOC analysts and detection engineers who need to read what a sample is doing, not just what a sandbox report says about it.

8 CHAPTERS
~12 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
static analysis dynamic analysis PE format unpacking process injection C2 communication YARA / Sigma anti-analysis

ALL CHAPTERS

/
01
BEGINNER 25 min

Malware Analysis Foundations

Malware types and classification, building an isolated analysis lab safely, static vs. dynamic analysis at a glance, and the legal and handling basics every analyst needs before touching a live sample.

malware classification analysis lab static vs dynamic
02
INTERMEDIATE 40 min

Static Analysis Fundamentals

Hashing and fuzzy hashing, the PE file format, strings and import/export table analysis, packer and signature detection, and disassembly basics behind a first-pass triage.

PE format hashing strings analysis disassembly
03
INTERMEDIATE 35 min

Dynamic Analysis & Sandboxing

Sandbox tooling, process and API call monitoring, network traffic capture, and the behavioral indicators that static analysis alone can't surface.

sandboxing API monitoring network capture
04
INTERMEDIATE 35 min

Unpacking & Deobfuscation

Packer and crypter mechanics, manual unpacking and OEP identification, string and configuration deobfuscation, and where memory forensics picks up what disk-based analysis misses.

packers unpacking memory forensics
05
INTERMEDIATE 40 min

Malware Tradecraft: Persistence, Injection & C2

Persistence mechanisms, process injection techniques from classic DLL injection to reflective loading, and the beaconing patterns behind command-and-control communication.

persistence process injection C2 beaconing
06
INTERMEDIATE 40 min

Detection Engineering: YARA, Sigma & Behavioral Rules

Writing YARA rules from analysis output, Sigma rules for process and behavioral detection, and turning extracted IOCs into a detection pipeline mapped to ATT&CK.

YARA Sigma IOC extraction
07
ADVANCED 35 min

Malware Threat Actor Campaigns

Documented loader-to-ransomware ecosystems, commodity C2 frameworks repurposed by multiple actors, and the tradecraft patterns connecting widely reported malware campaigns.

ransomware loader ecosystems case studies
08
ADVANCED 40 min

Advanced Evasion & Anti-Analysis

Anti-VM and anti-debug techniques, AMSI and EDR evasion concepts, fileless and living-off-the-land malware, and the hardening controls that close out the module.

anti-VM EDR evasion fileless malware

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Basic OS concepts: what a process, thread, and the filesystem and registry actually are (Windows-focused content)
  • No prior reverse engineering experience required, Chapter 1 builds static and dynamic analysis concepts from scratch
  • General awareness of MITRE ATT&CK: what tactics and techniques are, how T-numbers work
  • Some exposure to YARA or Sigma helps for Chapter 6 but is not required going in

WHAT YOU WILL KNOW AFTER

  • How to classify malware by type and behavior, and how to build an isolated analysis lab safely
  • How to run first-pass static analysis: hashing, PE structure, strings, import tables, and packer detection
  • How to run dynamic analysis in a sandbox and extract behavioral indicators static analysis alone can't surface
  • How unpacking and deobfuscation work, and where memory forensics picks up what disk-based analysis misses
  • How persistence, process injection, and C2 beaconing actually work under the hood
  • How to write YARA and Sigma rules from analysis output and map extracted IOCs to ATT&CK coverage
  • How documented malware campaigns and modern evasion techniques tie the whole module's tradecraft together

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.