Eight chapters covering malware analysis from first-pass triage through applied detection engineering: static and dynamic analysis techniques, unpacking and deobfuscation with a memory forensics tie-in, the persistence, process injection, and C2 tradecraft malware actually uses, YARA and Sigma rule writing, and the documented threat actor campaigns and evasion techniques that tie the whole module together. Built for SOC analysts and detection engineers who need to read what a sample is doing, not just what a sandbox report says about it.
No chapters match “”.
Malware types and classification, building an isolated analysis lab safely, static vs. dynamic analysis at a glance, and the legal and handling basics every analyst needs before touching a live sample.
Hashing and fuzzy hashing, the PE file format, strings and import/export table analysis, packer and signature detection, and disassembly basics behind a first-pass triage.
Sandbox tooling, process and API call monitoring, network traffic capture, and the behavioral indicators that static analysis alone can't surface.
Packer and crypter mechanics, manual unpacking and OEP identification, string and configuration deobfuscation, and where memory forensics picks up what disk-based analysis misses.
Persistence mechanisms, process injection techniques from classic DLL injection to reflective loading, and the beaconing patterns behind command-and-control communication.
Writing YARA rules from analysis output, Sigma rules for process and behavioral detection, and turning extracted IOCs into a detection pipeline mapped to ATT&CK.
Documented loader-to-ransomware ecosystems, commodity C2 frameworks repurposed by multiple actors, and the tradecraft patterns connecting widely reported malware campaigns.
Anti-VM and anti-debug techniques, AMSI and EDR evasion concepts, fileless and living-off-the-land malware, and the hardening controls that close out the module.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB. Score file hashes and C2 infrastructure pulled straight out of the static and dynamic analysis covered in Chapters 2 and 3.
Detection rule library across KQL, Sigma, and XQL. Pull ready-made behavioral detection logic for the injection and C2 patterns covered in Chapters 5 and 6.
Multi-artifact forensic parser. Extract and normalize the process, registry, and network artifacts a dynamic analysis run in Chapter 3 produces.
Visual pivot graph for investigations. Map the process-injection chains and C2 infrastructure relationships covered in Chapters 5 and 7.