Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Advanced Malware Code Analysis

Advanced malware code analysis is what you reach for when behavioural analysis runs out. The sample refuses to run, the loader unpacks in memory only, and the answer exists solely in the code.

Twelve weeks covers manual unpacking, anti-analysis defeat, cryptographic routine identification, configuration extraction and kernel components, working on families that were built specifically to resist people like you.

Duration
12 weeks
Format
Live online, instructor-led
Prerequisites
Reverse Engineering Malware
Class size
Capped at 12 learners
Advanced Malware Code Analysis

What you will be able to do

  • Work through large stripped binaries without losing your place
  • Unpack custom and multi-stage loaders manually and rebuild imports
  • Defeat anti-debugging, anti-virtual machine and timing based checks
  • Read obfuscated control flow and recover the logic underneath
  • Identify standard and modified cryptographic routines in compiled code
  • Build a configuration extractor that survives the next family update
  • Analyse kernel drivers and rootkit components safely
  • Write a capability assessment where each claim points to specific code

Course outline

6 modules

  • Working through large binaries efficiently
  • Recovering structures, classes and virtual calls
  • Identifying compilers, runtimes and statically linked libraries
  • Scripting the disassembler for repeated work
  • Tracking a family across successive versions

What you need before you start

  • Completion of Reverse Engineering Malware or equivalent daily experience
  • Fluent reading of x86 and x64 assembly
  • Scripting ability in Python for disassembler and automation work
  • A machine with 16 GB of RAM and virtualisation support

Who this course is for

  • Malware analysts working on samples that resist normal analysis
  • Reverse engineers supporting intelligence and detection teams
  • Detection engineers who write rules from code level features
  • Responders facing targeted implants rather than commodity malware
  • Analysts building automated unpacking and extraction tooling

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.