Advanced
Advanced Malware Code Analysis
Advanced malware code analysis is what you reach for when behavioural analysis runs out. The sample refuses to run, the loader unpacks in memory only, and the answer exists solely in the code.
Twelve weeks covers manual unpacking, anti-analysis defeat, cryptographic routine identification, configuration extraction and kernel components, working on families that were built specifically to resist people like you.
- Duration
- 12 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Reverse Engineering Malware
- Class size
- Capped at 12 learners

What you will be able to do
- Work through large stripped binaries without losing your place
- Unpack custom and multi-stage loaders manually and rebuild imports
- Defeat anti-debugging, anti-virtual machine and timing based checks
- Read obfuscated control flow and recover the logic underneath
- Identify standard and modified cryptographic routines in compiled code
- Build a configuration extractor that survives the next family update
- Analyse kernel drivers and rootkit components safely
- Write a capability assessment where each claim points to specific code
Course outline
6 modules
- Working through large binaries efficiently
- Recovering structures, classes and virtual calls
- Identifying compilers, runtimes and statically linked libraries
- Scripting the disassembler for repeated work
- Tracking a family across successive versions
What you need before you start
- Completion of Reverse Engineering Malware or equivalent daily experience
- Fluent reading of x86 and x64 assembly
- Scripting ability in Python for disassembler and automation work
- A machine with 16 GB of RAM and virtualisation support
Who this course is for
- Malware analysts working on samples that resist normal analysis
- Reverse engineers supporting intelligence and detection teams
- Detection engineers who write rules from code level features
- Responders facing targeted implants rather than commodity malware
- Analysts building automated unpacking and extraction tooling
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



