Core
Reverse Engineering Malware
Malware analysis training in Toronto begins with the question every responder faces: what does this sample actually do? You answer it by triage first, then behaviour, then code, using real Windows samples in an isolated lab.
Ten weeks builds the assembly, debugging and disassembly skills to unpack simple protections, recover command and control configuration, and write indicators and detection rules from what you find.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Advanced Incident Response and Threat Hunting
- Class size
- Capped at 12 learners

What you will be able to do
- Build and maintain an isolated lab where live samples can run safely
- Triage an unknown file and decide how deep analysis needs to go
- Record behaviour on file system, registry, process and network activity
- Read x86 and x64 assembly well enough to follow malicious logic
- Recognize Windows API patterns behind injection, persistence and theft
- Unpack straightforward packers and dump a working sample from memory
- Extract command and control configuration and indicators from a binary
- Write an analysis report and detection rules other teams can use
Course outline
6 modules
- Building an isolated analysis environment
- Handling live samples without infecting yourself
- Static triage: strings, imports, hashes and headers
- File formats and indicators of packing
- Deciding how much analysis a sample deserves
What you need before you start
- Incident response or forensics experience, ideally the advanced hunting course
- Understanding of Windows processes, memory and the file system
- Some programming exposure in any language
- A machine with 16 GB of RAM and virtualisation support for the lab
Who this course is for
- Incident responders who need to answer what a sample does
- Forensic analysts finding unknown binaries in casework
- Detection engineers writing rules from sample behaviour
- Threat intelligence analysts producing technical reporting
- SOC analysts moving toward malware analysis work
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



