
Malware Analysis Course
Master the full malware analysis pipeline — from setting up an isolated lab to reverse-engineering advanced threats. This course takes you through static analysis, dynamic execution, debugging, and detection engineering with hands-on, real-world samples. Build the technical depth that security teams rely on to identify, understand, and stop modern malware.
What your team will master:
You will learn how to safely execute and monitor malware in a controlled lab environment, inspect binaries using static and dynamic techniques, and read disassembled x86/x64 assembly to understand malicious logic. The course covers obfuscation, anti-debugging, and packing techniques used by real-world threats, along with methods to defeat them. You will analyze advanced malware families including ransomware, rootkits, and process injection tools. Finally, you will produce actionable threat intelligence by writing YARA rules, Sigma detections, and structured malware reports that defenders can deploy immediately.
How your team studies in practice Malware Analysis Course
How your team practices Malware Analysis Course
Professionals from these companies study at Dedika









Course content
8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Malware and Analysis
Foundations of Malware and Analysis
Lesson 1 • Legal and Ethical Responsibilities
Outlines responsible disclosure, data handling obligations, and ethical boundaries for analysts. Frames professional conduct expected throughout the course.
Lesson 2 • The Malware Analysis Workflow
Introduces the triage-to-report pipeline analysts follow on every sample. Connects static, dynamic, and code analysis phases into a unified process.
Lesson 3 • Building a Safe Analysis Lab
Teaches isolation techniques using virtual machines and network controls to prevent sample escape. Directly enables hands-on work in all subsequent chapters.
Lesson 4 • Malware Classification and Taxonomy
Covers viruses, worms, trojans, ransomware, spyware, and rootkits by behavior and payload. Provides the classification framework used throughout the course.
Chapter 2HideHide detailsSee detailsStatic Analysis Fundamentals
Static Analysis Fundamentals
Lesson 1 • Antivirus and Threat Intel Integration
Demonstrates submitting samples to multi-engine scanners and querying threat intelligence platforms. Contextualizes static findings within known threat landscapes.
Lesson 2 • Entropy and Packing Detection
Uses entropy measurement to identify packed or encrypted sections within binaries. Prepares analysts to unpack samples before deeper analysis.
Lesson 3 • PE Format Deep Dive
Analyzes the Portable Executable structure including headers, sections, and import tables. Understanding PE layout is essential for detecting packing and injection.
Lesson 4 • String Extraction and Analysis
Covers ASCII and Unicode string extraction to surface URLs, registry keys, and embedded commands. Strings often reveal malware intent before any execution.
Lesson 5 • File Identification and Hashing
Teaches format identification via magic bytes and cryptographic hashing for sample tracking. Establishes the first step of every static analysis workflow.
Chapter 3HideHide detailsSee detailsDynamic Analysis Fundamentals
Dynamic Analysis Fundamentals
Lesson 1 • Network Traffic Capture and Analysis
Covers packet capture, protocol dissection, and DNS query logging during malware execution. Network artifacts reveal command-and-control infrastructure and data exfiltration.
Lesson 2 • Process and System Monitoring
Teaches real-time observation of process creation, file writes, and registry changes during execution. Forms the behavioral baseline for every dynamic analysis session.
Lesson 3 • Memory Artifact Collection
Teaches capturing full memory dumps and process memory during live execution for later analysis. Memory artifacts expose injected code and in-memory-only payloads.
Lesson 4 • Automated Sandbox Analysis
Introduces automated sandboxes that generate behavioral reports without manual instrumentation. Analysts learn to interpret sandbox output and identify evasion artifacts.
Lesson 5 • Behavioral Indicator Documentation
Structures the process of recording, tagging, and prioritizing behavioral indicators from dynamic runs. Produces actionable threat intelligence for detection engineering.
Chapter 4HideHide detailsSee detailsDisassembly and Code Analysis
Disassembly and Code Analysis
Lesson 1 • Disassembler Workflow and Navigation
Teaches loading binaries, navigating functions, and annotating code in a professional disassembler. Efficient navigation directly accelerates analysis throughput.
Lesson 2 • Analyzing Malicious Algorithms
Focuses on custom encryption, encoding routines, and hashing functions embedded in malware. Decoding these algorithms is critical for extracting configuration data.
Lesson 3 • Control Flow Graph Interpretation
Uses control flow graphs to understand complex branching, exception handling, and obfuscated paths. CFG analysis reveals logic that linear reading obscures.
Lesson 4 • Recognizing Common Code Constructs
Identifies loops, conditionals, switch statements, and API call patterns in disassembled code. Pattern recognition reduces time spent on routine code structures.
Lesson 5 • x86 and x64 Assembly Primer
Covers registers, calling conventions, stack frames, and common instruction patterns for both architectures. Provides the assembly literacy required for all disassembly work.
Chapter 5HideHide detailsSee detailsDebugging and Interactive Analysis
Debugging and Interactive Analysis
Lesson 1 • Scripting and Automating Debug Sessions
Teaches writing debugger scripts to automate repetitive tasks such as logging API calls and patching checks. Automation dramatically increases analysis speed on large sample sets.
Lesson 2 • Debugger Fundamentals and Setup
Covers breakpoint types, stepping modes, and register inspection in a user-mode debugger. Establishes the interactive analysis skills built upon in every subsequent section.
Lesson 3 • Kernel-Mode Debugging Basics
Introduces two-machine kernel debugging to analyze drivers, rootkits, and kernel-level payloads. Extends debugging skills from user mode into privileged execution contexts.
Lesson 4 • Bypassing Anti-Debugging Techniques
Identifies and neutralizes common anti-debugging checks such as timing attacks and debugger flag tests. Defeating these checks is prerequisite to analyzing protected malware.
Lesson 5 • Unpacking Malware at Runtime
Uses debugger-assisted execution to reach the original entry point of packed samples and dump clean code. Runtime unpacking unlocks samples that resist static analysis.
Chapter 6HideHide detailsSee detailsObfuscation, Evasion, and Unpacking
Obfuscation, Evasion, and Unpacking
Lesson 1 • Anti-VM and Anti-Sandbox Evasion
Covers artifact-based and behavior-based checks malware uses to detect virtual environments. Analysts learn to spoof or remove these artifacts to force full execution.
Lesson 2 • Packer Internals and Custom Loaders
Dissects packer stub logic, self-modifying code, and custom loader routines at the assembly level. Deep packer knowledge enables unpacking without relying on known signatures.
Lesson 3 • Code Obfuscation Techniques
Examines junk code insertion, instruction substitution, and dead code patterns used to hinder analysis. Recognizing these patterns prevents wasted time on irrelevant code.
Lesson 4 • Defeating String and API Obfuscation
Targets runtime string decryption and dynamic API resolution techniques that hide malware capabilities. Recovering strings and API names restores analytical visibility.
Lesson 5 • Virtualization-Based Obfuscation
Analyzes bytecode-based virtual machine protectors that translate native code into custom instruction sets. Students learn to map virtual opcodes back to original semantics.
Chapter 7HideHide detailsSee detailsAdvanced Malware Techniques and Families
Advanced Malware Techniques and Families
Lesson 1 • Command-and-Control Protocols
Reverse-engineers HTTP, DNS, and custom binary C2 protocols to understand attacker communication. Protocol analysis enables network detection rule creation.
Lesson 2 • Process Injection and Hollowing
Covers DLL injection, process hollowing, reflective loading, and thread hijacking at the code level. These techniques are central to most advanced malware and APT tooling.
Lesson 3 • Ransomware Internals
Dissects file enumeration, encryption key management, and ransom note delivery in ransomware samples. Understanding internals supports decryption tool development and recovery.
Lesson 4 • Rootkit and Stealth Techniques
Analyzes DKOM, hook-based hiding, and filter driver techniques used by kernel-level rootkits. Stealth analysis requires combining kernel debugging with memory forensics.
Lesson 5 • Persistence Mechanisms
Analyzes registry run keys, scheduled tasks, service installation, and bootkit persistence methods. Identifying persistence is essential for complete incident remediation.
Chapter 8HideHide detailsSee detailsThreat Intelligence and Detection Engineering
Threat Intelligence and Detection Engineering
Lesson 1 • Sigma and Network Detection Rules
Covers Sigma rule authoring for log-based detection and Suricata rules for network traffic alerting. Bridges malware behavior to SIEM and IDS deployment.
Lesson 2 • Malware Attribution and Clustering
Uses code reuse, infrastructure overlap, and TTP similarity to cluster samples and attribute campaigns. Attribution supports strategic threat intelligence reporting.
Lesson 3 • YARA Rule Development
Teaches writing, testing, and optimizing YARA rules targeting unique byte patterns and string clusters. YARA rules are the primary static detection artifact produced by analysts.
Lesson 4 • Indicator Extraction and Enrichment
Systematically extracts network, host, and behavioral indicators and enriches them with threat context. Enriched indicators form the foundation of all detection and hunting work.
Lesson 5 • Threat Intelligence Report Writing
Structures technical and executive-level malware reports with findings, impact, and recommendations. Clear reporting ensures analysis value reaches decision-makers and defenders.
Your valid completion certificate
This course is for you:
SOC Analyst: wants to move beyond alert triage into deeper threat investigation.
Incident Responder: needs to understand malware behavior during active investigations.
Penetration Tester: seeks to understand offensive tools from a defender's perspective.
Computer Science Graduate: ready to specialize in a high-demand cybersecurity discipline.
IT Security Engineer: looking to add reverse engineering skills to their defensive toolkit.
Career Changer: transitioning into cybersecurity from a software development background.
Related Courses
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course



















