
Malware Analysis Course
Master the full malware analysis pipeline — from setting up an isolated lab to reverse-engineering advanced threats. This course takes you through static analysis, dynamic execution, debugging, and detection engineering with hands-on, real-world samples. Build the technical depth that security teams rely on to identify, understand, and stop modern malware.
What you will learn:
You will learn how to safely execute and monitor malware in a controlled lab environment, inspect binaries using static and dynamic techniques, and read disassembled x86/x64 assembly to understand malicious logic. The course covers obfuscation, anti-debugging, and packing techniques used by real-world threats, along with methods to defeat them. You will analyse advanced malware families including ransomware, rootkits, and process injection tools. Finally, you will produce actionable threat intelligence by writing YARA rules, Sigma detections, and structured malware reports that defenders can deploy immediately.
How you study in practice Malware Analysis Course
How you practise Malware Analysis Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.
Course content
8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Malware and Analysis
Foundations of Malware and Analysis
Lesson 1 • Legal and Ethical Responsibilities
Outlines responsible disclosure, data handling obligations, and ethical boundaries for analysts. Frames professional conduct expected throughout the course.
Lesson 2 • The Malware Analysis Workflow
Introduces the triage-to-report pipeline analysts follow on every sample. Connects static, dynamic, and code analysis phases into a unified process.
Lesson 3 • Building a Safe Analysis Lab
Teaches isolation techniques using virtual machines and network controls to prevent sample escape. Directly enables hands-on work in all subsequent chapters.
Lesson 4 • Malware Classification and Taxonomy
Covers viruses, worms, trojans, ransomware, spyware, and rootkits by behaviour and payload. Provides the classification framework used throughout the course.
Chapter 2HideHide detailsSee detailsStatic Analysis Fundamentals
Static Analysis Fundamentals
Lesson 1 • Antivirus and Threat Intel Integration
Demonstrates submitting samples to multi-engine scanners and querying threat intelligence platforms. Contextualises static findings within known threat landscapes.
Lesson 2 • Entropy and Packing Detection
Uses entropy measurement to identify packed or encrypted sections within binaries. Prepares analysts to unpack samples before deeper analysis.
Lesson 3 • PE Format Deep Dive
Analyses the Portable Executable structure including headers, sections, and import tables. Understanding PE layout is essential for detecting packing and injection.
Lesson 4 • String Extraction and Analysis
Covers ASCII and Unicode string extraction to surface URLs, registry keys, and embedded commands. Strings often reveal malware intent before any execution.
Lesson 5 • File Identification and Hashing
Teaches format identification via magic bytes and cryptographic hashing for sample tracking. Establishes the first step of every static analysis workflow.
Chapter 3HideHide detailsSee detailsDynamic Analysis Fundamentals
Dynamic Analysis Fundamentals
Lesson 1 • Network Traffic Capture and Analysis
Covers packet capture, protocol dissection, and DNS query logging during malware execution. Network artefacts reveal command-and-control infrastructure and data exfiltration.
Lesson 2 • Process and System Monitoring
Teaches real-time observation of process creation, file writes, and registry changes during execution. Forms the behavioural baseline for every dynamic analysis session.
Lesson 3 • Memory Artifact Collection
Teaches capturing full memory dumps and process memory during live execution for later analysis. Memory artefacts expose injected code and in-memory-only payloads.
Lesson 4 • Automated Sandbox Analysis
Introduces automated sandboxes that generate behavioural reports without manual instrumentation. Analysts learn to interpret sandbox output and identify evasion artefacts.
Lesson 5 • Behavioural Indicator Documentation
Structures the process of recording, tagging, and prioritising behavioural indicators from dynamic runs. Produces actionable threat intelligence for detection engineering.
Chapter 4HideHide detailsSee detailsDisassembly and Code Analysis
Disassembly and Code Analysis
Lesson 1 • Disassembler Workflow and Navigation
Teaches loading binaries, navigating functions, and annotating code in a professional disassembler. Efficient navigation directly accelerates analysis throughput.
Lesson 2 • Analysing Malicious Algorithms
Focuses on custom encryption, encoding routines, and hashing functions embedded in malware. Decoding these algorithms is critical for extracting configuration data.
Lesson 3 • Control Flow Graph Interpretation
Uses control flow graphs to understand complex branching, exception handling, and obfuscated paths. CFG analysis reveals logic that linear reading obscures.
Lesson 4 • Recognising Common Code Constructs
Identifies loops, conditionals, switch statements, and API call patterns in disassembled code. Pattern recognition reduces time spent on routine code structures.
Lesson 5 • x86 and x64 Assembly Primer
Covers registers, calling conventions, stack frames, and common instruction patterns for both architectures. Provides the assembly literacy required for all disassembly work.
Chapter 5HideHide detailsSee detailsDebugging and Interactive Analysis
Debugging and Interactive Analysis
Lesson 1 • Scripting and Automating Debug Sessions
Teaches writing debugger scripts to automate repetitive tasks such as logging API calls and patching checks. Automation dramatically increases analysis speed on large sample sets.
Lesson 2 • Debugger Fundamentals and Setup
Covers breakpoint types, stepping modes, and register inspection in a user-mode debugger. Establishes the interactive analysis skills built upon in every subsequent section.
Lesson 3 • Kernel-Mode Debugging Basics
Introduces two-machine kernel debugging to analyse drivers, rootkits, and kernel-level payloads. Extends debugging skills from user mode into privileged execution contexts.
Lesson 4 • Bypassing Anti-Debugging Techniques
Identifies and neutralises common anti-debugging checks such as timing attacks and debugger flag tests. Defeating these checks is prerequisite to analysing protected malware.
Lesson 5 • Unpacking Malware at Runtime
Uses debugger-assisted execution to reach the original entry point of packed samples and dump clean code. Runtime unpacking unlocks samples that resist static analysis.
Chapter 6HideHide detailsSee detailsObfuscation, Evasion, and Unpacking
Obfuscation, Evasion, and Unpacking
Lesson 1 • Anti-VM and Anti-Sandbox Evasion
Covers artefact-based and behaviour-based checks malware uses to detect virtual environments. Analysts learn to spoof or remove these artefacts to force full execution.
Lesson 2 • Packer Internals and Custom Loaders
Dissects packer stub logic, self-modifying code, and custom loader routines at the assembly level. Deep packer knowledge enables unpacking without relying on known signatures.
Lesson 3 • Code Obfuscation Techniques
Examines junk code insertion, instruction substitution, and dead code patterns used to hinder analysis. Recognising these patterns prevents wasted time on irrelevant code.
Lesson 4 • Defeating String and API Obfuscation
Targets runtime string decryption and dynamic API resolution techniques that hide malware capabilities. Recovering strings and API names restores analytical visibility.
Lesson 5 • Virtualisation-Based Obfuscation
Analyses bytecode-based virtual machine protectors that translate native code into custom instruction sets. Students learn to map virtual opcodes back to original semantics.
Chapter 7HideHide detailsSee detailsAdvanced Malware Techniques and Families
Advanced Malware Techniques and Families
Lesson 1 • Command-and-Control Protocols
Reverse-engineers HTTP, DNS, and custom binary C2 protocols to understand attacker communication. Protocol analysis enables network detection rule creation.
Lesson 2 • Process Injection and Hollowing
Covers DLL injection, process hollowing, reflective loading, and thread hijacking at the code level. These techniques are central to most advanced malware and APT tooling.
Lesson 3 • Ransomware Internals
Dissects file enumeration, encryption key management, and ransom note delivery in ransomware samples. Understanding internals supports decryption tool development and recovery.
Lesson 4 • Rootkit and Stealth Techniques
Analyses DKOM, hook-based hiding, and filter driver techniques used by kernel-level rootkits. Stealth analysis requires combining kernel debugging with memory forensics.
Lesson 5 • Persistence Mechanisms
Analyses registry run keys, scheduled tasks, service installation, and bootkit persistence methods. Identifying persistence is essential for complete incident remediation.
Chapter 8HideHide detailsSee detailsThreat Intelligence and Detection Engineering
Threat Intelligence and Detection Engineering
Lesson 1 • Sigma and Network Detection Rules
Covers Sigma rule authoring for log-based detection and Suricata rules for network traffic alerting. Bridges malware behaviour to SIEM and IDS deployment.
Lesson 2 • Malware Attribution and Clustering
Uses code reuse, infrastructure overlap, and TTP similarity to cluster samples and attribute campaigns. Attribution supports strategic threat intelligence reporting.
Lesson 3 • YARA Rule Development
Teaches writing, testing, and optimising YARA rules targeting unique byte patterns and string clusters. YARA rules are the primary static detection artefact produced by analysts.
Lesson 4 • Indicator Extraction and Enrichment
Systematically extracts network, host, and behavioural indicators and enriches them with threat context. Enriched indicators form the foundation of all detection and hunting work.
Lesson 5 • Threat Intelligence Report Writing
Structures technical and executive-level malware reports with findings, impact, and recommendations. Clear reporting ensures analysis value reaches decision-makers and defenders.
Your valid completion certificate
This course is for you:
SOC Analyst: wants to move beyond alert triage into deeper threat investigation.
Incident Responder: needs to understand malware behavior during active investigations.
Penetration Tester: seeks to understand offensive tools from a defender's perspective.
Computer Science Graduate: ready to specialize in a high-demand cybersecurity discipline.
IT Security Engineer: looking to add reverse engineering skills to their defensive toolkit.
Career Changer: transitioning into cybersecurity from a software development background.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in South Africa?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















