Choose your language
Malware Analysis Course
More than 2 million students worldwide

Malware Analysis Course

Master the full malware analysis pipeline — from setting up an isolated lab to reverse-engineering advanced threats. This course takes you through static analysis, dynamic execution, debugging, and detection engineering with hands-on, real-world samples. Build the technical depth that security teams rely on to identify, understand, and stop modern malware.

Dedika for businesses

What you will learn:

You will learn how to safely execute and monitor malware in a controlled lab environment, inspect binaries using static and dynamic techniques, and read disassembled x86/x64 assembly to understand malicious logic. The course covers obfuscation, anti-debugging, and packing techniques used by real-world threats, along with methods to defeat them. You will analyse advanced malware families including ransomware, rootkits, and process injection tools. Finally, you will produce actionable threat intelligence by writing YARA rules, Sigma detections, and structured malware reports that defenders can deploy immediately.

How you study in practice Malware Analysis Course

How you practise Malware Analysis Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Malware and Analysis

  • Lesson 1 • Legal and Ethical Responsibilities

    Outlines responsible disclosure, data handling obligations, and ethical boundaries for analysts. Frames professional conduct expected throughout the course.

  • Lesson 2 • The Malware Analysis Workflow

    Introduces the triage-to-report pipeline analysts follow on every sample. Connects static, dynamic, and code analysis phases into a unified process.

  • Lesson 3 • Building a Safe Analysis Lab

    Teaches isolation techniques using virtual machines and network controls to prevent sample escape. Directly enables hands-on work in all subsequent chapters.

  • Lesson 4 • Malware Classification and Taxonomy

    Covers viruses, worms, trojans, ransomware, spyware, and rootkits by behaviour and payload. Provides the classification framework used throughout the course.

Chapter 2See details

Static Analysis Fundamentals

  • Lesson 1 • Antivirus and Threat Intel Integration

    Demonstrates submitting samples to multi-engine scanners and querying threat intelligence platforms. Contextualises static findings within known threat landscapes.

  • Lesson 2 • Entropy and Packing Detection

    Uses entropy measurement to identify packed or encrypted sections within binaries. Prepares analysts to unpack samples before deeper analysis.

  • Lesson 3 • PE Format Deep Dive

    Analyses the Portable Executable structure including headers, sections, and import tables. Understanding PE layout is essential for detecting packing and injection.

  • Lesson 4 • String Extraction and Analysis

    Covers ASCII and Unicode string extraction to surface URLs, registry keys, and embedded commands. Strings often reveal malware intent before any execution.

  • Lesson 5 • File Identification and Hashing

    Teaches format identification via magic bytes and cryptographic hashing for sample tracking. Establishes the first step of every static analysis workflow.

Chapter 3See details

Dynamic Analysis Fundamentals

  • Lesson 1 • Network Traffic Capture and Analysis

    Covers packet capture, protocol dissection, and DNS query logging during malware execution. Network artefacts reveal command-and-control infrastructure and data exfiltration.

  • Lesson 2 • Process and System Monitoring

    Teaches real-time observation of process creation, file writes, and registry changes during execution. Forms the behavioural baseline for every dynamic analysis session.

  • Lesson 3 • Memory Artifact Collection

    Teaches capturing full memory dumps and process memory during live execution for later analysis. Memory artefacts expose injected code and in-memory-only payloads.

  • Lesson 4 • Automated Sandbox Analysis

    Introduces automated sandboxes that generate behavioural reports without manual instrumentation. Analysts learn to interpret sandbox output and identify evasion artefacts.

  • Lesson 5 • Behavioural Indicator Documentation

    Structures the process of recording, tagging, and prioritising behavioural indicators from dynamic runs. Produces actionable threat intelligence for detection engineering.

Chapter 4See details

Disassembly and Code Analysis

  • Lesson 1 • Disassembler Workflow and Navigation

    Teaches loading binaries, navigating functions, and annotating code in a professional disassembler. Efficient navigation directly accelerates analysis throughput.

  • Lesson 2 • Analysing Malicious Algorithms

    Focuses on custom encryption, encoding routines, and hashing functions embedded in malware. Decoding these algorithms is critical for extracting configuration data.

  • Lesson 3 • Control Flow Graph Interpretation

    Uses control flow graphs to understand complex branching, exception handling, and obfuscated paths. CFG analysis reveals logic that linear reading obscures.

  • Lesson 4 • Recognising Common Code Constructs

    Identifies loops, conditionals, switch statements, and API call patterns in disassembled code. Pattern recognition reduces time spent on routine code structures.

  • Lesson 5 • x86 and x64 Assembly Primer

    Covers registers, calling conventions, stack frames, and common instruction patterns for both architectures. Provides the assembly literacy required for all disassembly work.

Chapter 5See details

Debugging and Interactive Analysis

  • Lesson 1 • Scripting and Automating Debug Sessions

    Teaches writing debugger scripts to automate repetitive tasks such as logging API calls and patching checks. Automation dramatically increases analysis speed on large sample sets.

  • Lesson 2 • Debugger Fundamentals and Setup

    Covers breakpoint types, stepping modes, and register inspection in a user-mode debugger. Establishes the interactive analysis skills built upon in every subsequent section.

  • Lesson 3 • Kernel-Mode Debugging Basics

    Introduces two-machine kernel debugging to analyse drivers, rootkits, and kernel-level payloads. Extends debugging skills from user mode into privileged execution contexts.

  • Lesson 4 • Bypassing Anti-Debugging Techniques

    Identifies and neutralises common anti-debugging checks such as timing attacks and debugger flag tests. Defeating these checks is prerequisite to analysing protected malware.

  • Lesson 5 • Unpacking Malware at Runtime

    Uses debugger-assisted execution to reach the original entry point of packed samples and dump clean code. Runtime unpacking unlocks samples that resist static analysis.

Chapter 6See details

Obfuscation, Evasion, and Unpacking

  • Lesson 1 • Anti-VM and Anti-Sandbox Evasion

    Covers artefact-based and behaviour-based checks malware uses to detect virtual environments. Analysts learn to spoof or remove these artefacts to force full execution.

  • Lesson 2 • Packer Internals and Custom Loaders

    Dissects packer stub logic, self-modifying code, and custom loader routines at the assembly level. Deep packer knowledge enables unpacking without relying on known signatures.

  • Lesson 3 • Code Obfuscation Techniques

    Examines junk code insertion, instruction substitution, and dead code patterns used to hinder analysis. Recognising these patterns prevents wasted time on irrelevant code.

  • Lesson 4 • Defeating String and API Obfuscation

    Targets runtime string decryption and dynamic API resolution techniques that hide malware capabilities. Recovering strings and API names restores analytical visibility.

  • Lesson 5 • Virtualisation-Based Obfuscation

    Analyses bytecode-based virtual machine protectors that translate native code into custom instruction sets. Students learn to map virtual opcodes back to original semantics.

Chapter 7See details

Advanced Malware Techniques and Families

  • Lesson 1 • Command-and-Control Protocols

    Reverse-engineers HTTP, DNS, and custom binary C2 protocols to understand attacker communication. Protocol analysis enables network detection rule creation.

  • Lesson 2 • Process Injection and Hollowing

    Covers DLL injection, process hollowing, reflective loading, and thread hijacking at the code level. These techniques are central to most advanced malware and APT tooling.

  • Lesson 3 • Ransomware Internals

    Dissects file enumeration, encryption key management, and ransom note delivery in ransomware samples. Understanding internals supports decryption tool development and recovery.

  • Lesson 4 • Rootkit and Stealth Techniques

    Analyses DKOM, hook-based hiding, and filter driver techniques used by kernel-level rootkits. Stealth analysis requires combining kernel debugging with memory forensics.

  • Lesson 5 • Persistence Mechanisms

    Analyses registry run keys, scheduled tasks, service installation, and bootkit persistence methods. Identifying persistence is essential for complete incident remediation.

Chapter 8See details

Threat Intelligence and Detection Engineering

  • Lesson 1 • Sigma and Network Detection Rules

    Covers Sigma rule authoring for log-based detection and Suricata rules for network traffic alerting. Bridges malware behaviour to SIEM and IDS deployment.

  • Lesson 2 • Malware Attribution and Clustering

    Uses code reuse, infrastructure overlap, and TTP similarity to cluster samples and attribute campaigns. Attribution supports strategic threat intelligence reporting.

  • Lesson 3 • YARA Rule Development

    Teaches writing, testing, and optimising YARA rules targeting unique byte patterns and string clusters. YARA rules are the primary static detection artefact produced by analysts.

  • Lesson 4 • Indicator Extraction and Enrichment

    Systematically extracts network, host, and behavioural indicators and enriches them with threat context. Enriched indicators form the foundation of all detection and hunting work.

  • Lesson 5 • Threat Intelligence Report Writing

    Structures technical and executive-level malware reports with findings, impact, and recommendations. Clear reporting ensures analysis value reaches decision-makers and defenders.

Certification

Your valid completion certificate

This course is for you:

  • SOC Analyst: wants to move beyond alert triage into deeper threat investigation.

  • Incident Responder: needs to understand malware behavior during active investigations.

  • Penetration Tester: seeks to understand offensive tools from a defender's perspective.

  • Computer Science Graduate: ready to specialize in a high-demand cybersecurity discipline.

  • IT Security Engineer: looking to add reverse engineering skills to their defensive toolkit.

  • Career Changer: transitioning into cybersecurity from a software development background.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Dedika?

Is the certificate valid in South Africa?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course