• $890 or 6 monthly payments of $150

Malware Analysis and Development

  • Course
  • 110 Lessons
  • Includes 2 private spaces
  • Discord access

Learn advanced analysis techniques from real-world malware and harness this knowledge to craft your own malware, understanding attacker strategies. Empower yourself with both defensive and offensive cybersecurity skills.

Includes 2 private spaces

  • Malware & Security Research
  • Windows Internals & Programming

Read more about the instructors, course contents and special pricing:

Contents

Introduction

00-Introduction
Preview
MalwareAnalysisAndDevelopmentLabs.pdf
MalwareAnalysisAndDevelopment.pdf
Labs.zip
Demos.zip
Malware Samples.zip
Malware Samples Zip Password

Windows Internals Overview

1-Processes
Preview
2-Task Manager
3-Process Explorer
Preview
4-Virtual Memory
5-Threads
6-System Architecture
7-APIs
8-Objects and Handles
9-Labs Intro

Windows Application Development Fundamentals

1-Application Development Fundamentals
2-Working with Strings
3-System Information
4-Working with Handles
Preview
5-Sharing Objects by Name
6-Duplicating Handles
7-Object Names and Sessions
8-Sessions
9-Private Object Namespace

Processes, Memory and Threads

1-Process Creation
2-The CreateProcess API
3-Process Termination
4-Labs Solution Walkthrough
5-DllMain
Preview
6-Process and Thread Attributes
7-Process Enumeration
8-PEB and Other Details
9-Process Memory
10-Reserving and Committing Memory
11-Heaps
12-Threads Basics
13-Creating Threads
14-Odds and Ends

Dynamic Link Libraries

1-Building DLLs
2-Consuming DLLs
3-Reducing Dependencies
4-DLL Injection with a Remote Thread
5-DLL Injection with an APC
6-Odds and Ends

x86/x64 Fundamentals

1-Operating Modes
2-Assembling with Visual Studio
3-x86/x64 Basics
4-Operands and Address Modes
5-Fundamental Instructions
6-Calling External Functions
7-Calling Conventions
8-Bitwise Operations
9-Branch Instructions
10-The Stack
11-Shellcode
12-Injecting Shellcode
13-Odds and Ends

.NET Fundamentals

.NET Fundamentals

COM Fundamentals

1-COM Basics
2-COM Concepts, Clients and Servers
3-Creating and Using a COM Object
4-Smart Pointers
5-OLE/COM Object Viewer
6-COM Activation in Detail
7-CoCreateInstance in Detail
8-Out of Process Servers
9-COM Callbacks and Implementations

The Native API

1-Native API Basics
2-Object Manager and Native APIs
3-Registry APIs
4-Enumerating Processes and Handles

Introduction to Malware Analysis and Lab Setup

1 - The Importance of Understanding and Dissecting TTPs
2 - Introduction to Malware Analysis
3 - Understanding AV-EDR Vendor Detection Names
4 - Installing Flare-VM
5 - PE 101 - Part 1
6 - PE 101 - Part 2
7 - Strings
8 - Packing Detection - Part 1
Preview
9 - Packing Detection - Part 2
10 - Packing Detection - Part 3
11 - Detecting Malicious Functionality

Reverse Engineering .NET, VBA and Shellcode Malware

1 - Introduction to the SolarWinds Sunburst Attack
2 - Sunburst Backdoor Initial Analysis
Preview
3 - Sunburst Backdoor Backtracking (Function Call Tree Analysis)
4 - Sunburst Backdoor Reverse Engineering - Part 1
5 - Sunburst Backdoor Reverse Engineering - Part 2
6 - Sunburst Backdoor Reverse Engineering - Part 3
7 - Sunburst Backdoor Reverse Engineering - Part 4
8 - Sunburst Backdoor Reverse Engineering - Part 5
9 - VBA Macro Shellcode Analysis - Part 1
10 - VBA Macro Shellcode Analysis - Part 2
11 - VBA Macro Shellcode Analysis - Part 3

Reverse Engineering C/C++ Malware

1 - DarkSide Ransomware Initial Analysis
2 - Runtime Code Unpacking - Part 1
3 - Runtime Code Unpacking - Part 2
4 - Runtime Code Unpacking - Part 3
5 - Dynamic API Resolve
6 - Rebuilding the IAT (Import Address Table)
Preview
7 - DarkSide Ransomware TTPs Dissection - Part 1
8 - DarkSide Ransomware TTPs Dissection - Part 2

Malware Development

1-Minimal Executables
2-DarkSide Malware Techniques
3-Simple Memory Sharing
4-Memory Mapped Files
5-Payload in Resources
6-More Techniques

Bonus Content

One Electron to Rule Them All
For serious people only - MAoS - Malware Analysis on Steroids
Preview

Exclusive for TrainSec students, 20% discount:

Ever wanted to work with Threat.Zone? The time is now!

20% off for Malware analyst professional students.

With features like MemProcFS for analyzing memory dumps, CDR for sanitizing files, and CSI tools for digital forensics, Threat.Zone provides a powerful environment for malware analysis and security investigations.