Inside the Threat: A Training Course in Malware Analysis (U.S. Standards) (Online / Remote)
1Summary
Every piece of malware tells a story, if you know how to read it — where it came from, what it is trying to do, and how to stop it from doing it again. That reading process is a skill, not a guess, and it is exactly what separates a team that contains an infection quickly from one that spends days chasing symptoms. This Training Course from Arab British Fellowship Training Academy, aligned with U.S. standards such as NIST, teaches participants how to take malware apart and understand it methodically.
The course moves through the full analytical process: setting up a safe environment to run suspicious code, using static and dynamic analysis tools, and reverse-engineering samples to expose their behavior. Participants also learn how to extract indicators of compromise, analyze network traffic generated by malware, and turn findings into actionable reports that strengthen detection and response.
2Objectives and target group
Learning Outcomes
- Understand the major categories of malware and how they affect systems and networks.
- Apply malware analysis techniques aligned with NIST and other cybersecurity frameworks.
- Use industry-standard tools to analyze and reverse-engineer malicious software.
- Identify and dissect malware components to understand how they function.
- Develop strategies for detecting, preventing, and mitigating malware attacks.
- Apply malware analysis best practices within a real organizational workflow.
Who Should Attend?
- Information security professionals and cybersecurity analysts.
- Incident response teams and IT security officers.
- Malware researchers and digital forensics specialists.
- IT professionals and network administrators interested in malware detection.
- Anyone looking to build skills in malware analysis and cybersecurity.
3Course Content
Module 1: The Malware Landscape and Why It Keeps Evolving
- Common malware types: viruses, worms, trojans, ransomware, and more.
- How malware techniques have grown more sophisticated over time.
- The role of malware in modern cyberattacks.
Module 2: What Malware Actually Costs Organizations
- How malware affects systems, networks, and data.
- Real-world examples of malware attacks and their consequences.
- The economic and operational impact of infections.
Module 3: Standards and Frameworks Guiding Malware Analysis
- U.S. cybersecurity standards relevant to malware analysis: NIST, ISO 27001.
- Industry frameworks for detection and analysis.
- Why adhering to established standards matters during analysis and incident response.
Module 4: Setting Up a Safe Analysis Environment
- Benefits of virtual machines and sandboxes for malware analysis.
- Setting up a controlled, isolated environment.
- Best practices for preventing accidental infections during analysis.
Module 5: Static vs. Dynamic Analysis Tools
- Essential tools: disassemblers, debuggers, hex editors.
- Static analysis vs. dynamic analysis and when to use each.
- Sandboxing tools and virtual environments for dynamic analysis.
Module 6: Recognizing Malware Behavior
- Common execution patterns to watch for.
- Recognizing key indicators of compromise (IoCs).
- Monitoring and analyzing system behavior during execution.
Module 7: Disassembling and Reverse-Engineering Malware
- Disassembling code with tools like IDA Pro and Ghidra.
- Analyzing executable code to identify malware logic.
- Examining malware structure without executing it.
Module 8: Defeating Obfuscation and Anti-Debugging Tricks
- Common obfuscation methods used to evade detection.
- Detecting and bypassing anti-debugging techniques.
- Analyzing packed or encrypted malware.
Module 9: Extracting and Using Indicators of Compromise
- What IoCs are and why they matter.
- Extracting IoCs such as file hashes, IP addresses, and domain names.
- Turning extracted IoCs into reports and detection signatures.
Module 10: Running and Observing Malware Safely
- Setting up secure, isolated execution environments.
- Monitoring and recording malware behavior in real time.
- Tracking system changes, network activity, and affected files.
Module 11: Network Traffic Analysis and Memory Forensics
- Using tools like Wireshark to analyze malware-generated traffic.
- Recognizing command-and-control (C2) communication patterns.
- Using memory forensics tools like Volatility to detect in-memory malware.
Module 12: Advanced Persistence and Behavioral Reporting
- How malware maintains control over infected systems (rootkits, bootkits, firmware-based malware).
- Analyzing impact on system files and registry entries.
- Creating detailed behavioral reports, including hidden functionality and backdoors.
Module 13: From Detection to Incident Response
- Deploying endpoint detection and response (EDR) tools.
- Steps for containing, eradicating, and recovering from a malware incident.
- Coordinating with other cybersecurity teams during response.
Module 14: Reporting, Collaboration, and Organizational Best Practices
- Preparing clear, reliable reports for stakeholders and decision-makers.
- Coordinating with incident response teams to guide fast action.
- Best practices for reducing malware risk across the organization.