Malware Development and Reverse Engineering 1 : The Basics

Basic Programming Skills To Better Understand Reverse Engineering, Malware Analysis and Penetration Testing

   Watch Promo

What you'll learn

  • Basic Programming for Malware Analysis
  • Basic Programming Knowledge for Reverse Engineering
  • Creating and Compiling EXE and DLLs
  • Creating Windows Shellcode Using Metasploit on Kali Linux
  • Analyzing memory of a running malware
  • Injecting Shellcode into Running Processes
  • Creating Remote Thread
  • Encryption of Payloads and Function Call String Parameters
  • Hiding Shellcode Payloads in Executable Files
  • Obfuscating Function Calls
  • Malware Stealth Strategies
  • Encoding of Payloads
  • Trojan Development Life Cycle
  • How Anti Virus Works Under the Hood
  • Using Yara to Study Malware Signatures
  • Anti Virus Evasion Techniques
  • Dynamic Runtime API Loading
  • Windows API used in Malware

Requirements

  • Windows PC
  • Basic C Language
  • Basic Linux commands

Description

Many malware analysts perform reverse engineering on malware without knowing the why’s. They only know the how's. To fill that knowledge gap, I have created this course.

You will learn first-hand from a Malware Developers’ perspective what windows API functions are commonly used in malware and finally understand why you need to trace them when reversing malware.

Learning Methodology:

  1. Build programs that simulate Windows Trojans and Reverse Engineer them.
  2. This will make you a better Reverse Engineer and Malware Analyst and also Penetration Tester.
  3. The best way to understand malware is to be a Malware Developer.

Features:

  • Every topic will contain two parts: programming and reversing.
  • In the programming parts we will be writing programs that simulate trojan behavior by using API functions typically found in malware.
  • Then, in the reversing part, we take the programs that we wrote and perform reverse engineering on it
  • In this way, you will, for the first time, really understand why malware analyst do what they do when reversing a piece of malware

What you will learn:

  • How to compile and build executables and dynamic link libraries (DLL)
  • Windows API used in Malware
  • Creating shellcode using Metasploit on Kali Linux
  • Hiding shellcode payload in executable files
  • How to analyze and inspect memory of a running malware
  • Injecting Shellcode into running processes
  • Creating Remote Threads
  • Encryption of Payloads and Function Call String Parameters
  • Obfuscation of Function Calls
  • Malware Stealth Strategies
  • Encoding of Payloads
  • Trojan Development Life Cycle
  • How Anti Virus works under the hood
  • Using Yara to study malware signatures
  • Anti Virus Evasion Techniques
  • Dynamic Runtime API Loading
  • and more

We will be using free tools in this course, including Oracle Virtual Box and Flare-VM and the Community Edition of Microsoft Visual Studio 2019 C++. We will also install Kali Linux in the Virtual Box for learning how to use Metasploit to generate windows shellcode. Everything is highly practical. No boring theory or lectures. More like walk-throughs which you can replicate and follow along.

By the end of this course, you will have the basic skills to better understand how Malware works from the programmers' point of view. This knowledge and skills are suitable for those aspiring to be Red Teamers.

Also, having practical knowledge of malware development will give you a better understanding of how to reverse engineer malware. For example, when reversing and analyzing a trojan, we usually put breakpoints of dangerous API functions calls - but don't know why we do it. Now, in this course, I will show you the reasons for it. By the end of this course, you would have gained a solid foundation for understanding why and how malware reverse engineering works.

Suitable for:

  • Reverse Engineering and Malware Analysis Students
  • Programmers who want to know how Malware is created
  • Students planning on entering Malware Analysis and Reverse Engineering, or Penetration Testers as a Career Path
  • Penetration Testers and Ethical Hackers

Prerequisite:

  • Windows PC
  • Basic C Language
  • Basic Linux commands

Who this course is for:

  • Reverse Engineering and Malware Analysis Students
  • Programmers who want to know how Malware is created
  • Students planning on entering Malware Analysis and Reverse Engineering or Penetration Testers as a Career Path
  • Penetration Testers and Ethical Hacker


Your Instructor


Paul Chin
Paul Chin

I am a semi-retired college lecturer with more than 20 years experience in teaching computing and information technology. My interests range from reversing, coding to graphics design, apps, games development, music, health, spirituality and well-being. In my spare time, I also play the piano and keyboard. I enjoy teaching face-to-face and online and also love educating and inspiring others to succeed and live the life of their dreams.


Join Today & Get Access To This Course & Every Resource You Need Grow Your Cyber Skills & Advance Your Career. Beginner & Expert Training.

Course Curriculum


  Training Overview
Available in days
days after you enroll
  Section 1 : Introduction
Available in days
days after you enroll
  Section 3 : Building EXE and DLL and Examining PE Structure
Available in days
days after you enroll
  Section 5 : Generating Shellcodes Using Metasploit in Kali Linux
Available in days
days after you enroll
  Section 6 : Embedding Shellcode Payload in .RSRC Section and Analyzing with xdbg
Available in days
days after you enroll
  Section 7 : Testing Unpacked Dumped Shellcode Payload Using Hexeditor and a C Program
Available in days
days after you enroll
  Section 8 : Base64 Encoding of Shellcode Payload
Available in days
days after you enroll
  Section 9 : Reverse Engineering Base64 Encoded Payloads
Available in days
days after you enroll
  Section 10 : XOR Encryption of Payload
Available in days
days after you enroll
  Section 11 : Reverse Engineering XOR Encryption
Available in days
days after you enroll
  Section 12 : AES Encryption of Payload
Available in days
days after you enroll
  Section 13 : Reverse Engineering AES Encryption Using CryptDecrypt
Available in days
days after you enroll
  Section 14 : Testing Shellcode Using Shellcode Runner
Available in days
days after you enroll
  Section 15 : Obfuscating Functions Using GetProcAddress and XOR Encryption
Available in days
days after you enroll
  Section 16 : Reverse Engineering Function Obfuscation
Available in days
days after you enroll
  Section 18 - Reverse Engineering Code Cave Trojans
Available in days
days after you enroll
  Section 20 : Detecting Process Injection and Reverse Engineering it
Available in days
days after you enroll
  Section 21 : Testing Process Injection Shellcode with ShellcodeRunnerInjected
Available in days
days after you enroll
  Section 23 : Detecting and Reverse Engineering DLL Injection
Available in days
days after you enroll
  Section 24 : Creating a Stealth Trojan
Available in days
days after you enroll
  Section 25 : Lab Project _ Creating a Trojan with Encrypted Payload and Injection Capability
Available in days
days after you enroll
  Section 28 : Bonus Lecture
Available in days
days after you enroll

Frequently Asked Questions


When does the course start and finish?
The course starts now and never ends! It is a completely self-paced online course - you decide when you start and when you finish.
How long do I have access to the course?
How does lifetime access sound? After enrolling, you have unlimited access to this course for as long as you like - across any and all devices you own.
What if I am unhappy with the course?
We would never want you to be unhappy! If you are unsatisfied with your purchase, contact us in the first 30 days and we will give you a full refund.

Become A Member And Unlock Unlimited Access To This Course Plus Over 30,000+ Top Cyber Security Classes, Virtual Labs, Practice Tests, And Exam Simulations.

Designed To Help You Expand Your Skill Set And Propel Your Career Forward. Whether You're Just Starting Out Or You're An Industry Expert, There's Something Here For Everyone. Let's Grow Together!