Reverse Engineering & Malware Analysis - Intermediate Level

An Intermediate Level Course on Reverse Engineering and Analyzing Malware

   Watch Promo

What you'll learn

  • Types of Malware and Terminologies
  • Static Analysis
  • Dynamic Analysis
  • Assembly Language Refresher and Malicious APIs
  • API Hooking, Process Hijacking, Dumping Memory
  • Identifying Standard and Custom Packers
  • Unpacking Packed Malware
  • Enumerating Breakpoints and Memory Tracing
  • Hooking VirtualProtect, VirtualAlloc, GetProcAddress, CreateProcessInternalW and other common API's
  • Using Scylla Plugin to Dump Memory, Fixing IAT Tables
  • Using Delphi Interactive Reconstructor
  • Dumping Memory from Memory Viewer, Process Hacker and Memory Maps
  • API Enumeration Count Trick To Know When to Dump
  • Self-Injection and Remote Thread Injection
  • Fixing Section Alignments, Unmapping and Re-Basing Dumped Files
  • and more...

Requirements

  • Windows PC with Virtual Machine and Flare-VM Installed
  • Some basics in malware analysis or software reverse engineering.

Description

If you already have some basic reverse engineering and malware analysis knowledge and wish to go further, then this course is for you. I will take you from basic to intermediate level in reverse engineering and analyzing malware. You will learn using plenty of practical walk-throughs. The focus of this course will be on how to unpack malware. Most modern malware are packed in order to defeat analysis. Hence, this Intermediate Level Course provides the required knowledge and skills to unpack malware. All the needed tools will be introduced and explained. By the end of this course, you will have the intermediate level skill in malware analysis under your belt to further your studies in this field. Even if you do not intend to take up malware analysis as a career, still the knowledge and skills gained in reverse engineering and analysis would be beneficial to you to reverse software as well.

Everything is highly practical. No boring theory or lectures. More like walk-throughs which you can replicate and follow along. We will focus on API Hooking and Memory Analysis and Tracing to determine where and when to dump memory after a malware has unpacked its payload into memory. In this course, we will be using Oracle Virtual Machine installed with Flare-VM. Take note that all software used in this course are free.

Topics include:

  1. Types of Malware and Terminologies
  2. Dynamic and Static Analysis
  3. Assembly Language Refresher and Malicious APIs
  4. API Hooking, Process Hijacking, Dumping Memory
  5. Fixing Section Alignments, Un-mapping and Re-Basing Dumped Files
  6. Enumerating Breakpoints and Memory Tracing
  7. Hooking VirtualProtect, VirtualAlloc, GetProcAddress, CreateProcessInternalW and other common API's
  8. Using Scylla Plugin to Dump Memory
  9. Using Delphi Interactive Reconstructor
  10. Dumping Memory from Memory Viewer, Process Hacker and Memory Maps
  11. API Enumeration Count Trick To Know When to Dump
  12. Self-Injection and Remote Thread Injection
  13. and more...

This course is suitable for:

  • Students who has already done a basic level malware analysis course
  • Hackers looking for additional tools and techniques to reverse software
  • Reverse Engineers who want to venture into malware analysis

The prerequisites:

  • Some basics in malware analysis or software reverse engineering.
  • Windows PC with Virtual Machine and Flare-VM Installed.

Note:

If you do not have the basics of malware analysis, it is recommended to take my earlier course first, which is entitled:

Reverse Engineering & Malware Analysis Fundamentals

Go ahead and enroll now. I will see you inside!

Who this course is for:

  • Students who has already done a basic level malware analysis or reverse engineering course
  • Hackers looking for additional tools and techniques to reverse software
  • Reverse Engineers who want to venture into malware analysis


Your Instructor


Paul Chin
Paul Chin

I am a semi-retired college lecturer with more than 20 years experience in teaching computing and information technology. My interests range from reversing, coding to graphics design, apps, games development, music, health, spirituality and well-being. In my spare time, I also play the piano and keyboard. I enjoy teaching face-to-face and online and also love educating and inspiring others to succeed and live the life of their dreams.


Join Today & Get Access To This Course & Every Resource You Need Grow Your Cyber Skills & Advance Your Career. Beginner & Expert Training.

Course Curriculum


  Introduction
Available in days
days after you enroll
  Types of Malware and Malware Analysis Terminologies
Available in days
days after you enroll
  Assembly Language Refresher and Malicious APIs
Available in days
days after you enroll
  Resources For Further Study
Available in days
days after you enroll

Frequently Asked Questions


When does the course start and finish?
The course starts now and never ends! It is a completely self-paced online course - you decide when you start and when you finish.
How long do I have access to the course?
How does lifetime access sound? After enrolling, you have unlimited access to this course for as long as you like - across any and all devices you own.
What if I am unhappy with the course?
We would never want you to be unhappy! If you are unsatisfied with your purchase, contact us in the first 30 days and we will give you a full refund.

Become A Member And Unlock Unlimited Access To This Course Plus Over 30,000+ Top Cyber Security Classes, Virtual Labs, Practice Tests, And Exam Simulations.

Designed To Help You Expand Your Skill Set And Propel Your Career Forward. Whether You're Just Starting Out Or You're An Industry Expert, There's Something Here For Everyone. Let's Grow Together!