Skip to content

> analyze --sample suspicious.exe --learn

Learn reverse engineering to take malware apart.

A guided learning path, a catalog of attacker techniques and the analyst counter-moves that defeat them — everything you need to understand a malicious binary and detect it.

56
Lessons
174
Techniques
44
Assembly entries
52
Glossary terms

// The learning path

Eleven modules, from the PE format and Windows internals to evasion, unpacking and automation. Follow them in order or dip into what you need.

  1. 014/4

    Foundations
    Why we reverse malware, how to do it safely, and what a binary actually is — from source code to a running process.
  2. 025/5

    Binary Formats
    The PE format in depth — headers, sections, imports, exports and resources — plus the ELF essentials for Linux malware.
  3. 036/6

    Static Triage
    Answering the first questions about a sample in minutes, without running it — and turning what you find into detections.
  4. 045/5

    Disassembly & Code Analysis
    How disassemblers recover code, how to read compiler output, and how control-flow and data-flow analysis guide you.
  5. 055/5

    Windows Internals for Analysts
    The Windows concepts malware leans on — the API and native API, processes, threads, DLLs, mutexes, services, the registry and the user/kernel boundary.
  6. 065/5

    Dynamic Analysis
    Running samples under observation — behavioural monitoring, network simulation, debugging, API tracing and memory dumping.
  7. 076/6

    Malware Behaviours
    What malware actually does and how each behaviour looks in code and telemetry — persistence, command and control, credential theft, injection and stealth.
  8. 085/5

    Encoding, Crypto & Signatures
    Recognising encodings and cryptography, extracting configurations, and turning what you decode into network and host signatures.
  9. 096/6

    Evasion & Unpacking
    Defeating the tricks that waste analysts' time — anti-disassembly, anti-debugging, sandbox detection and packing — by patching, hooking and unpacking.
  10. 104/4

    Beyond the EXE
    Malware that is not a native executable — shellcode, .NET assemblies, scripts and malicious documents — and the tools each one needs.
  11. 115/5

    Automated & Advanced Analysis
    Letting tools do the heavy lifting — instrumentation, emulation, taint analysis, symbolic execution and analysis pipelines.

// Category

Anti-Forensicintermediate
Disabling, reconfiguring, or flooding the Linux Audit daemon to blind the subsystem that would otherwise log an attacker's own syscalls, file access, and privilege changes.
linux
Credential Accessbeginner
Reading saved passwords and session cookies from a browser's local profile store by calling the same OS decryption API a legitimate password manager would use.
windowslinuxmacos
Living off the Landbeginner
A malicious DLL renamed to .cpl and invoked via control.exe or rundll32's Control_RunDLL export runs as a trusted 'control panel item'.
windows
Living off the Landintermediate
Attackers abuse the signed Volume Shadow Copy utility diskshadow.exe, whose scripting language includes an exec command, as an unexpected LOLBin.
windows
Code Injectionintermediate
An app's Mach-O binary resolves a dynamic library by a weak or relative path; placing a malicious dylib where the loader looks first runs attacker code with the host app's privileges.
macos
Anti-Forensicadvanced
Loading an eBPF program attached to kernel tracepoints or kprobes to hide processes, files, or network connections from userspace tools — a kernel-assisted rootkit that needs no loadable kernel module.
linux

Blog