Practical Malware Analysis & Software Reverse Engineering

Skill Level: Beginner to Intermediate
Track: Technical Focus
Duration: 3 Days, 19 to 21 November 2025

Program Overview

A comprehensive, training Practical Malware Analysis & Software Reverse Engineering that offers knowledge ranging from beginner to intermediate levels on becoming a better malware analyst, digital forensics, and incident responder by learning effective and powerful techniques to dissect malware and identify the ingredients used to develop malware in the Windows operating system.

Are you a blue team defender with some experience in malware analysis, but still rely on third-party services like VirusTotal for key decisions, only performing surface-level analysis yourself? Or maybe you’re just starting out as a malware analyst and want to understand more about how these malware infections operate? Or are you a penetration tester or red teamer looking to better understand how malware analyst work in order to improve the success of your attack simulations?

This training is designed to provide participants with essential knowledge and practical skills in malware analysis and software reverse engineering, specifically for Windows environments, and to improve the malware analysis skills of SOC and IR professionals to the point where they can uncover secrets hidden in malware code using reverse engineering. The learned abilities are applicable not just to SOC and IR teams, but also to people who work or aspire to contribute to the development of anti-malware products such as antiviruses, EDRs, and sandboxes.

The course was designed to reflect the current variety of Windows malware, which includes a wide range of malware families written in various programming languages. Participants would learn how to use a wide range of malware analysis tools, including Sysinternals Suite, IDA, and others. This is a hands-on training session in which participants will learn how to dissect complex malware with modern reverse engineering tools.

You will receive a virtual machine with a complete environment for learning and testing your ability to analyze, along with malware binary. This will help you focus on understanding the key mechanisms rather than getting bogged down by less important technical details.

Learning Objective

  • Gain practical understanding of various methods for analyzing artefacts left on a compromised system.
  • Discover technique when dealing with sophisticated malware.
  • Explore tools to examine complex malware.
  • To examine and understand unknown malware.
  • To understand and identify malware categories.

Target Audience

  • Malware analyst, forensic investigators, incident responders and security engineers looking to enhance their malware analysis skills should take this training.
  • Red teamers who want to understand the approach and techniques of defenders.
  • All security engineers/professionals wanting to learn beginner to intermediate defensive tactics.

Knowledge Prerequisites

  • Be familiar with using Windows and Linux operating environments and be able to troubleshoot general OS connectivity and setup issues.
  • Be familiar with VMware and be able to import and configure virtual machines.
  • Have a general idea about core programming concepts such as variables, loops, and functions in order to quickly grasp the relevant concepts in this area. however, no programming experience is necessary.

Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent.

  • The use of Windows operating system is recommended due to the training material are covering Windows malware only.

  • Each participant required to Download and install VMware Workstation Pro 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ (for macOS hosts) prior to class beginning in order to run the given VM image. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. This course requires a “Pro” version of VMware software. The “Player” versions are not sufficient.

  • 8GB RAM required, at a minimum or more is required and dual core processors.

  • Reserved at least 200GB of hard disk space on your host machine for the VM image to run and to copy the given material.

  • Administrator / root access MANDATORY.

  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.

  • Wireless networking is required.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials.

Participants will need to download the course materials before the training begins. A secure link to access the materials will be provided in advance, with the exact date for the download to be announced by the organizer. The materials will be provided in a zipped folder, and the password to unzip the folder will be shared during the class. As a backup, the course materials will also be provided on a pre-loaded USB drive, which will be distributed on the day of the training.

Trainer: Fatah Hashim

Fatah Hashim is a member of the VX Engineering Security Research Group. He served in the cyber military sector in Malaysia Ministry of Defence (MINDEF) during his previous work and is now employed as a malware analyst in the national cybersecurity specialist agency. Specializing in offensive and defensive security software research, analysis, and development. His professional career and research interests focus on countering adversaries, malware research, reverse code engineering, and Red-Blue Teaming.

Training Agenda

  1. Introduction: Malware Analysis
  2. Overview of hands-on environment
  3. Basic knowledge for malware analysis
  4. Surface Analysis
  5. Dynamic Analysis
  1. Static Analysis
  2. Comprehensive exercise
  3. Malware Analysis hands-on scenario
  1. Dissecting the following malicious software:
    • Trojan Horses
    • Remote Access Tool (RAT)
    • File-less infection
  2. Detecting malware with YARA
  3. Preparing technical report