Malware Analyst’s Cookbook
by Michael Ligh, Steven Adair, Blake Hartstein, Matthew Richard · Michael Ligh, Steven Adair, Blake Hartstein, Matthew Richard
Recipe-style solutions for malware investigation: honeypots, sandbox automation, memory forensics with Volatility, and classification of samples. Readers finish able to build their own analysis tooling in Python and Perl rather than relying on commercial products.
This link may earn us a small commission at no extra cost to you. Affiliate disclosure
More resources on Malware Analysis
Hybrid Analysis
Free malware analysis service powered by CrowdStrike Falcon Sandbox. Submit files or URLs and receive static and behavioral reports with extracted indicators, MITRE ATT&CK mappings, and multi-engine verdicts you can reuse for triage.
FOR610 Reverse-Engineering Malware
Master malware analysis with FOR610! Learn reverse-engineering tools & techniques to dissect malicious code and defend against cyber threats.
Reverse Engineering Malware
Learn malware analysis and reverse engineering! This course from Malware Unicorn will equip you with practical skills to dissect malicious code.
Malware Analysis
Learn malware analysis techniques from Lenny Zeltser with this free, comprehensive course. Dive into dissecting and understanding malicious software.
MITRE ATT&CK
MITRE's public knowledge base of adversary tactics, techniques and procedures drawn from real-world intrusions, organised into enterprise, mobile and ICS matrices with linked threat groups, software, mitigations and detections. Defenders use it to describe attacker behaviour consistently and map detection coverage and gaps.
Practical Malware Analysis
A hands-on guide to dissecting Windows malware, covering sandboxing, x86 disassembly in IDA Pro, debugging with OllyDbg, unpacking, and anti-analysis tricks. Includes labs so readers can safely reverse real samples and write detection signatures.