Learning Paths
Structured learning paths that take you from fundamentals to advanced malware analysis techniques.
Recorded Browser Cases use recorded output; no specimen is downloaded or executed in the Browser Case. Optional Live Labs use externally referenced specimens in a learner-managed isolated VM.
Free
Path A: Core Analyst Path
Master the fundamentals of malware analysis. Start with safe lab practices, learn to identify indicators, and progress through static and dynamic analysis techniques. This is the mandatory starting path for all learners.
Premium
Path B: Windows Malware Internals
Deep-dive into Windows-specific malware techniques including .NET malware analysis, WMI abuse patterns, and PowerShell-based tradecraft used by modern threat actors.
First module free
Premium
Path C: Reverse Engineering
Learn to read disassembly, navigate Ghidra, map Windows API usage to behavior, and reconstruct malware capabilities from binary analysis.
First module free
Premium
Path D: Dynamic Analysis & Detection
Move beyond basic behavioral analysis. Learn advanced dynamic techniques, create YARA and Sigma rules, and produce professional incident reports.
First module free
Premium
Path F: Malicious Document & Script Analysis
Analyze weaponized Office documents, PDFs, and script-based malware. Extract macros, deobfuscate JavaScript/VBScript, and reconstruct multi-stage delivery chains used by modern threat actors.
First module free
Premium
Path E: Capstone Labs
Put your skills to the test with guided and semi-guided capstone exercises simulating real-world malware incidents from triage to final report. This path assumes Paths A through D and F: it integrates them rather than teaching anything new, so work it last.
First module free
