Lab setup
Building a safe, instrumented environment to detonate and study samples.
Hands-on training that turns engineers into malware analysts. We currently run one course, a five-day practical deep dive into malware analysis and reverse engineering, built and taught by a researcher who does this work in the field. On-site or remote.
From an empty lab to breaking real ransomware. Five days of doing, not watching.
Twelve modules, building from fundamentals to real-world ransomware.
Building a safe, instrumented environment to detonate and study samples.
The two core approaches, and when to reach for each.
Sandboxes and automated pipelines to triage samples quickly and at scale.
Reading x86/x64 well enough to follow any sample.
Working effectively in IDA Pro and Ghidra.
Driving execution and inspecting a sample as it runs.
Spotting and bypassing the tricks samples use to resist debuggers and analysts.
Unpacking, deobfuscation, and evasion handling.
Recognizing and reasoning about crypto inside malware.
Rust, Go, .NET, and script-based threats.
Pulling indicators and configuration for detection.
Hands-on practical work on real ransomware samples.
By the end of the week, the work is in your hands, not just in your notes.
Delivered on-site at your offices or fully remote, for an individual or a whole team. A working knowledge of C and a scripting language helps, and some basic digital-forensics experience is desirable. No prior reverse-engineering experience is required. Get in touch for available dates, group size, and a tailored agenda.
Tell us your team and your timeline, and we will set up the dates and tailor the agenda.