← Back to the catalogue
Domain 05 . Security

Malware Analysis

50
Hours of teaching
Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A malware analysis course from safe sample handling to behavioural and code-level analysis. The course builds an isolated analysis lab, then works through static triage, dynamic execution monitoring, unpacking, assembly-level review and indicator extraction, using real but defanged samples.

Learners produce analysis reports with detection signatures for each sample studied.

Who it is for
  • SOC and incident response analysts
  • Threat intelligence teams
  • Reverse engineering enthusiasts
  • Security researchers
Prerequisites
Operating system internals, networking, and comfort with Windows administration. Assembly exposure is helpful.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Sample Analysis Report with Signatures

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Build and isolate a malware analysis lab safely.
02
Triage samples with static indicators and hashing.
03
Observe behaviour with process, file and network monitoring.
04
Identify packing and unpack simple samples.
05
Read assembly to understand key routines.
06
Extract host and network indicators of compromise.
07
Write YARA rules and an analysis report.

Module structure

8 modules
Module 01

Lab and Safety

Isolation . Sample handling . Analysis workflow . Snapshots . Legal and ethical rules
Module 02

Malware Types

Trojans . Loaders . Rootkits . Ransomware . Info stealers . Living-off-the-land techniques
Module 03

Static Analysis

File headers . Strings . Entropy . PE structure . Imports and exports . Hashing and reputation
Tools — PEStudio, CFF Explorer
Module 04

Dynamic Analysis

Process monitoring . Network capture . Sandbox reports . File and registry changes . API calls
Tools — Wireshark, Cuckoo
Module 05

Packing and Obfuscation

Packers . Anti-analysis tricks . Shellcode basics . Manual unpacking . Script deobfuscation
Module 06

Code Analysis

x86 essentials . Key routine identification . Disassembly . Debugging
Tools — Ghidra, x64dbg
Module 07

Document and Script Malware

Macro analysis . PowerShell and JScript . PDF objects . LNK and archive lures
Lab
Phishing Attachment Analysis
Module 08

Detection and Reporting

IOC extraction . Sigma rules . Report structure . YARA rules . Threat classification

Assessment & certification

Module assignments and labs
25%
Mini projects
20%
Internal assessments
15%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
Malware AnalystThreat ResearcherReverse EngineerIncident Response EngineerDetection Engineer
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security