Malware Analysis and Reverse Engineering (RE) cover static and dynamic analysis of binaries: PE/ELF/Mach-O formats, disassembly/decompilation, debugging, unpacking, anti-analysis evasion, shellcode, and family attribution. It overlaps with DFIR (triage, IoC extraction, YARA) and offensive work (loader/implant development).
- Practical Malware Analysis by Michael Sikorski, Andrew Honig (No Starch) - Still the best starter book despite its age.
- Practical Reverse Engineering by Bruce Dang, Alexandre Gazet, Elias Bachaalany - Deeper x86/x64/ARM.
- The Ghidra Book by Chris Eagle, Kara Nance (No Starch)
- The IDA Pro Book by Chris Eagle
- Learning Malware Analysis by Monnappa K A (Packt) - Python-focused, great companion.
- Windows Internals by Pavel Yosifovich, Mark Russinovich et al. (7th Ed Parts 1 & 2)
- Rootkits and Bootkits by Alex Matrosov, Eugene Rodionov, Sergey Bratus (No Starch)
- Evasive Malware by Kyle Cucci (No Starch, 2024) - Modern anti-analysis techniques.
- The Art of Memory Forensics by Michael Hale Ligh et al.
- Reversing: Secrets of Reverse Engineering by Eldad Eilam - Older but classic.
- Serious Cryptography by JP Aumasson (No Starch) - For crypto used by malware (ransomware, C2).
- OALabs - malware analysis walkthroughs
- MalwareAnalysisForHedgehogs (Karsten Hahn)
- LiveOverflow - binary exploitation and RE
- stacksmashing - RE and hardware.
- HackadayU / Open Security Training 2
- RPISEC MBE (Modern Binary Exploitation)
- Recon Conference archives
- OffensiveCon talks
- SANS RE / DFIR Summit archives
- Malware Unicorn workshops
- Malware Unicorn - Reverse Engineering 101 & 102 (free) - Highly recommended starter.
- Open Security Training 2 (OST2) - free Intel, ARM, Windows, reverse engineering courses
- MalwareTech beginner RE challenges
- Dr. Josh Stroschein - free RE courses on YouTube
- NSA's free Ghidra class
- TryHackMe - Malware Analysis / Reverse Engineering paths
- Crackmes.one - CrackMe challenges at all levels.
- ret2 Wargames (free teaser)
- corelan.be exploit writing tutorials (free, classic)
- Zero2Automated free samples
- SANS FOR610: Reverse-Engineering Malware (GREM) - Canonical course.
- Zero2Automated by 0verfl0w_ and Daniel Bunce - Very respected advanced course.
- TCM Security - Practical Malware Analysis & Triage
- OffSec EXP-301 (OSED) - Windows User Mode Exploit Development
- OffSec EXP-401 (OSEE) - Advanced Windows Exploitation
- Pluralsight / INE - malware analysis paths
- FLARE-On CTF (annual, free) - Mandiant's annual RE challenge; archives are invaluable practice.
- Crackmes.one
- Reverse Engineering Challenges (Root-Me)
- pwnable.kr / pwnable.tw / pwnable.xyz
- HackTheBox - Reverse challenges
- Malware Traffic Analysis exercises
- MalwareBazaar / MalwareBazaar samples
- vx-underground - Largest public malware sample collection; handle with strict lab discipline.
- any.run public submissions
- theZoo - malware database for research
- IDA Pro / IDA Free / IDA Home - Industry-standard; Hex-Rays decompiler.
- Ghidra - NSA-developed, free and powerful.
- Binary Ninja - Modern, scriptable.
- radare2 + Cutter (Rizin fork: iaito) - Open-source RE framework.
- Hopper Disassembler - macOS/Linux commercial.
- objdump / readelf / nm / strings
- x64dbg / x32dbg
- WinDbg / WinDbg Preview
- OllyDbg (legacy, 32-bit only)
- GDB + pwndbg / GEF / peda
- LLDB
- dnSpy / dnSpyEx - .NET decompiler/debugger.
- CAPE Sandbox - Fork of Cuckoo, actively maintained.
- Cuckoo Sandbox (legacy)
- any.run - Interactive cloud sandbox.
- Joe Sandbox
- Hybrid Analysis
- Triage by Hatching / Recorded Future
- Procmon / Process Explorer / Sysinternals Suite
- API Monitor
- Noriben (Python sandbox wrapper)
- Scylla - Import reconstruction.
- UPX - Common packer (also unpacks).
- PE-sieve / hollows_hunter by hasherezade.
- VMUnprotect / de4dot - .NET deobfuscators.
- pefile (Python)
- LIEF - Library to parse PE/ELF/Mach-O.
- angr - Symbolic execution.
- Triton - DBA/taint framework.
- Unicorn Engine - CPU emulator.
- Qiling - Binary emulation framework.
- Capstone / Keystone
- YARA - Rule engine; bookmark YARA-Rules and Neo23x0 signature-base.
- Detect It Easy (DIE)
- PEstudio
- CAPA by Mandiant - Identifies capabilities in executables.
- FLOSS by Mandiant - Extracts obfuscated strings.
- GREM - GIAC Reverse Engineering Malware (SANS FOR610) - Industry benchmark.
- OSED - Offensive Security Exploit Developer (OffSec EXP-301)
- OSEE - Offensive Security Exploitation Expert (EXP-401)
- CREST Certified Malware Reverse Engineer (CCMRE)
- eCMAP / eCRE by INE Security
- Zero2Automated certificate
- MalwareTech blog
- Malwarebytes Labs threat intelligence
- Mandiant / FireEye blog
- Palo Alto Unit 42
- Cisco Talos Intelligence
- ESET We Live Security
- Kaspersky Securelist
- Check Point Research
- ReversingLabs blog
- CrowdStrike research
- Didier Stevens blog - Tools for PDF/OLE/script malware.
- Hexacorn - Persistence and Windows internals.
- hasherezade blog
- 0x00sec community forum
- FLARE team Google group / blog
- vx-underground papers archive
- Awesome Malware Analysis GitHub
- Awesome Reversing GitHub
- Practical Binary Analysis (free online supplement)