Skip to content

Latest commit

 

History

History
152 lines (136 loc) · 10.3 KB

File metadata and controls

152 lines (136 loc) · 10.3 KB

Awesome Malware Analysis & Reverse Engineering Learning Resources

Malware Analysis and Reverse Engineering (RE) cover static and dynamic analysis of binaries: PE/ELF/Mach-O formats, disassembly/decompilation, debugging, unpacking, anti-analysis evasion, shellcode, and family attribution. It overlaps with DFIR (triage, IoC extraction, YARA) and offensive work (loader/implant development).

ToC

  1. Books
  2. Videos
  3. Free/Paid Courses
  4. Free/Paid Labs
  5. RE / Malware Tools
  6. Certifications
  7. Blogs/Articles

Books

  1. Practical Malware Analysis by Michael Sikorski, Andrew Honig (No Starch) - Still the best starter book despite its age.
  2. Practical Reverse Engineering by Bruce Dang, Alexandre Gazet, Elias Bachaalany - Deeper x86/x64/ARM.
  3. The Ghidra Book by Chris Eagle, Kara Nance (No Starch)
  4. The IDA Pro Book by Chris Eagle
  5. Learning Malware Analysis by Monnappa K A (Packt) - Python-focused, great companion.
  6. Windows Internals by Pavel Yosifovich, Mark Russinovich et al. (7th Ed Parts 1 & 2)
  7. Rootkits and Bootkits by Alex Matrosov, Eugene Rodionov, Sergey Bratus (No Starch)
  8. Evasive Malware by Kyle Cucci (No Starch, 2024) - Modern anti-analysis techniques.
  9. The Art of Memory Forensics by Michael Hale Ligh et al.
  10. Reversing: Secrets of Reverse Engineering by Eldad Eilam - Older but classic.
  11. Serious Cryptography by JP Aumasson (No Starch) - For crypto used by malware (ransomware, C2).

Videos

  1. OALabs - malware analysis walkthroughs
  2. MalwareAnalysisForHedgehogs (Karsten Hahn)
  3. LiveOverflow - binary exploitation and RE
  4. stacksmashing - RE and hardware.
  5. HackadayU / Open Security Training 2
  6. RPISEC MBE (Modern Binary Exploitation)
  7. Recon Conference archives
  8. OffensiveCon talks
  9. SANS RE / DFIR Summit archives
  10. Malware Unicorn workshops

Free/Paid Courses

Free / low-cost

  1. Malware Unicorn - Reverse Engineering 101 & 102 (free) - Highly recommended starter.
  2. Open Security Training 2 (OST2) - free Intel, ARM, Windows, reverse engineering courses
  3. MalwareTech beginner RE challenges
  4. Dr. Josh Stroschein - free RE courses on YouTube
  5. NSA's free Ghidra class
  6. TryHackMe - Malware Analysis / Reverse Engineering paths
  7. Crackmes.one - CrackMe challenges at all levels.
  8. ret2 Wargames (free teaser)
  9. corelan.be exploit writing tutorials (free, classic)
  10. Zero2Automated free samples

Paid

  1. SANS FOR610: Reverse-Engineering Malware (GREM) - Canonical course.
  2. Zero2Automated by 0verfl0w_ and Daniel Bunce - Very respected advanced course.
  3. TCM Security - Practical Malware Analysis & Triage
  4. OffSec EXP-301 (OSED) - Windows User Mode Exploit Development
  5. OffSec EXP-401 (OSEE) - Advanced Windows Exploitation
  6. Pluralsight / INE - malware analysis paths

Free/Paid Labs

  1. FLARE-On CTF (annual, free) - Mandiant's annual RE challenge; archives are invaluable practice.
  2. Crackmes.one
  3. Reverse Engineering Challenges (Root-Me)
  4. pwnable.kr / pwnable.tw / pwnable.xyz
  5. HackTheBox - Reverse challenges
  6. Malware Traffic Analysis exercises
  7. MalwareBazaar / MalwareBazaar samples
  8. vx-underground - Largest public malware sample collection; handle with strict lab discipline.
  9. any.run public submissions
  10. theZoo - malware database for research

RE / Malware Tools

Disassemblers / decompilers

  1. IDA Pro / IDA Free / IDA Home - Industry-standard; Hex-Rays decompiler.
  2. Ghidra - NSA-developed, free and powerful.
  3. Binary Ninja - Modern, scriptable.
  4. radare2 + Cutter (Rizin fork: iaito) - Open-source RE framework.
  5. Hopper Disassembler - macOS/Linux commercial.
  6. objdump / readelf / nm / strings

Debuggers

  1. x64dbg / x32dbg
  2. WinDbg / WinDbg Preview
  3. OllyDbg (legacy, 32-bit only)
  4. GDB + pwndbg / GEF / peda
  5. LLDB
  6. dnSpy / dnSpyEx - .NET decompiler/debugger.

Sandboxes / dynamic analysis

  1. CAPE Sandbox - Fork of Cuckoo, actively maintained.
  2. Cuckoo Sandbox (legacy)
  3. any.run - Interactive cloud sandbox.
  4. Joe Sandbox
  5. Hybrid Analysis
  6. Triage by Hatching / Recorded Future
  7. Procmon / Process Explorer / Sysinternals Suite
  8. API Monitor
  9. Noriben (Python sandbox wrapper)

Android / mobile RE (see also mobile resources)

  1. jadx, apktool, Frida

Unpacking / anti-anti-analysis

  1. Scylla - Import reconstruction.
  2. UPX - Common packer (also unpacks).
  3. PE-sieve / hollows_hunter by hasherezade.
  4. VMUnprotect / de4dot - .NET deobfuscators.

Scripting / frameworks

  1. pefile (Python)
  2. LIEF - Library to parse PE/ELF/Mach-O.
  3. angr - Symbolic execution.
  4. Triton - DBA/taint framework.
  5. Unicorn Engine - CPU emulator.
  6. Qiling - Binary emulation framework.
  7. Capstone / Keystone

Detection / classification

  1. YARA - Rule engine; bookmark YARA-Rules and Neo23x0 signature-base.
  2. Detect It Easy (DIE)
  3. PEstudio
  4. CAPA by Mandiant - Identifies capabilities in executables.
  5. FLOSS by Mandiant - Extracts obfuscated strings.

Certifications

  1. GREM - GIAC Reverse Engineering Malware (SANS FOR610) - Industry benchmark.
  2. OSED - Offensive Security Exploit Developer (OffSec EXP-301)
  3. OSEE - Offensive Security Exploitation Expert (EXP-401)
  4. CREST Certified Malware Reverse Engineer (CCMRE)
  5. eCMAP / eCRE by INE Security
  6. Zero2Automated certificate

Blogs/Articles

  1. MalwareTech blog
  2. Malwarebytes Labs threat intelligence
  3. Mandiant / FireEye blog
  4. Palo Alto Unit 42
  5. Cisco Talos Intelligence
  6. ESET We Live Security
  7. Kaspersky Securelist
  8. Check Point Research
  9. ReversingLabs blog
  10. CrowdStrike research
  11. Didier Stevens blog - Tools for PDF/OLE/script malware.
  12. Hexacorn - Persistence and Windows internals.
  13. hasherezade blog
  14. 0x00sec community forum
  15. FLARE team Google group / blog
  16. vx-underground papers archive
  17. Awesome Malware Analysis GitHub
  18. Awesome Reversing GitHub
  19. Practical Binary Analysis (free online supplement)