(301) 220 2802
Basic Malware Analysis Training Near Washington, DC
TrainACE's Basic Malware Analysis class is a five-day, instructor-led course for IT and security professionals who need to take apart suspicious files and say with confidence what they do. You will work through the full analyst workflow, from triage and static analysis to dynamic detonation, memory forensics, and a final report, all inside an isolated lab built for handling live malware samples. The course is available in Greenbelt, MD, and live online.
This is a skills-based course. It is not tied to a certification exam. Every session includes two to three hands-on labs, and the week ends with a capstone exercise in which you analyze an unknown sample from start to finish and write it up the way a working analyst would.
Fundamentals of Malware Analysis is a practitioner-level course. There are no formal prerequisites, but you will move faster if you already work in IT or security and are comfortable with Windows, basic networking, and the command line. If you are new to IT, start with our foundational CompTIA tracks first. See the prerequisites section below.
Quick decision snapshot
- Best for: SOC analysts, incident responders, system and network administrators, and security professionals who need to investigate suspicious files themselves instead of escalating every alert.
- What you will be able to do: Triage a sample, extract indicators of compromise (IOCs), observe its behavior safely, write YARA detection rules, and produce a clear analysis report.
- What TrainACE includes: 30 hours of live instruction, 30 hands-on labs, a guided lab build using free and open-source tools you can keep using at work, and a certificate of completion.
Got Questions?
For more information about your specific needs, call us at (301) 220 2802 or complete the form below:
Why Choose TrainACE for Fundamentals of Malware Analysis Training?
Malware analysis is learned by doing. Recorded lectures can't tell you why a sample didn't detonate or what a strange registry write means, so that decision often comes down to having an experienced analyst in the room. TrainACE delivers this course live, hands-on, and in small groups.
- Training DC-area security teams since 2001: TrainACE has delivered hands-on cybersecurity training to federal agencies, DoD organizations, and government contractors in the Washington, DC region for more than two decades.
- Instructors with real credentials: Our malware analysis instructors bring real penetration testing, forensics, and DoD security experience to the classroom. See below.
- A toolchain you can actually use at work: Every tool in the course is free, open source, or available in a free tier, so you can rebuild the lab back at your own organization without a new software budget.
- Price & Quality Guarantee: Every enrollment is backed by TrainACE's Price & Quality Guarantee.
- Small class sizes: Enrollment is capped so you get direct instructor attention.
- Lifetime Career Support: Free Skills Clinics, Study Groups, and Career Path Recommendations after you graduate.
What that means for you
- Less trial and error: You learn a repeatable workflow and don't have to piece one together from blog posts and scattered tool documentation.
- Safer practice: You handle live samples in a properly isolated, snapshot-controlled lab with an instructor watching over the process.
- Immediate return: The workflow, YARA rules, and report template you build in class carry straight back to your day job.
The Caliber of Instructor You Can Expect
All TrainACE instructors hold active certifications in the subjects they teach and have at least three years of classroom experience. As an example of that standard, here is one of our core malware analysis instructors, Timber Wolfe.
Timber is a computer consultant with over 20 years of experience and a bachelor's degree in Computer Engineering from the University of Florida. He has spent his entire professional career in the DoD world, working at every level from board-level electronics and microcontrollers to hardware interfaces and high-level applications. He has been conducting penetration tests on software and hardware systems for more than ten years, and he takes part in government-sponsored Red Team events and cyber defense competitions. At TrainACE, he teaches a range of advanced security classes, and he authored our HoneyNetting and Honey Pot training course.
Selected certifications
- EC-Council CHFI (Computer Hacking Forensic Investigator)
- EC-Council CEH (Certified Ethical Hacker)
- EC-Council ECSA and LPT
- CompTIA Security+
- CompTIA A+ and Network+
Timber's background in hardware, low-level systems, and offensive security is the kind of experience that makes malware analysis click. Every instructor on the TrainACE team is held to the same standard.
Basic Malware Analysis Prerequisites
There are no formal prerequisites. This is still a practitioner course, though, and the pace assumes you are already comfortable working in Windows, understand basic networking (IP addressing, DNS, HTTP), and can use a command line. No programming background is required. Day 5 opens with an assembly language refresher before introducing disassembly and debugging.
You are likely a strong fit if you
- Work in a SOC, on an incident response team, or in a security operations role and want to investigate suspicious files yourself
- Are a system or network administrator who is regularly the first person to see infected machines
- Hold Security+, CySA+, CEH, or equivalent experience and want practical, hands-on analysis skills
- Plan to move on to advanced malware analysis or reverse engineering and need the foundation first
You may want a different first step if you
- Are new to IT and haven't yet built a foundation in operating systems and networking. Start with CompTIA Network+ or CompTIA Security+.
- Need a DoD 8140/8570 baseline certification. This course provides a certificate of completion, not a certification.
Course Format & Certificate of Completion
- Duration: 5 days, 30 hours of instruction
- Daily structure: A three-hour morning session and a three-hour afternoon session
- Hands-on labs: Two to three labs per session, 30 in total, including a three-part capstone
- Lab environment: Isolated VMware Workstation virtual machines running FLARE-VM (Windows) and REMnux (Linux)
- Certification exam: None. This is a skills-based course.
- Credential: TrainACE certificate of completion
Because the course isn't built around an exam, the time goes into practice: detonating samples, reading the evidence, and writing up findings. The Friday capstone puts it all together. You perform a complete static and dynamic analysis of an unknown sample, write a YARA rule and IOC list for it, and draft a report using the course template.
Tools you will work with
- Triage: VirusTotal, MalwareBazaar, HashMyFiles, CyberChef, TrID
- Static analysis: PEStudio, CFF Explorer, Detect It Easy, FLOSS, YARA
- Dynamic analysis: Sysinternals (Process Monitor, Process Explorer, Autoruns), System Informer, Wireshark, INetSim, FakeNet-NG
- Sandboxing and memory: ANY.RUN, CAPEv2, Hybrid Analysis, Volatility 3
- Code analysis: Ghidra, x64dbg, plus MITRE ATT&CK for behavior mapping
What You'll Learn in This Malware Analysis Class
The course follows the analyst workflow in order: triage, then static analysis, then dynamic analysis, then reporting. Each day builds on the one before it.
Day 1: Foundations, Lab Setup & Triage
- The analyst workflow and the strengths and limits of static, dynamic, and automated analysis
- Malware categories and behaviors, from worms and trojans to ransomware, rootkits, and fileless malware
- Legal, ethical, and safety considerations for handling live samples
- Building an isolated VMware Workstation lab with FLARE-VM, REMnux, and snapshot/revert discipline
- File hashing (including ssdeep fuzzy hashing), file-type identification, and pivoting in VirusTotal and MalwareBazaar
Day 2: Static Analysis
- Portable Executable (PE) structure: headers, sections, imports, exports, and resources
- Detecting packers, crypters, and obfuscation with entropy analysis
- Extracting IOCs from strings, including obfuscated and stack strings with FLOSS
- Writing and testing YARA rules for detection and classification
- Decoding Base64, XOR, and ROT obfuscation with CyberChef
Day 3: Dynamic Analysis
- Monitoring process, file system, and registry activity with Process Monitor and Process Explorer
- Finding Windows persistence mechanisms with before-and-after Autoruns comparisons
- Simulating a fake internet with INetSim and FakeNet-NG
- Capturing malware traffic in Wireshark and recognizing C2 beaconing and suspicious DNS
- Correlating host and network activity on a single behavioral timeline
Day 4: Sandboxing & Memory Forensics
- Automated sandbox analysis with ANY.RUN and CAPEv2, and how to read the reports
- Comparing findings across sandboxes such as Hybrid Analysis and Joe Sandbox
- Recognizing anti-VM, anti-debug, and sandbox-evasion techniques
- Capturing memory images from VMware snapshots
- Finding injected code and network indicators with Volatility 3 (pslist, pstree, malfind, netscan)
Day 5: Code Analysis, Reporting & Capstone
- An assembly language refresher covering registers, the stack, and calling conventions
- Disassembly and decompilation with Ghidra, and debugging decoding routines with x64dbg
- Building a consolidated IOC list and mapping behaviors to MITRE ATT&CK
- Writing an effective malware analysis report, from executive summary to recommendations
- Capstone: end-to-end analysis of an unknown sample, plus peer report review
Frequently Asked Questions
How long is the Basic Malware Analysis training?
The course runs five consecutive days with 30 hours of instruction, organized as a three-hour morning session and a three-hour afternoon session each day. It is offered in person in Greenbelt, MD, and live online.
Is there a certification exam?
No. Basic Malware Analysis is a skills-based course, and you will receive a TrainACE certificate of completion. If you also want a certification that covers related ground, see the next steps below.
Is this the right level for me?
If you already work in IT or security and are comfortable with Windows and basic networking, yes. You don't need prior malware analysis experience or programming skills. If you are new to IT, call us at (301) 220-2802 and an advisor will recommend the right starting point.
Is it safe to work with real malware in class?
Yes. Safety comes first in the course. Day 1 covers safe sample handling and the legal and ethical considerations, and you build an isolated lab network with snapshot and revert points before any sample is detonated. All analysis happens inside isolated virtual machines, never on production systems.
Do I need special equipment or software?
In-person students use TrainACE's lab workstations, which are preconfigured for the course. Every tool used in class is free, open source, or available in a free tier, so you can rebuild the same lab at your own organization after class. Live-online students need a reliable internet connection. Contact us for current lab access details for live-online attendance.
Where Does Basic Malware Analysis Take You Next?
Basic Malware Analysis gives you the core workflow. From here, most students either go deeper into malware itself or turn their skills into a recognized credential.
-
Intermediate Malware Analysis
The direct follow-on course. It takes on the evasion techniques introduced here (anti-disassembly, anti-debugging, anti-VM, and unpacking) along with shellcode and C++ code analysis. -
Reverse Engineering Malware
For analysts who want to go deeper into code, with kernel debugging in WinDbg, process injection, decryption routines, and rootkit analysis. -
CHFI - Computer Hacking Forensic Investigator
Adds a certification to your investigation skills, extending the memory and host forensics in this course into full digital forensics and evidence handling.
Not sure which path fits your role? Call us at (301) 220-2802 for a direct recommendation.
Ready to Enroll?
Select a class date from the schedule below, or call us at (301) 220-2802 to speak with an advisor. Do not settle for anonymous, online-only training - choose the DC-area experts who deliver real-world results.
Got Questions?
For more information about your specific needs, call us at (301) 220 2802 or complete the form below:
Got Questions?
For more information about your specific needs, call us at (301) 220 2802 or complete the form below:
Get your Basic Malware Analysis Training in our convenient IT training centers in Greenbelt, Maryland or live-online from anywhere.