# Malware Analysis Fundamentals (Intermediate) (Self-Paced)

Canonical URL: <https://www.nobledesktop.com/classes/intermediate-malware-analysis-fundamentals-self-paced>

## Overview

This course covers static analysis (examining a file without running it) and dynamic analysis (observing behavior via sandbox and monitoring reports), building the judgment for which technique to use when. NIST SP 800-83 Rev. 1 is the backbone, and the real tools analysts use thread through it — disassemblers, sandboxes, YARA, network capture, and CISA's Malware Next-Gen. Dynamic analysis is taught purely through explanation and example reports; no lab, sandbox, or live sample is required. A thread on sample sensitivity, data handling, and structured reporting runs throughout.

The course finishes by pulling it together: you'll track a single sample from first triage through a written report modeled on the CISA Malware Analysis Report (MAR) format — the structure most analysts already have to produce — built to read cleanly for a technical or a leadership audience either way.

## What you'll learn

- Static analysis: triage, string and metadata extraction, YARA, basic disassembly
- Read dynamic analysis output (sandboxing, monitoring, network simulation) and recognize evasive behavior from example reports
- Capture network IOCs and correlate them with threat intel and MITRE ATT&CK
- Reach for FLARE-VM, REMnux, and CISA Malware Next-Gen where each is appropriate, as against public multi-scanners
- Write a CISA-MAR-style report that serves both technical and leadership readers
- Track a single sample from first triage through to final report in a worked example

## Prerequisites

Incident response fundamentals (NIST 800-61) and basic forensics (NIST 800-86); comfortable with the Windows/Linux command line. Intermediate level.

## Pricing

**Tuition:** $1049
