| 1 |
Orientation, ethics & safe lab design |
Threat, vulnerability, risk, CIA, defence-in-depth, analyst responsibilities, sample provenance, chain of custody, VM isolation, snapshots, and lab safety. |
Personal lab plan and evidence-handling checklist. |
| 2 |
Windows, Linux & networking foundations |
Processes, services, scheduled tasks, registry, permissions, event logs, PowerShell, DNS, HTTP/S, TCP/IP, common ports, and basic Wireshark use. |
Normal-behaviour baseline and network observation worksheet. |
| 3 |
Malware triage workflow |
Intake questions, hashing, file types, metadata, reputation with approved offline artefacts, prioritisation, confidence levels, and triage decision points. |
First-look triage record with an evidence-backed disposition. |
| 4 |
PE and static analysis |
Windows PE structure, headers, sections, imports and exports, strings, resources, entropy, signatures, packer clues, and suspicious document indicators. |
Static analysis worksheet and initial IOC set. |
| 5 |
Assembly and debugging essentials |
x86/x64 concepts, registers, control flow, calling conventions, debugger navigation, breakpoints, API calls, and recognising common execution patterns. |
Annotated execution path for a benign training specimen. |
| 6 |
Dynamic behaviour analysis |
Process trees, file and registry changes, services, scheduled tasks, mutexes, handles, command lines, PowerShell, Procmon, and controlled execution. |
Behaviour timeline and parent-child process analysis. |
| 7 |
Network behaviour and command-and-control |
DNS and HTTP/S observations, beaconing, user agents, URI patterns, certificates, simulated C2, packet capture, and separating signal from normal traffic. |
Network IOC table and communication narrative. |
| 8 |
Persistence, evasion & unpacking |
Run keys, services, tasks, WMI, injection concepts, anti-analysis indicators, packing and obfuscation, unpacking strategy, and limits of conclusions. |
Persistence map and an unpacking decision log. |
| 9 |
Memory and artefact forensics |
Memory acquisition concepts, processes and injected regions, handles, command history, volatile artefacts, timeline correlation, and interpreting incomplete evidence. |
Memory triage notes and corroborated finding list. |
| 10 |
Detection engineering and ATT&CK |
IOC quality, YARA fundamentals, Sigma concepts, detection logic, false-positive thinking, MITRE ATT&CK mapping, and hand-off to SOC tooling. |
A small YARA rule, a Sigma-style detection, and ATT&CK mapping. |
| 11 |
Case management and professional reporting |
Scoping, hypotheses, evidence citations, confidence and uncertainty, technical findings, executive summaries, remediation recommendations, and verbal briefings. |
Complete draft malware triage report and five-minute briefing. |
| 12 |
Capstone investigation and assessment |
End-to-end triage of an instructor-provided case, peer review, practical assessment, presentation, feedback, portfolio refinement, and next-step development plan. |
Capstone case file, final report, detection pack, and presentation. |