Cybersecurity Online Part-time 12 weeks / Full-time 6 weeks Certificate + Digital Badge

Practical Malware Analysis & Triage

Build the judgement and practical workflow to safely triage suspicious files, understand malicious behaviour, extract useful indicators, and communicate defensible findings to a security team.

Part-time 12 weeks or full-time 6 weeks
Live online delivery with isolated labs
SGD 1,200 nett
Certificate + Digital Badge

From suspicious file to confident triage decision

This revised programme combines the essential foundations from the internship plan with a structured analyst workflow, repeatable practical labs, and a capstone case. The emphasis is on safe analysis, evidence quality, and useful defensive outcomes rather than tool memorisation.

What learners will practise

  • Establish a safe, isolated malware-analysis workspace and preserve evidence.
  • Perform rapid static triage of Windows PE files and suspicious documents.
  • Use controlled execution, process, file, registry, and network observations.
  • Recognise persistence, injection, packing, obfuscation, and evasion patterns.
  • Extract and validate IOCs, map behaviour to MITRE ATT&CK, and propose detections.
  • Write a concise technical report and an executive-ready incident summary.

Learning approach

Each learning block follows a consistent cycle: explain the concept, demonstrate a safe technique, complete a guided lab, then defend the conclusion in a case notebook. Learners work with benign training samples and instructor-provided artefacts inside an isolated lab. The programme does not authorise testing against third-party systems or handling live malware outside the defined environment.

Target learners

The programme is designed for people moving into hands-on defensive security work or strengthening the malware triage capability they already use.

Target learner profiles and programme fit
Learner profile Why this programme fits
SOC and security operations analysts Develop a repeatable escalation workflow for suspicious attachments, endpoints, and alerts.
Junior incident responders and DFIR practitioners Strengthen evidence handling, behavioural analysis, IOC extraction, and reporting.
Security engineers and blue-team practitioners Connect analysis findings to YARA, Sigma, endpoint, and network detection ideas.
Cybersecurity graduates, interns, and career switchers Build a grounded portfolio case and the practical habits expected in an analyst role.
IT professionals moving into security Translate existing Windows, networking, scripting, and troubleshooting experience into triage work.
Security-minded developers and threat researchers Understand how malicious code behaves and how to communicate findings responsibly to defenders.
Prerequisites: Learners should be comfortable with basic computer operations, files and processes, networking concepts such as IP addresses, ports and DNS, and a command line. Familiarity with Windows and Linux, Python or another scripting language, and basic cybersecurity/SOC concepts is strongly recommended. Prior IT, software, system administration, SOC, or cybersecurity working experience is helpful but not mandatory for motivated learners who can complete the pre-course preparation.

Plan the commitment before you enrol

Both formats cover the same learning outcomes and practical assessments. Full-time delivery compresses two part-time learning blocks into each week and requires protected study time.

Part-time

8–10 committed hours / week

12 weeks. Typically 3 hours of live instruction or facilitated lab time plus 5–7 hours of guided practice, case notes, and assessment work.

Full-time

18–20 committed hours / week

6 weeks. Typically 7–8 hours of live instruction or facilitated lab time plus 10–12 hours of lab practice, case notes, and assessment work.

Equipment and software requirements
Requirement Minimum / recommended setup
Computer 64-bit PC or Mac with hardware virtualisation enabled, at least 16 GB RAM (32 GB recommended), a modern multi-core CPU, and at least 100 GB of free SSD space for virtual machines and snapshots.
Host operating system Supported current Windows, macOS, or Linux host with permission to install and run a virtualisation platform. Learners using a managed corporate device must confirm that the lab tools are permitted.
Analysis lab An isolated Windows virtual machine, snapshots, a host-only or otherwise controlled lab network, and a separate workspace for instructor-provided samples. Live samples must not be opened on a production endpoint.
Software VirtualBox, VMware, or an equivalent approved hypervisor; Windows analysis VM; Python 3.11+; PowerShell; Git; a modern browser; and the course tools supplied or approved by the instructor. Docker is optional.
Internet and collaboration Stable internet access of at least 20 Mbps, webcam and microphone for live sessions, and a current browser for the learning platform, video sessions, and downloads.
Safety and access Local administrator rights or equivalent support for installing the lab, reliable backups, and a commitment never to upload course samples to public sandboxes or external services without explicit approval.

A revised 12-week learning journey

The part-time cohort follows the sequence below. The full-time cohort covers the same sequence in six weeks by combining adjacent weekly blocks. Tools may evolve, but the analyst outcomes and safe-work principles remain constant.

Practical Malware Analysis and Triage curriculum
Week Focus Detailed topics Practical output
1 Orientation, ethics & safe lab design Threat, vulnerability, risk, CIA, defence-in-depth, analyst responsibilities, sample provenance, chain of custody, VM isolation, snapshots, and lab safety. Personal lab plan and evidence-handling checklist.
2 Windows, Linux & networking foundations Processes, services, scheduled tasks, registry, permissions, event logs, PowerShell, DNS, HTTP/S, TCP/IP, common ports, and basic Wireshark use. Normal-behaviour baseline and network observation worksheet.
3 Malware triage workflow Intake questions, hashing, file types, metadata, reputation with approved offline artefacts, prioritisation, confidence levels, and triage decision points. First-look triage record with an evidence-backed disposition.
4 PE and static analysis Windows PE structure, headers, sections, imports and exports, strings, resources, entropy, signatures, packer clues, and suspicious document indicators. Static analysis worksheet and initial IOC set.
5 Assembly and debugging essentials x86/x64 concepts, registers, control flow, calling conventions, debugger navigation, breakpoints, API calls, and recognising common execution patterns. Annotated execution path for a benign training specimen.
6 Dynamic behaviour analysis Process trees, file and registry changes, services, scheduled tasks, mutexes, handles, command lines, PowerShell, Procmon, and controlled execution. Behaviour timeline and parent-child process analysis.
7 Network behaviour and command-and-control DNS and HTTP/S observations, beaconing, user agents, URI patterns, certificates, simulated C2, packet capture, and separating signal from normal traffic. Network IOC table and communication narrative.
8 Persistence, evasion & unpacking Run keys, services, tasks, WMI, injection concepts, anti-analysis indicators, packing and obfuscation, unpacking strategy, and limits of conclusions. Persistence map and an unpacking decision log.
9 Memory and artefact forensics Memory acquisition concepts, processes and injected regions, handles, command history, volatile artefacts, timeline correlation, and interpreting incomplete evidence. Memory triage notes and corroborated finding list.
10 Detection engineering and ATT&CK IOC quality, YARA fundamentals, Sigma concepts, detection logic, false-positive thinking, MITRE ATT&CK mapping, and hand-off to SOC tooling. A small YARA rule, a Sigma-style detection, and ATT&CK mapping.
11 Case management and professional reporting Scoping, hypotheses, evidence citations, confidence and uncertainty, technical findings, executive summaries, remediation recommendations, and verbal briefings. Complete draft malware triage report and five-minute briefing.
12 Capstone investigation and assessment End-to-end triage of an instructor-provided case, peer review, practical assessment, presentation, feedback, portfolio refinement, and next-step development plan. Capstone case file, final report, detection pack, and presentation.

What completion looks like

Learners are assessed on safe working practice, reasoning quality, technical evidence, and communication—not on whether they can reproduce a single tool command.

Weekly lab practice

Guided exercises, analyst worksheets, evidence citations, and short reflections establish repeatable habits.

Case notebook

Each learner builds a defensible record of hypotheses, observations, confidence, IOCs, and recommended next actions.

Capstone assessment

An end-to-end investigation, technical report, detection artefacts, and a clear briefing demonstrate applied readiness.

Certificate of Completion Digital Badge and Certificate

Learners who meet the attendance, lab participation, assessment, and capstone requirements will earn a Certificate of Completion digital badge and certificate from Digital Futures Academy. The credential records successful completion of this programme; it is not represented as a government licence or an external professional certification.

Before you join

Is the programme suitable for someone without previous malware-analysis experience?

Yes, if you have the stated foundations and are willing to complete the preparation work. The curriculum starts with safe lab design, operating systems, networking, and a structured triage workflow before moving into deeper analysis.

What is the difference between the part-time and full-time options?

The outcomes, curriculum, labs, and assessment standard are the same. Part-time runs for 12 weeks at 8–10 committed hours per week. Full-time runs for 6 weeks at 18–20 committed hours per week and combines two learning blocks in each week.

Will I receive live malware samples?

Learning uses benign training samples and instructor-provided artefacts in an isolated environment. Any sample handling is governed by the lab safety rules. Learners must not download or execute unapproved live malware on personal or production systems.

What does the SGD 1,200 nett fee include?

The fee covers online instruction, guided lab materials, assessment activities, feedback, and issuance of the Certificate of Completion digital badge and certificate when the completion requirements are met. Personal computer, operating-system, virtualisation, and internet costs remain the learner's responsibility.

What can I do after completing the programme?

You should be able to contribute to malware triage, SOC escalation, junior incident-response, detection-engineering, or security-analysis workflows. Continued practice, supervised case work, and further study are recommended before independently handling high-risk incidents.

Build practical malware triage capability

Ask about cohort dates, delivery format, and whether your current experience is a good fit.