Skip to content

Malware Fundamentals

Malware (malicious software) is any program designed to damage, spy on, extort, or take control of a system without consent. Understanding it is key both for the red team (knowing how an adversary operates to emulate it in authorized exercises) and the blue team (detecting, analyzing, and responding). This area focuses on understanding the techniques and, above all, on analyzing samples safely: malware analysis is a fundamental defensive discipline.

Virus / Worm self-replicating (virus needs a host; worm spreads alone over the network)
Trojan disguised as legitimate software
RAT Remote Access Trojan: remote control of the machine
Ransomware encrypts data and demands ransom (see mal-ransomware)
Infostealer steals credentials, cookies, crypto wallets
Keylogger / Spyware logs keystrokes / spies on activity
Rootkit / Bootkit hides its presence at a deep system level
Loader / Dropper downloads/runs another payload (first stage)
Botnet network of infected machines controlled by a C2 (see mal-c2)
Wiper destroys data (no ransom; sabotage)
1. Delivery phishing, exploit, download, USB (see social engineering)
2. Execution the code runs (often loader/dropper -> payload)
3. Evasion avoid AV/EDR (see mal-evasion, mal-obfus)
4. Persistence survive reboots (see mal-persist)
5. C2 communication with the attacker (see mal-c2)
6. Action theft, encryption, espionage, lateral propagation
  • Offensive / Red Team: in authorized exercises, real-adversary TTPs (C2 frameworks, loaders, evasion) are emulated to test defenses. The goal is to measure detection and response, not cause damage.
  • Analysis / Blue Team: given a suspicious sample, the analyst determines what it does, how, and how to detect/contain it. It’s the direct application of reversing (see Introduction to Reversing).

This wiki prioritizes analysis and understanding techniques to defend; offensive use is limited to authorized environments (red team with scope).

Analyzing malware involves handling (and sometimes running) dangerous code. Never on your real machine:

# isolated lab
dedicated VM (snapshots), isolated or simulated network
REMnux Linux distro for malware analysis (preinstalled tools)
FLARE VM Windows environment for analysis (Mandiant)
# simulated network for dynamic analysis (see mal-dynamic)
INetSim / FakeNet fake the Internet to capture what the malware tries to contact
# never connect the lab to your real network/Internet without control
1. Triage hash, VirusTotal, file type, strings (without running)
2. Static disassemble/decompile, imports, encrypted strings (see mal-static)
3. Dynamic run in an isolated sandbox, observe behavior (see mal-dynamic)
4. Deobfuscate bypass packing/obfuscation (see mal-obfus)
5. Extract IOCs C2 domains/IPs, hashes, mutexes, registry keys
6. Signatures write YARA/Sigma rules for detection (see mal-yara)
7. Report TTPs (map to MITRE ATT&CK), IOCs, remediation
  • Modern EDR/AV (behavior detection, not just signatures), application allowlisting (AppLocker/WDAC).
  • Segmentation, least privilege, patching (closes entry paths), offline backups (see Ransomware (analysis and defense)).
  • Threat intelligence: consume IOCs and TTPs; behavior detection (Sigma, EDR) over hashes.
  • Anti-phishing training (the #1 entry vector), MFA, and an incident-response process (see dfir).