Malware Fundamentals
Malware (malicious software) is any program designed to damage, spy on, extort, or take control of a system without consent. Understanding it is key both for the red team (knowing how an adversary operates to emulate it in authorized exercises) and the blue team (detecting, analyzing, and responding). This area focuses on understanding the techniques and, above all, on analyzing samples safely: malware analysis is a fundamental defensive discipline.
Malware types
Section titled “Malware types”Virus / Worm self-replicating (virus needs a host; worm spreads alone over the network)Trojan disguised as legitimate softwareRAT Remote Access Trojan: remote control of the machineRansomware encrypts data and demands ransom (see mal-ransomware)Infostealer steals credentials, cookies, crypto walletsKeylogger / Spyware logs keystrokes / spies on activityRootkit / Bootkit hides its presence at a deep system levelLoader / Dropper downloads/runs another payload (first stage)Botnet network of infected machines controlled by a C2 (see mal-c2)Wiper destroys data (no ransom; sabotage)The malware attack lifecycle
Section titled “The malware attack lifecycle”1. Delivery phishing, exploit, download, USB (see social engineering)2. Execution the code runs (often loader/dropper -> payload)3. Evasion avoid AV/EDR (see mal-evasion, mal-obfus)4. Persistence survive reboots (see mal-persist)5. C2 communication with the attacker (see mal-c2)6. Action theft, encryption, espionage, lateral propagationThe two faces: offensive and analysis
Section titled “The two faces: offensive and analysis”- Offensive / Red Team: in authorized exercises, real-adversary TTPs (C2 frameworks, loaders, evasion) are emulated to test defenses. The goal is to measure detection and response, not cause damage.
- Analysis / Blue Team: given a suspicious sample, the analyst determines what it does, how, and how to detect/contain it. It’s the direct application of reversing (see Introduction to Reversing).
This wiki prioritizes analysis and understanding techniques to defend; offensive use is limited to authorized environments (red team with scope).
The analysis environment (essential)
Section titled “The analysis environment (essential)”Analyzing malware involves handling (and sometimes running) dangerous code. Never on your real machine:
# isolated labdedicated VM (snapshots), isolated or simulated networkREMnux Linux distro for malware analysis (preinstalled tools)FLARE VM Windows environment for analysis (Mandiant)# simulated network for dynamic analysis (see mal-dynamic)INetSim / FakeNet fake the Internet to capture what the malware tries to contact# never connect the lab to your real network/Internet without controlAnalysis workflow
Section titled “Analysis workflow”1. Triage hash, VirusTotal, file type, strings (without running)2. Static disassemble/decompile, imports, encrypted strings (see mal-static)3. Dynamic run in an isolated sandbox, observe behavior (see mal-dynamic)4. Deobfuscate bypass packing/obfuscation (see mal-obfus)5. Extract IOCs C2 domains/IPs, hashes, mutexes, registry keys6. Signatures write YARA/Sigma rules for detection (see mal-yara)7. Report TTPs (map to MITRE ATT&CK), IOCs, remediationFor the defense
Section titled “For the defense”- Modern EDR/AV (behavior detection, not just signatures), application allowlisting (AppLocker/WDAC).
- Segmentation, least privilege, patching (closes entry paths), offline backups (see Ransomware (analysis and defense)).
- Threat intelligence: consume IOCs and TTPs; behavior detection (Sigma, EDR) over hashes.
- Anti-phishing training (the #1 entry vector), MFA, and an incident-response process (see dfir).
Testing checklist
Section titled “Testing checklist”- Set up an isolated lab (REMnux/FLARE VM, simulated network)
- Triage: hash, VirusTotal, file, strings
- Classify the malware type and its likely goal
- Static analysis (Static Malware Analysis)
- Dynamic analysis in a sandbox (Dynamic Malware Analysis)
- Deobfuscate/unpack if applicable (Obfuscation and Packing)
- Extract IOCs and map TTPs to MITRE ATT&CK
- Write detection (YARA/Sigma, YARA Rules)