This track builds the analytical skills that underpin everything else we teach. Reverse engineering is the common foundation of malware analysis, vulnerability research and exploit development, and students who complete it are well prepared to move into the vulnerability research and exploitation track.
Malicious Documents Analysis and Non-Binary Analysis are shorter, self-contained courses. They fit naturally between Malware Analysis 1 and 2, but can also be taken independently.
Recommended Order
6 courses · 190 hoursA complete path from reading disassembled code for the first time to analysing modern, heavily protected threats. Assembly comes first; after that, the malware analysis courses build on each other and should be taken in order.
Assembly x64/x86
All the Assembly concepts used in reverse engineering and malware analysis. Students learn the instructions and architectural details required to write and, above all, understand reversed code.
Malware Analysis 1
Introduces the foundations of reverse engineering and malware analysis: the recommended tools, how to retrieve key information from a binary, how to correlate what you find, and how to start an analysis from real artifacts. Includes an overview of the PE format.
Malicious Documents Analysis
Techniques for analysing the malicious documents commonly used as the initial attack vector against companies. Students learn to analyse different document types and extract the indicators of compromise that lead to the next stage of the infection chain.
Non-Binary Analysis
Reverse engineering of non-PE artifacts: .lnk files, obfuscated and encrypted Python, obfuscated PowerShell, JavaScript and other formats. A very practical course built around real-world samples.
Malware Analysis 2
Professional techniques and advanced concepts for analysing threats from several perspectives, starting with building an appropriate analysis infrastructure. Core topics include Windows Internals concepts and extensive work in IDA Pro.
Malware Analysis 3
Advanced analysis of modern threats. Covers sophisticated IDA Pro capabilities including FLIRT signatures and the IDA SDK, followed by IDC and IDA Python taught through mixed concept and practical examples.
Certification
- Blackstorm Reverse Engineering Associate — after Malicious Documents Analysis and Malware Analysis 1
- Blackstorm Reverse Engineering Professional — after Malware Analysis 2
- Blackstorm Reverse Engineering Expert — after Malware Analysis 3
Dates and enrolment
Scheduled dates for every course in this track are listed on the training page, together with format, payment and enrolment details.