Malware Triage

Read it. Run it. Say what you know.

Triage is a verdict delivered under time pressure on incomplete evidence, and the recurring failure is stating it more strongly than the evidence supports. This course teaches the techniques and the wording together, because every one of them fails by returning less output rather than wrong output, and less output reads as reassurance. A clean reputation result, a thin capability profile, a quiet sandbox run and an empty hunt are four measurements that found nothing, presented in the same shape as four measurements that found nothing to worry about.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 10 CPE Credits

What you'll be able to do

Produce a verdict that states what it rests on and what it does not, in six fields somebody else can evaluate six weeks later
Read a file's structure against an ordinary binary: sections, entropy, imports, signatures, and the packing that makes every later result describe a wrapper
Recover what an author hid with FLOSS and read what they could not avoid leaving with capa, mapped to ATT&CK in a form a hunter can act on
Read a reputation result properly, including the clean one: why age and volume make a zero interpretable and why searching a hash is not submitting a file
Run a sample in an environment you have proved isolated, capture what matters, and tell a sample that did nothing from one that decided not to
Extract indicators ordered by what it costs the actor to change them, write a YARA rule that survives a recompile, and test it where it counts
Run triage as a function rather than an item: order a queue, recognize the three boundaries early, write a handoff that transfers your hour, and audit your own closures
FOR203 | Premium tier | 7 modules across 4 phases | 10–12 hours at your own pace | 10 CPE credits | Updated August 2026
Course Agenda View Course ModulesHide Course Modules

Course overview

Malware triage is taught almost everywhere as a tour of tools, which produces analysts who can run a scanner and cannot say what its result covers. This course teaches the tools and the reasoning together, because on this discipline they are the same skill: zero of seventy-two engines is a fact about a corpus rather than about a file, a four-item capability profile on a packed sample is an accurate description of a wrapper, and a sandbox run where nothing happened is indistinguishable from one where the sample decided not to. Learn how to:

Produce a verdict in six fields that states what it rests on and what it does not
Read a file's structure against an ordinary binary, because normal is what makes abnormal visible
Separate what a sample is equipped to do from what it actually did, and keep them separate in writing
Run a sample in an environment you have proved isolated, and read the report against what you expected
Extract indicators ordered by what it costs the actor to change them, and hunt them with a denominator attached

By the end you will work a queue the way somebody accountable for its verdicts does, with an honest account of what a file can and cannot tell you.

Who this course is for

You are a SOC analyst, incident responder, threat hunter, or the person a suspicious attachment gets forwarded to. No reverse engineering experience is assumed and none is taught, because triage stops where reverse engineering starts and this course tells you where that line is. This course is for you if you want to:

Close a file in four minutes and be able to defend the closure six weeks later
Stop reading a clean scanner result as evidence that a file is safe
Know when a sample is beyond triage, early, rather than after an afternoon of trying things
Hand a finding to a responder or a detection engineer in a form they can act on without asking you anything

If suspicious files reach you and the verdict is yours to write, this course is for you.

What you'll learn

Seven modules, working from the verdict you are producing to running triage as a function rather than an item.

Write the six-field verdict, record provenance at intake, and run a first pass that closes most items in four minutes
Identify a file properly, read its sections, entropy and imports, and recognize what packing does to every later result
Read a signature as three separate claims, and recover with FLOSS what plain string extraction cannot see
Use capability analysis to answer the question an import table cannot, and map it to ATT&CK in a form a hunter can act on
Read a reputation result by its history fields rather than its ratio, and know why searching a hash is not submitting a file
Build an analysis environment you have proved isolated, and take a memory image the sample could not interfere with
Tell a sample that did nothing from one that detected the environment and declined, using evidence outside the report
Order indicators by cost to the adversary, write a YARA rule that survives a recompile, and test it where it counts
Run a queue: order it, timebox it, recognize the three boundaries early, and audit your own closed items

Key course takeaways

Work a file end to end, from an attachment somebody forwarded to a verdict a colleague can evaluate without you in the room
Know the four sentences that claim more than their evidence, and the specific reading that produces each one
Never treat an empty result as a finding until the check has been proved capable of returning one, which is the idea in this course that transfers furthest
Carry six runbooks and six worked cases for the situations this work repeats, including the ones that end in a weaker verdict than the evidence first suggested
Recognize where triage stops, because a discipline that feeds three others is only as useful as its honesty about its own edges

Things you need to know

What are the prerequisites for this course?

None. No reverse engineering, assembly or malware analysis experience is assumed, and every concept is explained where it is first used. If suspicious files have ever reached your queue you will recognize the problems this course solves.

Do I need live malware to follow along?

No, and the course was built that way deliberately. The four specimens it works are buildable rather than downloadable: the first takes two minutes from any small Windows binary, a packer and a rename, and it carries the same properties the sections read while being a file you know is harmless. Holding that alongside the fact that no corpus can distinguish it from a targeted payload is one of the better exercises in the course.

What about handling real samples?

Possession of live malware is a matter of jurisdiction and employer policy, and a training course is the wrong place to decide that for you. The course teaches the isolation, provenance and handling discipline that decision requires, states plainly where the legal question sits, and does not recommend a sample source.

What tools does this use?

Free and open ones throughout: Detect It Easy, pefile, FLOSS, capa, YARA, osslsigncode, UPX, and the free tiers of VirusTotal, MalwareBazaar and public sandboxes. Nothing in the course requires a commercial license.

Is this course current?

Every command, field name and invocation was checked at the time of writing. Tool output formats change, capa's rule set is versioned, and reputation APIs revise their fields, so the references module names what to check first when something behaves differently from the page.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Samples, outputs and scenarios are illustrative and use the fictional Northgate Engineering environment. Verify against your own tooling before relying on any specific behavior, and treat what your own commands actually return as authoritative over any document, including this one.

Nothing in this course is legal advice. Whether you may acquire, store or submit malware samples depends on your jurisdiction and your employer, and that question belongs with somebody who can authorize an answer.

Ridgeline Cyber is not affiliated with any tool vendor named here. Product names are used descriptively.

Version and changelog

Version 1.0 · August 2026

Initial release as a full course, replacing the earlier short course. Seven modules covering the triage discipline, static examination, capability analysis, reputation and intelligence, detonation, indicators and detection, and the verdict and the queue, with a course orientation and a reference layer of cheatsheets, runbooks, worked cases, a playground, an operational reference and further reading.

Research-gated against the documentation for each tool taught, MITRE ATT&CK, and the Malware Behavior Catalog.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.