Malware Triage
Read it. Run it. Say what you know.
Triage is a verdict delivered under time pressure on incomplete evidence, and the recurring failure is stating it more strongly than the evidence supports. This course teaches the techniques and the wording together, because every one of them fails by returning less output rather than wrong output, and less output reads as reassurance. A clean reputation result, a thin capability profile, a quiet sandbox run and an empty hunt are four measurements that found nothing, presented in the same shape as four measurements that found nothing to worry about.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: The Discipline
What Malware Triage teaches: taking an unknown file and producing a verdict somebody can act on, under time pressure, without reverse engineering it. Static examination, capability mapping, reputation, detonation, indicators, and the honest limits of each. Start here.
What a triage verdict is answering, how long you actually have and what that buys, the classes of thing that arrive in a queue, evidence integrity applied rather than described, and the first pass that decides whether a sample deserves the next twenty minutes.
Phase 2: Reading the File
Everything a file will tell you about itself before it runs: what it actually is, how it was compiled and prepared, whether it is packed, what a signature is worth, and the strings it did and did not intend you to see.
What a program can do, named and mapped to ATT&CK, from code that has never run. The technique most triage workflows omit, what its results are worth, and where it stops.
Phase 3: Outside and Running It
What other people already know: hash lookups, detection counts and what they establish, sample repositories, the submission decision, and the arithmetic of a clean result.
Running the sample yourself: the environment, what to capture, reading a behavioral report, and separating a sample that did nothing from one that decided not to.
Phase 4: Output and Practice
Turning a verdict into something deployable: what to extract, which values survive the next build, writing a rule that holds, and handing over indicators somebody can actually use.
Running triage as a function rather than performing it once: the queue, the handoff, the boundary where triage stops, and what a triage practice looks like when it is working.
Phase 0: Course Resources
Six lookup pages for the commands that decide a triage item: identification, static reading, capability, reputation, detonation and indicators, each with what the result carries and what it does not.
Show 6 lessonsHide lessons
Six runbooks for the procedures this work repeats: the four-minute pass, a novel sample, a packed one, an item feeding an incident, a sample that will not run, and the escalation.
Triage items reasoned end to end, including the ones that finish with a weaker verdict than the evidence first suggested and the one where the tooling was working perfectly and the reading was wrong.
Every practice surface available for this course, what each one gives you, where the gaps are, and the exercises worth building yourself.
Every command, verdict field, format and check from the Malware Triage course in one place, organized by task and linked back to the section that explains when not to use it.
Show 1 lessonHide lessons
The tools, documentation, sample sources and standards this course draws on, with what each is good for and where it goes stale.
Course Completion
Malware Triage end-of-course exam: a sample where every automated check is clean, testing whether you can establish capability statically, explain why four honest results were all wrong, and produce a verdict somebody else can evaluate.
Show 1 lessonHide lessons
Course overview
Malware triage is taught almost everywhere as a tour of tools, which produces analysts who can run a scanner and cannot say what its result covers. This course teaches the tools and the reasoning together, because on this discipline they are the same skill: zero of seventy-two engines is a fact about a corpus rather than about a file, a four-item capability profile on a packed sample is an accurate description of a wrapper, and a sandbox run where nothing happened is indistinguishable from one where the sample decided not to. Learn how to:
By the end you will work a queue the way somebody accountable for its verdicts does, with an honest account of what a file can and cannot tell you.
How this course works
Triage is not analysis. The question is whether this file needs a reverse engineer, answered in minutes with a verdict somebody can act on. This course runs the same loop for every sample it examines.
1. Establish what the file is before what it does. Format, size, signing state, packing. Half of triage verdicts are reachable without running anything.
2. Read capability from the structure. Imports, strings, sections and resources describe what the file is equipped to do, which bounds what it could have done.
3. Check reputation, and know what a miss means. An unknown hash is not a clean hash. It is a file nobody has submitted, which for a targeted sample is expected.
4. Detonate only when static triage has run out. Detonation is slow, evadable and produces the most convincing wrong answer available. It is the last step, not the first.
5. Produce indicators and a verdict together. A verdict with no indicators cannot be actioned. Indicators with no verdict get ignored in a queue.
What this course assumes
No minimum experience and no prerequisite course. File formats, the PE structure, packing and the sandbox model are explained where they first matter.
What makes it go faster: an isolated virtual machine you are willing to break. Not required for most of the course, and every sample is examined with its output shown.
What this course does not cover: reverse engineering, debugging and unpacking as disciplines. This course is about deciding whether a sample needs those, quickly and defensibly, which is a different job.
Who this course is for
You are a SOC analyst, incident responder, threat hunter, or the person a suspicious attachment gets forwarded to. No reverse engineering experience is assumed and none is taught, because triage stops where reverse engineering starts and this course tells you where that line is. This course is for you if you want to:
If suspicious files reach you and the verdict is yours to write, this course is for you.
What you'll learn
Seven modules, working from the verdict you are producing to running triage as a function rather than an item.
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None. No reverse engineering, assembly or malware analysis experience is assumed, and every concept is explained where it is first used. If suspicious files have ever reached your queue you will recognize the problems this course solves.
Do I need live malware to follow along?
No, and the course was built that way deliberately. The four specimens it works are buildable rather than downloadable: the first takes two minutes from any small Windows binary, a packer and a rename, and it carries the same properties the sections read while being a file you know is harmless. Holding that alongside the fact that no corpus can distinguish it from a targeted payload is one of the better exercises in the course.
What about handling real samples?
Possession of live malware is a matter of jurisdiction and employer policy, and a training course is the wrong place to decide that for you. The course teaches the isolation, provenance and handling discipline that decision requires, states plainly where the legal question sits, and does not recommend a sample source.
What tools does this use?
Free and open ones throughout: Detect It Easy, pefile, FLOSS, capa, YARA, osslsigncode, UPX, and the free tiers of VirusTotal, MalwareBazaar and public sandboxes. Nothing in the course requires a commercial license.
Is this course current?
Every command, field name and invocation was checked at the time of writing. Tool output formats change, capa's rule set is versioned, and reputation APIs revise their fields, so the references module names what to check first when something behaves differently from the page.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
Samples, outputs and scenarios are illustrative and use the fictional Northgate Engineering environment. Verify against your own tooling before relying on any specific behavior, and treat what your own commands actually return as authoritative over any document, including this one.
Nothing in this course is legal advice. Whether you may acquire, store or submit malware samples depends on your jurisdiction and your employer, and that question belongs with somebody who can authorize an answer.
Ridgeline Cyber is not affiliated with any tool vendor named here. Product names are used descriptively.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.