Malware Triage
Read it. Run it. Say what you know.
Triage is a verdict delivered under time pressure on incomplete evidence, and the recurring failure is stating it more strongly than the evidence supports. This course teaches the techniques and the wording together, because every one of them fails by returning less output rather than wrong output, and less output reads as reassurance. A clean reputation result, a thin capability profile, a quiet sandbox run and an empty hunt are four measurements that found nothing, presented in the same shape as four measurements that found nothing to worry about.
What you'll be able to do
Course overview
Malware triage is taught almost everywhere as a tour of tools, which produces analysts who can run a scanner and cannot say what its result covers. This course teaches the tools and the reasoning together, because on this discipline they are the same skill: zero of seventy-two engines is a fact about a corpus rather than about a file, a four-item capability profile on a packed sample is an accurate description of a wrapper, and a sandbox run where nothing happened is indistinguishable from one where the sample decided not to. Learn how to:
By the end you will work a queue the way somebody accountable for its verdicts does, with an honest account of what a file can and cannot tell you.
Who this course is for
You are a SOC analyst, incident responder, threat hunter, or the person a suspicious attachment gets forwarded to. No reverse engineering experience is assumed and none is taught, because triage stops where reverse engineering starts and this course tells you where that line is. This course is for you if you want to:
If suspicious files reach you and the verdict is yours to write, this course is for you.
What you'll learn
Seven modules, working from the verdict you are producing to running triage as a function rather than an item.
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None. No reverse engineering, assembly or malware analysis experience is assumed, and every concept is explained where it is first used. If suspicious files have ever reached your queue you will recognize the problems this course solves.
Do I need live malware to follow along?
No, and the course was built that way deliberately. The four specimens it works are buildable rather than downloadable: the first takes two minutes from any small Windows binary, a packer and a rename, and it carries the same properties the sections read while being a file you know is harmless. Holding that alongside the fact that no corpus can distinguish it from a targeted payload is one of the better exercises in the course.
What about handling real samples?
Possession of live malware is a matter of jurisdiction and employer policy, and a training course is the wrong place to decide that for you. The course teaches the isolation, provenance and handling discipline that decision requires, states plainly where the legal question sits, and does not recommend a sample source.
What tools does this use?
Free and open ones throughout: Detect It Easy, pefile, FLOSS, capa, YARA, osslsigncode, UPX, and the free tiers of VirusTotal, MalwareBazaar and public sandboxes. Nothing in the course requires a commercial license.
Is this course current?
Every command, field name and invocation was checked at the time of writing. Tool output formats change, capa's rule set is versioned, and reputation APIs revise their fields, so the references module names what to check first when something behaves differently from the page.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
Samples, outputs and scenarios are illustrative and use the fictional Northgate Engineering environment. Verify against your own tooling before relying on any specific behavior, and treat what your own commands actually return as authoritative over any document, including this one.
Nothing in this course is legal advice. Whether you may acquire, store or submit malware samples depends on your jurisdiction and your employer, and that question belongs with somebody who can authorize an answer.
Ridgeline Cyber is not affiliated with any tool vendor named here. Product names are used descriptively.
Version and changelog
Version 1.0 · August 2026
Initial release as a full course, replacing the earlier short course. Seven modules covering the triage discipline, static examination, capability analysis, reputation and intelligence, detonation, indicators and detection, and the verdict and the queue, with a course orientation and a reference layer of cheatsheets, runbooks, worked cases, a playground, an operational reference and further reading.
Research-gated against the documentation for each tool taught, MITRE ATT&CK, and the Malware Behavior Catalog.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.