Malware Triage

Read it. Run it. Say what you know.

Triage is a verdict delivered under time pressure on incomplete evidence, and the recurring failure is stating it more strongly than the evidence supports. This course teaches the techniques and the wording together, because every one of them fails by returning less output rather than wrong output, and less output reads as reassurance. A clean reputation result, a thin capability profile, a quiet sandbox run and an empty hunt are four measurements that found nothing, presented in the same shape as four measurements that found nothing to worry about.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 12 CPE Credits

What you'll be able to do

✓Produce a verdict that states what it rests on and what it does not, in six fields somebody else can evaluate six weeks later
✓Read a file's structure against an ordinary binary: sections, entropy, imports, signatures, and the packing that makes every later result describe a wrapper
✓Recover what an author hid with FLOSS and read what they could not avoid leaving with capa, mapped to ATT&CK in a form a hunter can act on
✓Read a reputation result properly, including the clean one: why age and volume make a zero interpretable and why searching a hash is not submitting a file
✓Run a sample in an environment you have proved isolated, capture what matters, and tell a sample that did nothing from one that decided not to
✓Extract indicators ordered by what it costs the actor to change them, write a YARA rule that survives a recompile, and test it where it counts
✓Run triage as a function rather than an item: order a queue, recognize the three boundaries early, write a handoff that transfers your hour, and audit your own closures
FOR203 | Premium tier | 7 modules across 4 phases | 10–12 hours at your own pace | 12 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: The Discipline

Module 0Course OrientationCourse Preview

What Malware Triage teaches: taking an unknown file and producing a verdict somebody can act on, under time pressure, without reverse engineering it. Static examination, capability mapping, reputation, detonation, indicators, and the honest limits of each. Start here.

Show 7 lessonsHide lessons
  1. 0.10.1 What Triage Actually IsPreview
  2. 0.20.2 How This Course Is StructuredPreview
  3. 0.30.3 The Environment You Will BuildPreview
  4. 0.40.4 Where This Shows UpPreview
  5. 0.50.5 What It Cannot DoPreview
  6. 0.60.6 Following AlongPreview
  7. 0.7Module SummaryPreview
Module 1The Triage Discipline

What a triage verdict is answering, how long you actually have and what that buys, the classes of thing that arrive in a queue, evidence integrity applied rather than described, and the first pass that decides whether a sample deserves the next twenty minutes.

Show 8 lessonsHide lessons
  1. 1.11.1 The Verdict You Are Producing
  2. 1.21.2 What the Clock Buys You
  3. 1.31.3 What Arrives, and What Each Class Implies
  4. 1.41.4 Provenance and Integrity
  5. 1.51.5 The First Pass
  6. 1.61.6 Writing the Disposition
  7. 1.7Module Summary
  8. 1.8Check My Knowledge

Phase 2: Reading the File

Module 2Static Examination

Everything a file will tell you about itself before it runs: what it actually is, how it was compiled and prepared, whether it is packed, what a signature is worth, and the strings it did and did not intend you to see.

Show 8 lessonsHide lessons
  1. 2.12.1 Identification, Properly
  2. 2.22.2 Reading the Structure
  3. 2.32.3 Packing and Entropy
  4. 2.42.4 Signatures and Trust
  5. 2.52.5 Strings
  6. 2.62.6 Putting the Static Picture Together
  7. 2.7Module Summary
  8. 2.8Check My Knowledge
Module 3Capability

What a program can do, named and mapped to ATT&CK, from code that has never run. The technique most triage workflows omit, what its results are worth, and where it stops.

Show 8 lessonsHide lessons
  1. 3.13.1 The Question Imports Could Not Answer
  2. 3.23.2 Running capa and Reading the Output
  3. 3.33.3 ATT&CK and the Malware Behavior Catalog
  4. 3.43.4 Reading a Profile
  5. 3.53.5 Where Capability Analysis Stops
  6. 3.63.6 Capability in the Verdict
  7. 3.7Module Summary
  8. 3.8Check My Knowledge

Phase 3: Outside and Running It

Module 4Reputation and Intelligence

What other people already know: hash lookups, detection counts and what they establish, sample repositories, the submission decision, and the arithmetic of a clean result.

Show 8 lessonsHide lessons
  1. 4.14.1 What a Lookup Establishes
  2. 4.24.2 Reading a Detection Count
  3. 4.34.3 The Clean Result
  4. 4.44.4 Submission Is a Disclosure
  5. 4.54.5 Beyond the Multi-Scanner
  6. 4.64.6 Reputation in the Verdict
  7. 4.7Module Summary
  8. 4.8Check My Knowledge
Module 5Detonation

Running the sample yourself: the environment, what to capture, reading a behavioral report, and separating a sample that did nothing from one that decided not to.

Show 8 lessonsHide lessons
  1. 5.15.1 What Detonation Actually Establishes
  2. 5.25.2 The Environment
  3. 5.35.3 Running It
  4. 5.45.4 Reading the Report
  5. 5.55.5 The Sample That Decided Not to Run
  6. 5.65.6 Detonation in the Verdict
  7. 5.7Module Summary
  8. 5.8Check My Knowledge

Phase 4: Output and Practice

Module 6Indicators and Detection

Turning a verdict into something deployable: what to extract, which values survive the next build, writing a rule that holds, and handing over indicators somebody can actually use.

Show 8 lessonsHide lessons
  1. 6.16.1 What an Indicator Is For
  2. 6.26.2 The Durability Ordering
  3. 6.36.3 Extracting From What You Have
  4. 6.46.4 Writing a Rule That Holds
  5. 6.56.5 What a Negative Result Establishes
  6. 6.66.6 Indicators in the Verdict and the Handoff
  7. 6.7Module Summary
  8. 6.8Check My Knowledge
Module 7The Verdict and the Queue

Running triage as a function rather than performing it once: the queue, the handoff, the boundary where triage stops, and what a triage practice looks like when it is working.

Show 8 lessonsHide lessons
  1. 7.17.1 The Verdict, Assembled
  2. 7.27.2 Running a Queue
  3. 7.37.3 Where Triage Stops
  4. 7.47.4 The Handoff
  5. 7.57.5 Auditing Your Own Queue
  6. 7.67.6 A Triage Function That Works
  7. 7.7Module Summary
  8. 7.8Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

Six lookup pages for the commands that decide a triage item: identification, static reading, capability, reputation, detonation and indicators, each with what the result carries and what it does not.

Show 6 lessonsHide lessons
  1. 1Identification and Preparation
  2. 2Reading the Structure
  3. 3Strings and Capability
  4. 4Reputation
  5. 5Detonation
  6. 6Indicators and Rules
ResourcesCookbooks

Six runbooks for the procedures this work repeats: the four-minute pass, a novel sample, a packed one, an item feeding an incident, a sample that will not run, and the escalation.

Show 6 lessonsHide lessons
  1. 1The Four-Minute Pass
  2. 2A Sample Nobody Has Seen
  3. 3A Packed Sample
  4. 4An Item Feeding an Incident
  5. 5A Sample That Will Not Run
  6. 6Writing the Escalation
ResourcesWalkthroughs

Triage items reasoned end to end, including the ones that finish with a weaker verdict than the evidence first suggested and the one where the tooling was working perfectly and the reading was wrong.

Show 6 lessonsHide lessons
  1. 1The File That Was Clean
  2. 2The Profile That Described a Stub
  3. 3The Sample That Did Nothing
  4. 4The Process That Was Still Running
  5. 5The Hunt That Covered Eight Hundred
  6. 6The Item That Should Have Been Escalated
ResourcesPlayground

Every practice surface available for this course, what each one gives you, where the gaps are, and the exercises worth building yourself.

ResourcesOperational Reference

Every command, verdict field, format and check from the Malware Triage course in one place, organized by task and linked back to the section that explains when not to use it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences and Further Reading

The tools, documentation, sample sources and standards this course draws on, with what each is good for and where it goes stale.

Course Completion

CompletionCourse Exam

Malware Triage end-of-course exam: a sample where every automated check is clean, testing whether you can establish capability statically, explain why four honest results were all wrong, and produce a verdict somebody else can evaluate.

Show 1 lessonHide lessons
  1. 1Course Completion. Malware Triage

Course overview

Malware triage is taught almost everywhere as a tour of tools, which produces analysts who can run a scanner and cannot say what its result covers. This course teaches the tools and the reasoning together, because on this discipline they are the same skill: zero of seventy-two engines is a fact about a corpus rather than about a file, a four-item capability profile on a packed sample is an accurate description of a wrapper, and a sandbox run where nothing happened is indistinguishable from one where the sample decided not to. Learn how to:

✓ Produce a verdict in six fields that states what it rests on and what it does not
✓ Read a file's structure against an ordinary binary, because normal is what makes abnormal visible
✓ Separate what a sample is equipped to do from what it actually did, and keep them separate in writing
✓ Run a sample in an environment you have proved isolated, and read the report against what you expected
✓ Extract indicators ordered by what it costs the actor to change them, and hunt them with a denominator attached

By the end you will work a queue the way somebody accountable for its verdicts does, with an honest account of what a file can and cannot tell you.

How this course works

Triage is not analysis. The question is whether this file needs a reverse engineer, answered in minutes with a verdict somebody can act on. This course runs the same loop for every sample it examines.

1. Establish what the file is before what it does. Format, size, signing state, packing. Half of triage verdicts are reachable without running anything.

2. Read capability from the structure. Imports, strings, sections and resources describe what the file is equipped to do, which bounds what it could have done.

3. Check reputation, and know what a miss means. An unknown hash is not a clean hash. It is a file nobody has submitted, which for a targeted sample is expected.

4. Detonate only when static triage has run out. Detonation is slow, evadable and produces the most convincing wrong answer available. It is the last step, not the first.

5. Produce indicators and a verdict together. A verdict with no indicators cannot be actioned. Indicators with no verdict get ignored in a queue.

What this course assumes

No minimum experience and no prerequisite course. File formats, the PE structure, packing and the sandbox model are explained where they first matter.

What makes it go faster: an isolated virtual machine you are willing to break. Not required for most of the course, and every sample is examined with its output shown.

What this course does not cover: reverse engineering, debugging and unpacking as disciplines. This course is about deciding whether a sample needs those, quickly and defensibly, which is a different job.

Who this course is for

You are a SOC analyst, incident responder, threat hunter, or the person a suspicious attachment gets forwarded to. No reverse engineering experience is assumed and none is taught, because triage stops where reverse engineering starts and this course tells you where that line is. This course is for you if you want to:

✓ Close a file in four minutes and be able to defend the closure six weeks later
✓ Stop reading a clean scanner result as evidence that a file is safe
✓ Know when a sample is beyond triage, early, rather than after an afternoon of trying things
✓ Hand a finding to a responder or a detection engineer in a form they can act on without asking you anything

If suspicious files reach you and the verdict is yours to write, this course is for you.

What you'll learn

Seven modules, working from the verdict you are producing to running triage as a function rather than an item.

✓ Write the six-field verdict, record provenance at intake, and run a first pass that closes most items in four minutes
✓ Identify a file properly, read its sections, entropy and imports, and recognize what packing does to every later result
✓ Read a signature as three separate claims, and recover with FLOSS what plain string extraction cannot see
✓ Use capability analysis to answer the question an import table cannot, and map it to ATT&CK in a form a hunter can act on
✓ Read a reputation result by its history fields rather than its ratio, and know why searching a hash is not submitting a file
✓ Build an analysis environment you have proved isolated, and take a memory image the sample could not interfere with
✓ Tell a sample that did nothing from one that detected the environment and declined, using evidence outside the report
✓ Order indicators by cost to the adversary, write a YARA rule that survives a recompile, and test it where it counts
✓ Run a queue: order it, timebox it, recognize the three boundaries early, and audit your own closed items

Key course takeaways

✓ Work a file end to end, from an attachment somebody forwarded to a verdict a colleague can evaluate without you in the room
✓ Know the four sentences that claim more than their evidence, and the specific reading that produces each one
✓ Never treat an empty result as a finding until the check has been proved capable of returning one, which is the idea in this course that transfers furthest
✓ Carry six runbooks and six worked cases for the situations this work repeats, including the ones that end in a weaker verdict than the evidence first suggested
✓ Recognize where triage stops, because a discipline that feeds three others is only as useful as its honesty about its own edges

Things you need to know

What are the prerequisites for this course?

None. No reverse engineering, assembly or malware analysis experience is assumed, and every concept is explained where it is first used. If suspicious files have ever reached your queue you will recognize the problems this course solves.

Do I need live malware to follow along?

No, and the course was built that way deliberately. The four specimens it works are buildable rather than downloadable: the first takes two minutes from any small Windows binary, a packer and a rename, and it carries the same properties the sections read while being a file you know is harmless. Holding that alongside the fact that no corpus can distinguish it from a targeted payload is one of the better exercises in the course.

What about handling real samples?

Possession of live malware is a matter of jurisdiction and employer policy, and a training course is the wrong place to decide that for you. The course teaches the isolation, provenance and handling discipline that decision requires, states plainly where the legal question sits, and does not recommend a sample source.

What tools does this use?

Free and open ones throughout: Detect It Easy, pefile, FLOSS, capa, YARA, osslsigncode, UPX, and the free tiers of VirusTotal, MalwareBazaar and public sandboxes. Nothing in the course requires a commercial license.

Is this course current?

Every command, field name and invocation was checked at the time of writing. Tool output formats change, capa's rule set is versioned, and reputation APIs revise their fields, so the references module names what to check first when something behaves differently from the page.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Samples, outputs and scenarios are illustrative and use the fictional Northgate Engineering environment. Verify against your own tooling before relying on any specific behavior, and treat what your own commands actually return as authoritative over any document, including this one.

Nothing in this course is legal advice. Whether you may acquire, store or submit malware samples depends on your jurisdiction and your employer, and that question belongs with somebody who can authorize an answer.

Ridgeline Cyber is not affiliated with any tool vendor named here. Product names are used descriptively.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.