Real-World Malware Forensics -> 20 Labs

Manjil Katuwal

profile
Best Seller
Real-World Malware Forensics -> 20 Labs
profile
Digital Product
3Sales

20 real malware labs. One guide. From your first phishing document to extracting a Cobalt Strike beacon config.

This is not a theory course. This is exactly what I do when a malware sample lands in my isolated lab. Every command, every Volatility plugin, every Wireshark filter, every Ghidra step. Rebuilt so you can follow along without guessing.

What is inside

Part 1: Platform Setup and Lab Architecture

Build an isolated, forensically sound lab that SOC directors actually trust. VMware topology, REMnux, Windows 10 LTSC, FakeNet-NG, deception layer to beat sandbox detection, and the exact snapshot strategy to never contaminate your host.

Part 2: Investigation Methodology

The five-phase workflow that separates junior analysts from L3 investigators. Triage. Static. Dynamic. Forensics. Report. With timing benchmarks and the golden rule: observe for five minutes after launch because most malware sleeps before it strikes.

20 Hands-On Labs

Lab 01: Emotet Phishing Analysis (LetsDefend) Extract obfuscated VBA macros, decode the PowerShell download cradle, pull network IOCs from compromised WordPress sites, and write your first YARA rule.

Lab 02: QakBot Memory Forensics (LetsDefend) Use Volatility 3 to find process injection into explorer.exe, dump the injected payload, and extract C2 IPs from netscan.

Lab 03: HTB Recollection (Volatility) Full memory forensics on a compromised host. Registry persistence, hidden processes, and evidence correlation for structured answers.

Lab 04: HTB Reminiscent (PowerShell PCAP) Trace a phishing attack from PCAP to PowerShell Event ID 4104. Decode multi-layer base64 and correlate timestamps across logs and network traffic.

Lab 05: HTB Bumblebee (SQLite Browser Forensics) Chrome artefact analysis. Query History and Login Data databases, convert Windows FILETIME timestamps, and identify the malicious download vector.

Lab 06: CyberDefenders PacketMaze (Network RE) Zeek log analysis, JA3 fingerprinting for C2 identification, and HTTP object extraction with full IOC hashing.

Lab 07: CyberDefenders XL-Macro (Excel 4.0) XLM macro deobfuscation. Excel 4.0 is old but attackers love it because AV misses it. Extract the download cradle from hidden cell formulas.

Lab 08: CyberDefenders BlackEnergy (APT Memory) Kernel-mode rootkit detection. SSDT hooks, hidden drivers with modscan, DKOM process hiding. The same techniques apply to Turla and Lazarus today.

Lab 09: CyberDefenders African Swallow (DNS Tunnel) Detect DNS tunnelling with entropy analysis. Decode base32-exfiltrated data from high-entropy subdomains and reconstruct what was stolen.

Lab 10: CyberDefenders Tomcat Takeover (Web Shell) Apache log analysis, JSP web shell identification, and memory pivoting to find lateral movement spawned by java.exe.

Lab 11: RedLine Stealer Static Analysis (MalwareBazaar) PE analysis, .NET deobfuscation with de4dot and dnSpy, C2 config extraction, and credential theft target mapping without executing a single byte.

Lab 12: AsyncRAT Dynamic Analysis (MalwareBazaar) Controlled execution in x64dbg. API breakpoints, AES config extraction from memory, persistence via registry, and raw TCP beacon decryption in Python.

Lab 13: AgentTesla Deobfuscation Chain (MalwareBazaar) Peel four layers: encoded PowerShell to .NET loader to packed binary to final keylogger. Extract plaintext SMTP credentials used for exfiltration.

Lab 14: IcedID PCAP Decryption (Any.run) Extract the hardcoded RC4 key via static analysis in Ghidra, capture live PCAP, and decrypt the C2 traffic to read actual commands.

Lab 15: Cobalt Strike Beacon Config (Any.run) The skill every IR team needs. Extract beacon configuration from shellcode, identify Malleable C2 profiles, and fingerprint JA3 hashes from TLS traffic.

Lab 16: HTB Unit42 (Log4Shell Forensics) Reconstruct CVE-2021-44228 exploitation from Apache logs and LDAP callbacks. Full ATT&CK mapping from initial access to web shell.

Lab 17: CyberDefenders PoisonedCredentials (AD Attack) Kerberoasting, Pass-the-Hash, and DCSync detection purely from Windows Event IDs. Know exactly what to hunt for in Security logs.

Lab 18: Ransomware Crypto Weakness (MalwareBazaar) Assess PRNG quality, find weak seeds like GetTickCount, detect partial encryption, and determine if decryption without ransom is possible.

Lab 19: HTB OpTinselTrace (Supply Chain) Binary diffing with BinDiff, trojanised software analysis, certificate pivoting, and tracing CI/CD compromise artefacts.

Lab 20: Capstone: Full IR to STIX Report End-to-end incident response. From PCAP and memory image to YARA rules, Sigma rules, ATT&CK matrix, and a complete STIX 2.1 intelligence bundle.

Appendices

Appendix A: Master Tool Cheatsheet Every tool, every key command, every source link. Volatility, x64dbg, Ghidra, Wireshark, Zeek, CAPA, olevba, de4dot, dnSpy, CobaltStrikeParser, YARA, Sigma, stix2.

Appendix B: Interview Answer Templates Exactly what to say when a SOC director asks: "Walk me through how you analyse a suspicious executable." "How do you detect process injection in memory?" "You find a Cobalt Strike beacon, what do you do?" "How do you detect DNS tunnelling?"

Appendix C: 30-60-90 Day Learning Roadmap Week-by-week platform rotation. Days 1-7 setup and triage. Days 8-14 memory forensics. Days 15-30 network and C2. Days 31-60 Cobalt Strike and AD attacks. Days 61-90 supply chain and capstone. Plus advanced gaps to fill after the 90 days.

Who this is for

L2 analysts ready to move into L3 investigation and malware research SOC analysts who want to stop running tools blindly and actually understand what the tool is showing them Blue teamers building detection engineering skills with YARA and Sigma Students preparing for GREM, GCIH, eMAPT, or practical malware analysis roles Anyone who wants to walk into an interview and talk through a real lab instead of repeating certification buzzwords

After working through this guide you will be able to

Set up a lab that defeats sandbox detection and produces court-admissible evidence Execute a full five-phase investigation on any malware sample Extract C2 configs from memory without relying on automated sandboxes Write YARA and Sigma rules that actually catch malware in production Produce an IR report with ATT&CK mapping and STIX intelligence that senior analysts respect

50 pages. 20 labs. Zero padding. All field-tested.

What are people saying

Documents where good and best !! Malware labs where true gem 💎
Anonymous
Jun 2026
I was new to cybersecurity career blue roadmap, Manjil walked me through the flowchart it was good session given up . Tools few channels , network packet.
Richard R
Jun 2026
$10$33