Professional Certification Program
Certified Malware Forensics Analyst (CMFA)
Enroll / Inquire Now
Duration
4 Weeks (20 Hours)
Level
Intermediate
Format
Live Virtual & Hands-on Lab Range
Tuition / Fee
र 25,000 INR
The Certified Malware Forensics Analyst (CMFA) program equips incident responders, SOC analysts, and digital forensic investigators with actionable skills to dissect, trace, and attribute malicious software across Windows, Linux, and mobile environments. Participants learn to reconstruct attacker behavior from static binaries, live memory, and network artifacts, and translate technical findings into actionable, court- and client-ready incident reports.
Course Syllabus & Overview
Course Syllabus & Overview
Module 1: Introduction to Malware Analysis
Course overview and objectives
Introduction to malware: definitions and types
Overview of malware analysis: static vs. dynamic analysis
Module 2: Setting Up a Malware Analysis Lab
Creating a safe and isolated analysis environment
Tools and software for malware analysis (virtual machines, sandboxes)
Legal and ethical considerations
Module 3: Static Analysis Techniques
Introduction to static analysis
Analyzing malware without executing it
Tools: strings, PEiD, Binwalk, etc.
Examining file headers and structure
Module 4: Dynamic Analysis Techniques
Introduction to dynamic analysis
Analyzing malware behavior by executing it in a controlled environment
Tools: Process Monitor, Process Explorer, Wireshark
Monitoring system changes and network activity
Module 5: Reverse Engineering Fundamentals
Introduction to reverse engineering
Tools: IDA Pro, Ghidra, OllyDbg
Disassemblers and decompilers
Understanding assembly language basics
Module 6: Advanced Static Analysis
Advanced file analysis techniques
Analyzing obfuscated and packed malware
Techniques for de-obfuscation and unpacking
Tools: UPX, ASPack, PEiD
Module 7: Advanced Dynamic Analysis
Advanced behavior analysis
Analyzing malware network communication
Techniques for bypassing anti-analysis mechanisms
Using honeypots and deception technologies
Module 8: Memory Forensics
Introduction to memory forensics
Analyzing volatile memory for malware artifacts
Tools: Volatility, Rekall
Case studies in memory forensics
Module 9: Malware Evasion Techniques
Understanding how malware evades detection
Anti-debugging and anti-virtualization techniques
Techniques for detecting and defeating evasion tactics
Case studies of evasive malware
Module 10: Network-Based Malware Analysis
Network traffic analysis for malware detection
Tools: Wireshark, Bro/Zeek, Suricata
Analyzing command and control (C2) communication
Case studies in network-based malware analysis
Module 11: Automated Malware Analysis
Introduction to automated malware analysis
Tools: Cuckoo Sandbox, Joe Sandbox
Creating and analyzing automated reports
Limitations of automated analysis
Module 12: Incident Response and Malware Removal
Incident response process for malware infections
Tools for malware removal and system recovery
Developing and implementing mitigation strategies
Case studies in incident response
Practical Labs:
Participants analyze real-world malware samples in an isolated lab environment across the full analysis lifecycle — from static triage through memory forensics and network C2 tracing — and deliver a comprehensive incident response report documenting findings, IOCs, and remediation steps.
Official Certificate Issued Upon Successful Capstone Evaluation
Submit Registration Application