← All 186 courses
SEC-407 Security

Malware Analysis & Triage for Defenders

Answer the three questions a SOC has about a suspicious file: what it does, what it touched, and how to detect it again. Learners work inside an isolated lab with disciplined sample handling, run static triage across file structure, strings and packing indicators, then observe process, file, registry and network behaviour under controlled detonation. Findings become extracted indicators, tested YARA and Sigma rules, and an evidence record the incident case can be built on.

B4Professional
6modules
42skill atoms
2role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Safe Handling & Lab Architecture7 skill atoms
isolated analysis network with no production reachabilityvirtual machine snapshots and clean restore pointshypervisor escape and analyst workstation risksample encryption, password-protected archives and transfer disciplinechain of custody from the moment of collectionlegal and data-handling constraints on customer sampleslab hygiene checklist before and after every run
2Triage Workflow & Sandbox Methodology7 skill atoms
the triage questions a SOC actually needs answeredautomated sandbox detonation and reading its report criticallyanti-analysis and sandbox evasion indicators to expectdetonation timeouts and dormant sample behaviourpublic multi-scanner submission and the disclosure risk it carrieswhen to escalate from triage to deep analysistime-boxing analysis against live incident pressure
3Static Triage7 skill atoms
file type identification beyond the extensionPE, ELF and Office document structure reviewsection entropy and packing indicatorsimport table and API usage as capability hintsembedded strings, URLs and configuration fragmentsmacro, script and OLE object inspection in documentshashing and fuzzy hashing with imphash and ssdeep
4Behavioural Observation7 skill atoms
process creation trees and parent-child anomaliesfile system writes, drops and staging directoriesregistry persistence keys and scheduled task creationservice installation and autorun locationsprocess injection and suspicious memory region indicatorstoken and privilege activity worth recordingseparating installer noise from malicious behaviour
5Network & Indicator Extraction7 skill atoms
command and control beaconing patterns, intervals and jitterDNS resolution behaviour and domain generation indicatorsTLS certificate and JA3 style fingerprintsextracted configuration such as C2 hosts and campaign identifiersindicator confidence tiering and expirypyramid of pain applied to what you extractedfalse positive risk from shared hosting infrastructure
6Detection Authoring & Case Record7 skill atoms
YARA rules built on stable strings and structurestesting rules against a known-good corpus before shippingSigma rules for the observed host and network behaviourATT&CK technique mapping of observed activityanalysis report format the incident record can consumeindicator sharing through MISP and STIX/TAXIIretesting rules as the family evolves
Where it fits

SEC-407 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

SOC Analyst

Professional stage
SEC-406SEC-407SEC-402

OT / ICS Security Engineer

Professional stage
SEC-206SEC-407SEC-402

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-407 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free