courses

CS 492/592: Malware Reverse Engineering

Location: FAB 48 (TR 09:00-10:40)

Instructor: D. Kevin McGrath

TA: Chris Lu

Code Party:

Syllabus

Schedule (SUBJECT TO CHANGE – CHECK REGULARLY)

Instruction runs 28 September – 6 December 2026, and finals week is 7–11 December. The university is closed on Thursday 26 November (Thanksgiving), so Week 9 has a single meeting. Week numbers link to that week’s pages below.

Week Meetings (TR) Topic Learning Activities Due (23:59:59)
1 Sep 29, Oct 1 Introduction, lab environment, ethics/legal    
2 Oct 6, Oct 8 Malware triage and file identification HW1  
3 Oct 13, Oct 15 Static analysis: PE/ELF structure   HW1 — Mon Oct 12
4 Oct 20, Oct 22 Static analysis: IDA Classroom and Cutter HW2  
5 Oct 27, Oct 29 Dynamic analysis: sandboxes and tracing HW3  
6 Nov 3, Nov 5 Dynamic analysis: network behavior   HW2 — Mon Nov 2
7 Nov 10, Nov 12 Anti-analysis techniques HW4 HW3 — Mon Nov 9
8 Nov 17, Nov 19 Malware families: ransomware, RATs, rootkits   HW4 — Mon Nov 16
9 Nov 24 only
(Nov 26 — Thanksgiving, university closed)
YARA rules; shellcode analysis    
10 Dec 1, Dec 3 Fuzzing (AFL++, libFuzzer), C vulnerabilities, and symbolic execution (angr) HW5 HW5 — Fri Dec 4
Finals Dec 7–11
no class meeting
No lecture; no office hours Final project Final project — Fri Dec 11

*Explorations are ungraded learning activities that typically involve a hands-on activity related to the current topic.

Pages

Lecture content

Week 1 — Introduction and Lab Environment

Week 2 — Malware Triage and File Identification

Week 3 — Static Analysis: PE/ELF Structure and x86 Assembly

Week 4 — Reverse Engineering Platforms

Week 5 — Dynamic Analysis

Week 6 — Malware Network Behavior

Week 7 — Anti-Analysis Techniques

Week 8 — Malware Families

Week 9 — YARA Rules and Shellcode Analysis

Week 10 — Fuzzing and Symbolic Execution

Other stuff

Analysis Environment

Homework

All homework is submitted via a private GitLab repo on gitlab.cecs.pdx.edu. Add dmcgrath and chlu as developer or higher. Each assignment should be in its own folder (e.g., hw1/) with a hw1.md file and any supporting files.

Previous Offerings