CS 492/592: Malware Reverse Engineering
Location: EB 103
Instructor: D. Kevin McGrath
- PDX username: dmcgrath
- Office hours:
- Location: FAB 120-15
- Times:
- Wednesday: Code Party! 18:00 - 22:00 FAB 86-01
- Whenever you see me in my office with the door open
Teaching Assistant: Gatlin Newhouse
- PDX username: gtn
- Office hours:
- Times: TBD
- CS 492/592: Malware Reverse Engineering
- Recorded Lectures
- Pages
- Lecture content
- Week 1 — Introduction and Lab Environment
- Week 2 — Basic Static Analysis
- Week 3 — Advanced Static Analysis
- Week 4 — Reverse Engineering Platforms
- Week 5 — Dynamic Analysis
- Week 6 — Malware Network Behavior
- Week 7 — Anti-Analysis Techniques and Shellcode
- Week 8 — Malware Families
- Week 10 — Fuzzing and Symbolic Execution
- Other stuff
- Analysis Environment
- Useful links for learning
- Lecture content
- Homework
- Previous Offerings
Recorded Lectures
All of these are raw recordings, and have not been edited.
- Week 1 - Lecture 1: no recording
- Week 1 - Lecture 2
- Week 2 - Lecture 1
- Week 2 - Lecture 2: class canceled
- Week 3 - Lecture 1
- Week 3 - Lecture 2
- Week 4 - Lecture 1
- Week 4 - Lecture 2: In class activity, no recording
- Week 5 - Lecture 1
- Week 5 - Lecture 2
- Week 6 - Lecture 1: no recording
- Week 6 - Lecture 2
- Week 7 - Lecture 1
- Week 7 - Lecture 2
- Week 8 - Lecture 1: no recording
- Week 8 - Lecture 2: no recording
- Week 9 - Lecture 1: no recording
- Week 9 - Lecture 2: no recording
- Week 10 - Lecture 1: no recording
- Week 10 - Lecture 2: no recording
Pages
Lecture content
- Using Wine – running Windows malware on Linux
Week 1 — Introduction and Lab Environment
- REMnux Installation
- Malware Triage
- AI-Assisted Analysis: REMnux and Kali MCP Servers
- Using the REMnux MCP Server with Claude Code
Week 2 — Basic Static Analysis
- Static Analysis
- Unix Text Processing: sed and awk – substitution, in-place editing, validation, and pipeline patterns
Week 3 — Advanced Static Analysis
- Advanced Static Analysis: x86, IDA Pro, and C Constructs – summary of PMA Part 2
- Reverse Engineering
Week 4 — Reverse Engineering Platforms
- IDA Classroom: Installation and Licensing
- IDA Pro Cheat Sheet
- Ghidra Cheat Sheet
- Reverse Engineering Platforms: IDA, Ghidra, and Cutter – comprehensive intro to the three main RE platforms
Week 5 — Dynamic Analysis
- Dynamic Analysis
- Advanced Dynamic Analysis – debugger scripting, runtime unpacking, Frida, eBPF/ETW, injection detection
Week 6 — Malware Network Behavior
- Malware Network Behavior Analysis – downloaders, DGA, C2 protocols, credential stealers, exfiltration, FakeNet-NG/INetSim
- Lab: Malware Network Behavior and Network Signatures – Ch. 11 & 14 labs: downloaders, reverse shells, beacon analysis, Snort rules
- Suricata: Network Signatures for Malware Detection – rule syntax, application-layer keywords, HTTP/DNS/TLS detection, EVE JSON
Week 7 — Anti-Analysis Techniques and Shellcode
Week 8 — Malware Families
- Malware Families
- Adversary Models: MITRE ATT&CK and Related Frameworks – ATT&CK, Kill Chain, Diamond Model, D3FEND, ENGAGE, UKC
- APT Groups – definitions, naming conventions (Mandiant/CrowdStrike/Microsoft/MITRE), active groups by nation-state, common TTPs
Week 10 — Fuzzing and Symbolic Execution
- Yara – YARA and YARA-X
- Fuzzing and C Vulnerabilities – AFL++, libFuzzer, ASan, C vulnerability classes
- Symbolic Execution with angr – recovering passwords, triggers, and checksums; bypassing anti-analysis; managing path explosion
Other stuff
- Setup
- Working with Wine
- Hyper-V setup
- Poster-style overviews of binary types (PE, ELF, mach-O, etc.)
Analysis Environment
- REMnux install
- REMnux — Linux distribution for malware analysis (our primary analysis environment)
- REMnux documentation — installation, tools, and usage guides
Useful links for learning
- Malware Traffic Analysis
- Any.run — interactive malware sandbox
- VirusTotal — file/URL scanning
- Hybrid Analysis — free malware analysis
- MalwareBazaar — malware sample repository
- IDA Classroom — free educational edition of IDA Pro (industry standard)
- Cutter — GUI frontend for Rizin
- Rizin — maintained fork of radare2 with cleaner API
- radare2 — open source reverse engineering framework
- Ghidra — open source reverse engineering suite developed by the US National Security Agency (NSA)
- YARA — malware identification/classification
- AFL++ — coverage-guided fuzzer
- angr — binary analysis and symbolic execution framework
- angr CTF — guided angr exercises
- Shell Storm — shellcode database
Homework
All homework is submitted via a private GitLab repo on gitlab.cecs.pdx.edu. Add dmcgrath and gtn as developer or higher. Each assignment should be in its own folder (e.g., hw1/) with a hw1.md file and any supporting files.
Previous Offerings
- None yet