Malware Analysis

Malware analysis is the process of dissecting malicious software to understand how it works, how to identify it, and how to defeat or eliminate it. It is a core skill for incident responders and security professionals.

What Malware Analysts Do

A malware analyst acts as a technical investigator for security incidents. Their main responsibilities include:

  • Determining functionality — figuring out exactly what a malware sample does (e.g., what files it modifies, what network connections it makes).
  • Creating or improving detections — writing better antivirus signatures, network signatures, or behavioral rules.
  • Identifying scope of infection — finding other machines that may be compromised by the same malware family.
  • Ensuring complete removal — confirming that all components of a malware package are deleted, not just one visible file.
  • Communicating findings — translating technical details into answers that management, legal teams, or clients can understand.

The Value of a Malware Analyst

The role is valuable because Malware is involved in most computer intrusions and security incidents. With millions of malware samples in the wild and new variants appearing daily, organizations cannot rely only on automated tools. A skilled analyst can:

  • Reduce dependence on expensive external consultants during incidents.
  • Improve the organization’s ability to respond to threats quickly and accurately.
  • Provide actionable intelligence that strengthens defenses across the network.

The authors note that malware analysis is in high demand, partly because trained analysts are relatively scarce.

Key Mindset

You do not need to be an “uber-hacker” to be effective. Malware analysis is a practical discipline built around a consistent set of tools and techniques. Like other technical skills, it improves with deliberate practice and study.

What This Book Focuses On

This book focuses on:

  • Analyzing malware after it has been found, not finding it in the first place.
  • Windows executables, the most common and difficult type of malware to analyze.
  • Advanced threats such as backdoors, covert malware, and rootkits.

It deliberately avoids malicious scripts and Java programs to focus on executable malware in depth.

Source

Practical Malware Analysis by Michael Sikorski and Andrew Honig, section “What Is Malware Analysis?” (pp. xxviii–29).