INTERMEDIATE TO ADVANCED
⏱ 20+ WEEKS
100 MODULES
Windows Malware Development
Understand modern offensive tooling by building it
You cannot reliably detect or evade what you do not understand at the implementation level. This course builds Windows offensive tooling from first principles: PE format, memory management, injection, syscalls, and the anti-analysis techniques real samples use. It is aimed at red teamers who need tooling that survives contact with modern defences, and at analysts who want to understand samples from the author's side rather than only the disassembler's. All work is for authorised red team use and defensive research, in isolated lab environments.
👤Who this is for
- →Red teamers whose off-the-shelf tooling keeps getting caught
- →Malware analysts who want to understand samples from the build side
- →Detection engineers who need to know what they are writing signatures against
- →Offensive security researchers building custom capability
⚡Prerequisites
•Solid C or C++ programming ability
•Working knowledge of Windows internals
•Comfortable with a debugger
•An isolated lab environment you control
Curriculum
32 units · 128 topics · 20+ weeks
UNIT 01
Introduction to malware development
✦Course objectives and legal context
✦Lab environment setup (isolated VMs)
✦Development toolchain (Visual Studio, compilers)
✦Debugging fundamentals with x64dbg and WinDbg
UNIT 02
Windows internals: processes and threads
✦Process creation and the PEB
✦Thread architecture and TEB
✦Process and thread enumeration
✦Handle table internals
UNIT 03
Windows internals: memory management
✦Virtual memory and page tables
✦VirtualAlloc, VirtualProtect, and memory regions
✦Heap management and allocators
✦Memory-mapped files and sections
UNIT 04
Windows internals: kernel objects
✦Handles, tokens, and security descriptors
✦Access control and privilege model
✦Object manager internals
✦Interacting with the kernel from user mode
UNIT 05
The Windows API surface
✦Win32 API categories and documentation
✦NTAPI vs Win32 API
✦API resolution and GetProcAddress
✦Dynamic API loading patterns
UNIT 06
PE format fundamentals
✦DOS header and PE signature
✦COFF and optional header fields
✦Section table and section alignment
✦Rich header analysis
UNIT 07
PE format: imports and exports
✦Import Address Table (IAT)
✦Import Name Table and thunking
✦Export directory and ordinal resolution
✦Delayed imports and API sets
UNIT 08
PE format: relocations and resources
✦Base relocation table processing
✦Position-independent code principles
✦Resource directory structure
✦Embedding and extracting PE resources
UNIT 09
DLL internals
✦DLL loading with LoadLibrary
✦DllMain entry points and thread notifications
✦DLL search order and hijacking
✦DLL proxying and forwarding
UNIT 10
Shellcode fundamentals
✦Position-independent shellcode design
✦Avoiding null bytes and bad characters
✦Shellcode encoding techniques
✦Custom shellcode from scratch in assembly
UNIT 11
Payload encryption: XOR and RC4
✦XOR encryption and brute-force concerns
✦Multi-byte XOR key generation
✦RC4 stream cipher implementation
✦Encrypting and decrypting payloads at runtime
UNIT 12
Payload encryption: AES
✦AES-256 CBC implementation with CNG
✦Key derivation and IV management
✦Encrypting shellcode for staged delivery
✦Decryption stubs and in-memory execution
UNIT 13
String obfuscation and entropy
✦Compile-time string encryption
✦Stack string construction
✦API hashing (djb2, CRC32, custom)
✦Entropy analysis and management
UNIT 14
Payload staging and delivery
✦Staged vs stageless payloads
✦HTTP/S payload download and execution
✦UUID and MAC address shellcode smuggling
✦Payload retrieval from alternate sources
UNIT 15
Process injection: classic techniques
✦VirtualAllocEx + WriteProcessMemory + CreateRemoteThread
✦Target process selection and access rights
✦Shellcode injection walkthrough
✦Detection indicators of classic injection
UNIT 16
Process injection: thread hijacking
✦Suspending and modifying thread context
✦SetThreadContext for execution redirection
✦NtQueueApcThread and user APC injection
✦Early bird APC injection
UNIT 17
Process injection: advanced methods
✦Process hollowing (RunPE)
✦Process Doppelgänging with transacted files
✦Process herpaderping
✦Module stomping and phantom DLL loading
UNIT 18
DLL injection techniques
✦Classic DLL injection with LoadLibrary
✦Reflective DLL injection
✦Manual mapping from memory
✦sRDI (shellcode Reflective DLL Injection)
UNIT 19
Callback-based execution
✦EnumWindows and timer callbacks
✦Fiber-based execution
✦Thread pool callbacks (TpAllocWork)
✦Vectored exception handler abuse
UNIT 20
Direct syscalls
✦System call architecture on Windows
✦Syscall stub structure and SSN resolution
✦Implementing direct syscalls in C/ASM
✦SysWhispers and Hell's Gate techniques
UNIT 21
Indirect syscalls
✦Why indirect syscalls evade call-stack analysis
✦Implementing indirect syscall stubs
✦Combining with API hashing
✦Tartarus' Gate and Halo's Gate variants
UNIT 22
Unhooking ntdll
✦Understanding userland API hooking by EDRs
✦Reading clean ntdll from disk
✦Remapping ntdll from KnownDlls
✦Perun's Fart and fresh-copy techniques
UNIT 23
ETW and AMSI bypass
✦Event Tracing for Windows architecture
✦Patching ETW for evasion
✦AMSI scanning internals
✦AMSI bypass techniques and patch points
UNIT 24
Anti-debugging techniques
✦IsDebuggerPresent and PEB flags
✦NtQueryInformationProcess debug checks
✦Timing-based anti-debug (RDTSC, GetTickCount)
✦Hardware breakpoint detection
UNIT 25
Anti-VM and sandbox detection
✦Registry and file system VM indicators
✦CPUID and hypervisor detection
✦MAC address and hardware fingerprinting
✦User interaction checks (mouse movement, clicks)
UNIT 26
Timing-based evasion
✦Sleep obfuscation with Ekko and Foliage
✦Delayed execution to bypass sandboxes
✦Encrypting memory during sleep
✦Fluctuating thread stack spoofing
UNIT 27
Persistence mechanisms
✦Registry Run key persistence
✦Scheduled task persistence
✦COM object hijacking
✦WMI event subscription persistence
UNIT 28
Rootkit fundamentals
✦User-mode rootkit concepts
✦IAT and inline hooking
✦DKOM (Direct Kernel Object Manipulation) overview
✦Hiding processes and network connections
UNIT 29
Building a complete loader
✦Architecture of a production loader
✦Combining encryption, injection, and evasion
✦Staged loading with multiple layers
✦Error handling and operational security
UNIT 30
C2 communication basics
✦HTTP/S C2 communication channels
✦Domain fronting concepts
✦Named pipe and SMB channels
✦Sleep and jitter for traffic blending
UNIT 31
Detection engineering perspective
✦Understanding EDR telemetry sources
✦ETW providers relevant to malware
✦Writing YARA rules for your own tooling
✦Mapping techniques to MITRE ATT&CK
UNIT 32
Capstone: red team tooling project
✦Designing a custom implant from scratch
✦Integrating all course techniques
✦Testing against AV/EDR in an isolated lab
✦Code review, documentation, and OPSEC analysis