Malware Triage / Static AnalysisIntermediateFree, no sign-up
Signed, Not Trusted
A case from the Malware Triage Lab
Briefing
An endpoint sensor at a fictional robotics company quarantines a binary pretending to be a Windows system process. It carries a valid-looking code signature from a certificate that was revoked months ago. The triage queue mixes its static and sandbox artifacts with a day of ordinary submissions. Separate the sample from the noise, identify the masquerade, confirm the packing, and extract indicators you can block, without running anything.
492 events7 log sourcesabout 40 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Static triage: hashes, PE structure, imports and entropy
- Reading a code-signing chain and knowing when a signature means nothing
- Working a sandbox report and separating it from unrelated submissions
- Extracting host and network indicators worth deploying
Maps to these certifications
GREMGCFAGCIHCySA+
Log sources in the corpus
PE Header · PE Section · Imports · Strings · Behaviour · Network · Persistence
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.