How to do: Malware Analysis
This talk provides a practical introduction to malware analysis for beginners, focusing on building a foundational workflow rather than reverse engineering. In my talk, I will be covering key principles around ensuring a safe lab setup, basic static analysis, and dynamic analysis using sandbox environments, in addition to any tools that you have within your own lab environment (FlareVM). I will be referencing my writeup as an example.
Malware analysis can seem intimidating to those unfamiliar with it. As someone starting his infosec journey, I was hesitant to even run malware in a virtual environment, worried that it might escape and infect my main system.. particularly at a time when I was building my portfolio and applying for jobs.
In this talk, I will discuss how I overcame that fear by leveraging a few key principles and tools that help you analyze safely and more confidently. There will be a strong emphasis on practical safety measures, including what to do and where to get your malware samples, and I will discuss some of the tools I currently use when analyzing malware.
I'm Matt Nguyen, an upcoming and young cyber professional with interests in Information Security, Security Operations, Incident Response and Malware Analysis. My background was in healthcare as a physical therapy technician, encountered cyber by accident, and decided to go to school/learn cyber full-time. I was a founder/former President of a cyber club at Austin Community College from 2024 to 2025, where I hosted 6 events with over 8 speakers and had over 100 club members. Since then, I have been attending networking events, volunteering at local conferences, and serving on the committee for a past conference this year (IntelliC0N 2025). Now I currently attend school, moderate a break into a cyber nonprofit called The GingerHacker Initiative, and am on the committee for another conference coming in 2027. In my free time, I do analyze malware but also read/nerd out on Martial arts.