Dynamic Malware Analysis Checklist: Safe Lab Setup, Tools and Steps

Explore the 12-step dynamic malware analysis checklist with top tools like Wireshark, Procmon, Volatility, and Cuckoo Sandbox. Ideal for SOC teams, analysts & cybersecurity learners in 2026.

Jun 23, 2025 - 10:51
Updated: 4 days ago
108.4k
Dynamic Malware Analysis Checklist: Safe Lab Setup, Tools and Steps

Quick answer: Dynamic malware analysis means running a suspicious file in an isolated lab and recording what it does. The checklist is: build an isolated VM with a clean snapshot, capture a baseline, start monitors (Procmon, Process Explorer, Regshot, Wireshark, Sysmon), run the sample, observe processes, files, registry and network, then revert the snapshot and write a report. Use harmless samples to practise.

Key takeaways

  • Never run malware on your normal computer. Use an isolated virtual machine with no shared folders and a host-only or simulated network.
  • Take a clean snapshot first, and revert to it after every run.
  • Monitor processes, files, registry, network traffic and persistence mechanisms, and record timestamps.
  • Practise with the harmless EICAR test file and known training samples, not live malware from unknown sources.
  • End with a short report: what it did, indicators of compromise and how to detect and stop it.

What is dynamic malware analysis?

Dynamic analysis runs a suspicious file and observes its behaviour: what processes it starts, which files and registry keys it changes, what it connects to and whether it tries to stay on the system. Static analysis, by contrast, inspects the file without running it, using strings, headers and disassembly. Good analysts use both. Dynamic analysis is quicker for finding behaviour, but some malware detects virtual machines or waits before acting.

Safety and legal note. Malware can destroy data and spread. Use only an isolated lab, and handle samples as dangerous. Keep analysis to samples you are entitled to hold, for example for study or in your job. Do not distribute or deploy malware.

The checklist

StepTools and techniquePurpose
1. Build the labVirtualBox or VMware, a Windows VM, host-only networkContain the sample
2. SnapshotVM snapshot of a clean, patched stateReturn to a known state
3. BaselineRegshot (first shot), file listingKnow what changes
4. Start monitorsProcess Monitor, Process Explorer, Sysmon, WiresharkRecord behaviour
5. Simulate networkINetSim or FakeNet-NG on a second VMCatch network calls safely
6. ExecuteRun the sample, wait, perform normal actionsTrigger behaviour
7. ObserveProcess tree, file writes, registry, services, scheduled tasksUnderstand actions
8. Network analysisWireshark capture and simulator logsFind domains, IPs, protocols
9. Second snapshot compareRegshot second shot and compareList system changes
10. Collect indicatorsHashes, file names, mutexes, domainsBuild detection
11. Revert and reportRestore snapshot, write findingsClean up and share

Step by step

Build an isolated lab

Use a Windows VM with no shared folders, no clipboard sharing, no drag and drop and a host-only or internal network. Keep the host fully patched and do not connect the analysis VM to your home network. For a prebuilt toolset, the open-source FLARE-VM project on GitHub installs analysis tools on Windows. See also our post on what a sandbox is.

Take a baseline

Snapshot the clean VM. Run Regshot to record the registry and file state. Note running processes and open ports.

Start monitoring

Start Process Monitor with filters for the sample's process. Start Process Explorer to see the process tree. Use Sysmon to log process creation and network connections. Start a Wireshark capture. A second VM running INetSim or FakeNet-NG can answer DNS and HTTP requests so the sample behaves as if online without reaching the real internet.

Run the sample

Run it and wait. Some samples sleep. Click around, open files and use the browser to trigger behaviour. Note the exact time.

Observe

  • Processes: child processes, injection into other processes, use of PowerShell or scripts.
  • Files: dropped files, changed files, encrypted files (ransomware).
  • Registry and persistence: Run keys, services, scheduled tasks, startup folder.
  • Network: DNS names, IPs, ports, protocols, beaconing intervals.
  • Defence evasion: VM checks, disabled security tools, deleted logs.

Compare and collect indicators

Take the second Regshot and compare. List hashes, file paths, registry keys, mutex names and network indicators. Map behaviours to MITRE ATT&CK techniques on attack.mitre.org to describe them in a standard way.

Revert and report

Revert the VM to the clean snapshot. Write a short report: sample hash, environment, timeline, behaviours, indicators of compromise, detection ideas (for example a Sysmon rule or firewall block) and recommendations.

How can you practise safely?

Start with the EICAR test file, a harmless string that antivirus products treat as a virus, to check your monitoring and snapshots work. Then use training samples provided by your course or reputable malware research resources, always inside the lab. Our post on automated malware analysis tools covers online and local sandboxes.

Limits of dynamic analysis

  • Malware may detect virtual machines or sandboxes and stay quiet.
  • Time-delayed or condition-based behaviour may not trigger.
  • It shows what happened, not all the code that exists. Combine with static analysis.
  • Fileless techniques leave fewer files; see our post on fileless malware.

Common mistakes

  • Running a sample on a machine connected to your real network.
  • Skipping the snapshot and reusing a dirty VM.
  • Stopping after a few seconds when malware sleeps.
  • Not recording timestamps and hashes.

Next steps

Next steps: to learn malware analysis and incident response in depth, see our CHFI course, and read about automated malware analysis tools.

Related reading

Frequently Asked Questions

Dynamic malware analysis runs a suspicious file in an isolated environment and observes its behaviour, such as processes, file and registry changes and network connections, to understand what it does and how to detect it.

Static analysis inspects a file without running it, using strings, headers and disassembly. Dynamic analysis runs it and watches behaviour. Static is safer but can be blocked by obfuscation, while dynamic can miss delayed or hidden behaviour.

Common tools include virtual machines, Process Monitor, Process Explorer, Sysmon, Regshot and Wireshark, plus INetSim or FakeNet-NG for simulated network services. Online or local sandboxes automate parts of the process.

A sandbox contains the malware so it cannot damage your real systems or spread. With snapshots, you can revert to a clean state after each run and repeat the analysis safely.

Executing the sample triggers its behaviour so you can record processes it starts, files and registry keys it changes, persistence methods and network communication, which you then turn into indicators and detections.

Process Monitor (Procmon) from Sysinternals records file system, registry and process activity in real time. Regshot compares registry and file snapshots before and after execution.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.