Dynamic Malware Analysis Checklist: Safe Lab Setup, Tools and Steps
Explore the 12-step dynamic malware analysis checklist with top tools like Wireshark, Procmon, Volatility, and Cuckoo Sandbox. Ideal for SOC teams, analysts & cybersecurity learners in 2026.
Quick answer: Dynamic malware analysis means running a suspicious file in an isolated lab and recording what it does. The checklist is: build an isolated VM with a clean snapshot, capture a baseline, start monitors (Procmon, Process Explorer, Regshot, Wireshark, Sysmon), run the sample, observe processes, files, registry and network, then revert the snapshot and write a report. Use harmless samples to practise.
Key takeaways
- Never run malware on your normal computer. Use an isolated virtual machine with no shared folders and a host-only or simulated network.
- Take a clean snapshot first, and revert to it after every run.
- Monitor processes, files, registry, network traffic and persistence mechanisms, and record timestamps.
- Practise with the harmless EICAR test file and known training samples, not live malware from unknown sources.
- End with a short report: what it did, indicators of compromise and how to detect and stop it.
What is dynamic malware analysis?
Dynamic analysis runs a suspicious file and observes its behaviour: what processes it starts, which files and registry keys it changes, what it connects to and whether it tries to stay on the system. Static analysis, by contrast, inspects the file without running it, using strings, headers and disassembly. Good analysts use both. Dynamic analysis is quicker for finding behaviour, but some malware detects virtual machines or waits before acting.
Safety and legal note. Malware can destroy data and spread. Use only an isolated lab, and handle samples as dangerous. Keep analysis to samples you are entitled to hold, for example for study or in your job. Do not distribute or deploy malware.
The checklist
| Step | Tools and technique | Purpose |
|---|---|---|
| 1. Build the lab | VirtualBox or VMware, a Windows VM, host-only network | Contain the sample |
| 2. Snapshot | VM snapshot of a clean, patched state | Return to a known state |
| 3. Baseline | Regshot (first shot), file listing | Know what changes |
| 4. Start monitors | Process Monitor, Process Explorer, Sysmon, Wireshark | Record behaviour |
| 5. Simulate network | INetSim or FakeNet-NG on a second VM | Catch network calls safely |
| 6. Execute | Run the sample, wait, perform normal actions | Trigger behaviour |
| 7. Observe | Process tree, file writes, registry, services, scheduled tasks | Understand actions |
| 8. Network analysis | Wireshark capture and simulator logs | Find domains, IPs, protocols |
| 9. Second snapshot compare | Regshot second shot and compare | List system changes |
| 10. Collect indicators | Hashes, file names, mutexes, domains | Build detection |
| 11. Revert and report | Restore snapshot, write findings | Clean up and share |
Step by step
Build an isolated lab
Use a Windows VM with no shared folders, no clipboard sharing, no drag and drop and a host-only or internal network. Keep the host fully patched and do not connect the analysis VM to your home network. For a prebuilt toolset, the open-source FLARE-VM project on GitHub installs analysis tools on Windows. See also our post on what a sandbox is.
Take a baseline
Snapshot the clean VM. Run Regshot to record the registry and file state. Note running processes and open ports.
Start monitoring
Start Process Monitor with filters for the sample's process. Start Process Explorer to see the process tree. Use Sysmon to log process creation and network connections. Start a Wireshark capture. A second VM running INetSim or FakeNet-NG can answer DNS and HTTP requests so the sample behaves as if online without reaching the real internet.
Run the sample
Run it and wait. Some samples sleep. Click around, open files and use the browser to trigger behaviour. Note the exact time.
Observe
- Processes: child processes, injection into other processes, use of PowerShell or scripts.
- Files: dropped files, changed files, encrypted files (ransomware).
- Registry and persistence: Run keys, services, scheduled tasks, startup folder.
- Network: DNS names, IPs, ports, protocols, beaconing intervals.
- Defence evasion: VM checks, disabled security tools, deleted logs.
Compare and collect indicators
Take the second Regshot and compare. List hashes, file paths, registry keys, mutex names and network indicators. Map behaviours to MITRE ATT&CK techniques on attack.mitre.org to describe them in a standard way.
Revert and report
Revert the VM to the clean snapshot. Write a short report: sample hash, environment, timeline, behaviours, indicators of compromise, detection ideas (for example a Sysmon rule or firewall block) and recommendations.
How can you practise safely?
Start with the EICAR test file, a harmless string that antivirus products treat as a virus, to check your monitoring and snapshots work. Then use training samples provided by your course or reputable malware research resources, always inside the lab. Our post on automated malware analysis tools covers online and local sandboxes.
Limits of dynamic analysis
- Malware may detect virtual machines or sandboxes and stay quiet.
- Time-delayed or condition-based behaviour may not trigger.
- It shows what happened, not all the code that exists. Combine with static analysis.
- Fileless techniques leave fewer files; see our post on fileless malware.
Common mistakes
- Running a sample on a machine connected to your real network.
- Skipping the snapshot and reusing a dirty VM.
- Stopping after a few seconds when malware sleeps.
- Not recording timestamps and hashes.
Next steps
Next steps: to learn malware analysis and incident response in depth, see our CHFI course, and read about automated malware analysis tools.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0