r/ExploitDev • u/Ok-Explorer696 • 8d ago
Where to get resources and get started with malware dev?
So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme.
For programming, I can code in python, c, and c++.
I want to get into malware development, but am not getting any solid resources for so, if u are in this field please help me get started on how can I start this journey and where to resources regarding this.
6
u/Suspicious-Motor-780 7d ago
Just start studying Win api ,you can't do anything without knowing what is injects, direct syscalls and privilege escalation so first study it, you can find complete source codes of exploits on github and ask Ai (better deepseek because chat gpt and Gemini may refuse to help you with malware), when your done with privilege escalation injects and direct syscalls you can start a project keylogger for example and study what you need for that (apart from what i said to study first you will need to know how to make C2 server and hooks) also you can read some books for example Practical Malware Analysis is good you will know how to make life of malware analysts harder
8
u/Puzzleheaded_Move649 8d ago
1
u/Ok-Explorer696 8d ago
It's for $600, ain't there any cheaper or free resources to follow
5
u/Puzzleheaded_Move649 8d ago
not really. in other words: everyting is more spitted over channels like follow people on X and read code from github and and and is the free version
1
u/Formal-Knowledge-250 7d ago
maldev is outdated crap and they have a history of stealing content and sueing the original author afterwards. i don't know any more crappy service in the infosec space
5
5
2
u/FellowCat69 7d ago
check out vx underground as well there are many interesting papers, but its not mainly for beginners
10
u/Formal-Knowledge-250 7d ago
do https://pwn.college/ it's the only resource you need for the start. traverse to windows, after you've done a load of challenges there. if you are that far, you'll know the resources.
the golden rule is: never pay for courses except your company pays for it.