18 cards · Foundations, Practitioner, Applied, Advanced, Expert
Malware & intel interview questions and practice topics
Malware and threat intelligence: ransomware, loaders and C2, persistence, MITRE ATT&CK techniques, and how analysts turn indicators into detections.
Each card is a topic to explain out loud against the clock: 10 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Malware & intel as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- Ransomware attack lifecycleWalk me through a modern human-operated ransomware attack from initial access to the ransom note.Explain · Interview · Deep dive
- The 60-second heartbeatWalk me through confirming whether this is C2 and what you would do next.Incident · Interview
- Windows persistence mechanismsExplain · Deep dive
L3 Applied Abuse and defence in real systems
- C2 beaconingHow does command-and-control beaconing work, and how would you detect it on the network?Explain · Interview · Deep dive
- InfostealersExplain · Deep dive
- Living off the land (LOLBins)What does 'living off the land' mean, and why is it hard for defenders?Explain · Interview
- Phishing kits and AiTMHow do adversary-in-the-middle phishing kits bypass MFA, and what actually stops them?Explain · Interview
- The RaaS economyDeep dive
- Unpacking the Office stagerYou have an encoded PowerShell command from a malicious Office doc. How do you analyse it and what do you extract?Incident · Interview
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Identity & AD · Cloud · Cryptography · Blue team / DFIR · Famous breaches · GRC · AI security