A few weeks ago I spent a full lab session doing something that sounds simple on paper and is genuinely satisfying in practice: taking a packed, obfuscated piece of malware and peeling back every layer until I could see what it actually does.

This post is my write-up of that session. It's long, because the lab itself covered a lot of ground —...