
Two Sides of The Same Coin – From Dissected Malware to EDR Evasion
This blog is not here to give you a “step-by-step recipe.” It’s here to open
Uriel Kosayev is a cybersecurity researcher, reverse engineer, and keynote speaker with over a decade of experience in malware analysis, offensive security, and incident response. As founder of TrainSec Academy and author of Antivirus Bypass Techniques and MAoS – Malware Analysis on Steroids, he is recognized for making complex concepts practical and actionable, with one clear mission: teaching professionals to think like attackers and act like defenders.
Uriel develops and teaches advanced cybersecurity courses that combine real-world techniques with deep technical insight, helping professionals strengthen their skills in both red and blue team operations.
At TrainSec, Uriel leads specialized training programs focused on offensive security, malware analysis, and practical defense strategies.
 
															For by wise counsel, you shall wage your war, and in a multitude of counselors there is victory. (Proverbs 24:6)
Released September 7th, 2025
Fighting Malware to the Death – Real-World Threats and Reverse Engineering Tactics
This book is a field guide to dissecting malware in the real world. From first byte to persistence, obfuscation, payload logic, and attacker tradecraft, nothing is skipped. Learn step-by-step reverse engineering, spot evasion and C2 tricks, and apply proven methodologies to bring order to chaos. Built on real cases and incident response, it equips analysts, responders, red teamers, and defenders with tactics that work under fire.
You’ll master:
Real-world impact: each case study comes from actual incident responses, where decisions matter and errors are costly.
8000+ People bought this book
Learn practical techniques and tactics to combat, bypass, and evade antivirus software
At TrainSec, we’re proud to offer exclusive, in-depth training courses taught by Uriel Kosayev, courses focus on advanced topics in Malware Analysis & Development, Blue Team Course, Workshops and more, combining deep technical knowledge with practical experience.
Browse the available courses below to learn directly from one of the world’s leading offensive security experts.
 
															 
															 
															 
															 
															 
															The following articles were written by Uriel as part of the TrainSec free knowledge library.

This blog is not here to give you a “step-by-step recipe.” It’s here to open

There are a variety of threats in today’s cyber landscape, but one of the biggest

In this video, I’ll walk you through my methodology and insights gained when uncovering how

We’re excited to share the recorded workshop on Remote Thread Injection and EDR-based detection that

Explore BlackByte ransomware: ProxyShell exploits, anti-debugging, and reverse engineering insights. Dive deep into this malware’s

In this video, I’ll show you how to debug a DLL file with an IDA

We’re excited to share a special occasion with you – Uriel Kosayev, one of our

In the video, I draw from my 15 years of experience to explain that recognizing

In this malware analysis video, we explore how MuddyWater, an Iranian APT group, utilizes legitimate

Authors Uriel Kosayev — @MalFuzzer, Hai Vaknin — @VakninHai, Tamir Yehuda — @Tamirye94, Matan Bahar — @Bl4ckShad3 Prologue As red teamers, we are

By Uriel Kosayev (@MalFuzzer) Introduction Intel is a very well-known and large company that serves many

(CVE-2020-8842) Introduction MSI TrueColor utility comes as a pre-installed utility program on MSI gaming laptops

As Mac malware becomes more widespread and as detection mechanisms get more sophisticated, malware actors

Microsoft WslService Unquoted Service Path By Uriel Kosayev Introduction WslService is a deployed service on

Last month, we decided to enrich our knowledge by delving into research on a popular
The following articles were written by Uriel as part of the TrainSec free knowledge library.
CVE-2019-6971 and CVE-2019-6972
Contributed the keymgr.dll credentials dump technique