// Prerequisites

What to read before The Android Malware Handbook

If The Android Malware Handbook feels too steep at advanced level, here is what to read first. Lighter books in the same topics that build the prerequisites this one assumes.

  1. 01 · 2018

    Malware Data Science

    Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.

    Intermediate
    4/5Joshua Saxe, Hillary Sanders
  2. 02 · 2012

    Practical Malware Analysis

    Still the gold standard textbook for static and dynamic malware analysis on Windows.

    Intermediate
    5/5Michael Sikorski, Andrew Honig
  3. 03 · 2014

    Countdown to Zero Day

    Kim Zetter's investigative reconstruction of Stuxnet, the joint US/Israeli operation that physically damaged Iranian uranium-enrichment centrifuges via a worm, and what its discovery revealed about state-level cyber capability.

    Beginner
    5/5Kim Zetter
  4. 04 · 2014

    The Art of Memory Forensics

    Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.

    Advanced
    5/5Michael Hale Ligh, Andrew Case, Jamie Levy, AAron Walters
  5. 05 · 2014

    Android Security Internals

    Nikolay Elenkov on the actual implementation of Android's security model: package manager internals, permissions, keystore, SELinux integration, verified boot.

    Advanced
    4/5Nikolay Elenkov
  6. 06 · 2025

    Cybersécurité et Malwares

    Now in its 5th edition, the French-language reference for malware analysis by Sébastien Larinier and Paul Rascagnères, a well-known APT threat researcher, running from identification to Threat Intelligence across Windows, macOS, Linux, Android, and iOS.

    Advanced
    4/5Sébastien Larinier, Paul Rascagnères
  7. 07 · 2026

    Dissecting the Dark Web

    HUMAN Security's VP of Threat Intelligence tears down real malware-as-a-service offerings sold on dark web forums, chapter by chapter, from stealers and loaders to ransomware and living-off-the-land post-exploitation kits.

    Advanced
    4/5Lindsay Kaye
  8. 08 · 2024

    Evading EDR

    A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.

    Advanced
    4/5Matt Hand
← Back to The Android Malware HandbookWhat to read after The Android Malware Handbook →