Question for malware analysts out there, do you usually detonate the malware in a sandboxed environment to perform some sort of basic dynamic analysis before going through the assembly, ghidra, and Ida?
I watched a course suggesting that path, but im more inclined to avoid malware execution before knowing more about It.
From beginner point of view
Pros
Getting good faster info from execution
Cons
Dunno how good bad guy Is at pwning my setup or escape the sandbox
What do you suggest?