When you have to deal with malware in your day job, for research purposes, or just for fun, one of the key points is to have a lab ready to be launched. Your sandbox must be properly protected and isolated to detonate your samples in a safe way but it must also be fulfilled with tools, and scripts. This toolbox is yours and will be based on your preferred tools but starting from zero is hard, that’s why there are specific Linux distributions built for this purpose. The one that I use in FOR610 and for my daily investigations is REMnux, created and maintained by Lenny Zeltser. This environment offers tons of tools that help to perform all the malware analysis steps from static analysis up to code reversing and debugging.
Article Link: InfoSec Handlers Diary Blog - SANS Internet Storm Center