This site provides documentation for REMnux,® a free Linux toolkit for reverse-engineering and analyzing malware. REMnux strives to make it easier for forensic investigators and incident responders to start using the variety of freely-available tools that can examine malware, yet might be difficult to find or set up.
Another REMnux initiative involves building Docker images of popular malware analysis tools. The goals of this effort is to allow investigators to conveniently utilize difficult-to-setup applications without having to install the REMnux distro. You can run Dockerized application containers as part of your existing environment.
REMnux is maintained by Lenny Zeltser with extensive help from David Westcott. You can learn the malware analysis techniques that make use of the tools installed and pre-configured on the REMnux distro by taking Reverse-Engineering Malware training at SANS Institute.