This document provides an overview of Zen and the art of collecting and analyzing malware. It discusses how tools like Nepenthes and mwcollect can be used to passively collect malware through emulated vulnerabilities. Nepenthes employs a modular approach, with modules for vulnerabilities, shellcode handling, geolocation, DNS lookup, and downloading payloads via HTTP, FTP, and other protocols. Statistics on malware collected are also presented, followed by a demonstration and discussion of future directions.