malware-analysis

Featured

Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)

Data & Documents 382 stars 66 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
86
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Malware Analysis ## When to Activate - Triaging an unknown binary/script: identity, packing verdict, capability map, IOCs, go/no-go for detonation. - Recovering the real payload from a packed/crypted/obfuscated loader (commodity loaders, RAT chains, .NET). - Detonating safely and recovering **fileless / in-memory** artifacts (injection, AMSI/ETW patching, WMI persistence). - Extracting malware configuration (C2, keys, sleep/jitter, campaign IDs) for threat intel and detection. - Detecting/characterizing C2 on the wire (beacon cadence, JA4+ fingerprints, tunneled/DoH channels). - Writing durable, low-FP YARA-X detection from analysis findings; incident-response scoping. ## Technique Map | Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | Hash/imphash/Rich/ssdeep/TLSH triage + PE anomalies | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | | Per-section entropy + packer/RWX/EP heuristics | T1027.002 | CWE-1066 | references/static-triage-capa.md | scripts/triage.py | | Obfuscated string recovery (FLOSS) | T1140, T1027.013 | CWE-656 | references/static-triage-capa.md | scripts/triage.py | | Capability detection → ATT&CK (capa, static+dynamic) | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | | Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling) | T1140, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/auto_unpack.py | | DBI unpacking via API hooks (Frida)...

Details

Author
hypnguyen1209
Repository
hypnguyen1209/offensive-claude
Created
4 months ago
Last Updated
5 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

malware-reverse-engineering

Malware reverse engineering and suspicious artifact analysis skill for defensive triage, static analysis, dynamic analysis planning, unpacking strategy, indicators of compromise, behavior summaries, YARA/Sigma ideas, and remediation guidance. Use for suspicious binaries, scripts, documents, logs, memory artifacts, sandbox reports, and malware family analysis in isolated environments.

0 Updated 1 weeks ago
Garyson26
Data & Documents Listed

malware-triage

Safe static triage of a suspicious file, hash, or sandbox report without ever executing it: hash lookups, file type by magic, entropy and packing indicators, PE/ELF/LNK/PDF/Office/archive metadata, interesting strings and IOCs, sandbox report interpretation (Tria.ge, ANY.RUN, VMRay, Hybrid Analysis, CAPE, Joe), capability and MITRE ATT&CK assessment, YARA rule drafting, and hand-off to detection and incident work. Use it whenever someone asks "what is this file", "is this hash bad", "can you look at this sample / attachment / binary / script / DLL / LNK / ISO", pastes a VirusTotal or sandbox result, wants a YARA rule, or an EDR alert names an unknown executable, even if they never say the word malware.

0 Updated 1 weeks ago
ftrout
Data & Documents Listed

malware-dynamic-analysis

Behavioral analysis of a sample executed in an isolated VM. Use after triage when runtime behavior, C2 traffic, dropped files, persistence, or injection must be observed. Claude produces a tailored VM runbook from triage predictions, then parses the exported text evidence (Procmon CSV, Sysmon JSON/CSV, tshark output, autoruns, strings) on the host to reconstruct behavior and extract IOCs. The analyst runs the VM; Claude never executes the sample.

47 Updated 2 weeks ago
gl0bal01