malware-analysis
FeaturedUse when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)
Install
Quality Score: 95/100
Skill Content
Details
- Author
- hypnguyen1209
- Repository
- hypnguyen1209/offensive-claude
- Created
- 4 months ago
- Last Updated
- 5 days ago
- Language
- Python
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
malware-reverse-engineering
Malware reverse engineering and suspicious artifact analysis skill for defensive triage, static analysis, dynamic analysis planning, unpacking strategy, indicators of compromise, behavior summaries, YARA/Sigma ideas, and remediation guidance. Use for suspicious binaries, scripts, documents, logs, memory artifacts, sandbox reports, and malware family analysis in isolated environments.
malware-triage
Safe static triage of a suspicious file, hash, or sandbox report without ever executing it: hash lookups, file type by magic, entropy and packing indicators, PE/ELF/LNK/PDF/Office/archive metadata, interesting strings and IOCs, sandbox report interpretation (Tria.ge, ANY.RUN, VMRay, Hybrid Analysis, CAPE, Joe), capability and MITRE ATT&CK assessment, YARA rule drafting, and hand-off to detection and incident work. Use it whenever someone asks "what is this file", "is this hash bad", "can you look at this sample / attachment / binary / script / DLL / LNK / ISO", pastes a VirusTotal or sandbox result, wants a YARA rule, or an EDR alert names an unknown executable, even if they never say the word malware.
malware-dynamic-analysis
Behavioral analysis of a sample executed in an isolated VM. Use after triage when runtime behavior, C2 traffic, dropped files, persistence, or injection must be observed. Claude produces a tailored VM runbook from triage predictions, then parses the exported text evidence (Procmon CSV, Sysmon JSON/CSV, tshark output, autoruns, strings) on the host to reconstruct behavior and extract IOCs. The analyst runs the VM; Claude never executes the sample.