malware-analysis
Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)
Install / Use
npx skills add hypnguyen1209/offensive-claude --skill malware-analysisInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of malware-analysis
malware-analysis scores 86/100 on our quality scale, 2307th of 4,619 Development & Engineering skills we index (top 50%).
Its SKILL.md is 8.9 KB long, well organised into 12 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 377 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 14 days ago, so malware-analysis is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
malware-analysis compared with similar skills
All 4 of these similar skills score higher than malware-analysis; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| malware-analysis (this skill)by hypnguyen1209 | 86 | 377 | 14d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 45.0k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 4d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
Frequently asked questions
- How do I install malware-analysis?
- Run
npx skills add hypnguyen1209/offensive-claude --skill malware-analysis. The install tabs above show the steps for each supported agent. - Which AI agents does malware-analysis work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is malware-analysis safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is malware-analysis still maintained?
- The repository was last updated 14 days ago, so malware-analysis is actively maintained.
Skill content
View source on GitHubname: malware-analysis description: Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing) metadata: type: defensive phase: analysis tools: capa, FLOSS, YARA-X, pefile, x64dbg, dnSpyEx, de4dot, Frida, Qiling, Speakeasy, unipacker, Volatility3, FakeNet-NG, INetSim, 1768.py, CobaltStrikeParser, MACO, CAPEv2, Zeek, ja4, Suricata mitre: TA0042 kill_chain: phase: [weaponize] step: [2] attck_tactics: [TA0042, TA0005, TA0011] attck_techniques: [T1027, T1027.002, T1027.013, T1140, T1055, T1055.012, T1620, T1562.001, T1497, T1547.001, T1546.003, T1059.001, T1071.001, T1071.004, T1573, T1572, T1568.002, T1480] depends_on: [reverse-engineering] feeds_into: [threat-hunting, incident-response, edr-evasion, network-attack] inputs: [malware_sample, memory_image, pcap_capture, sandbox_report] outputs: [yara_rules, ioc_list, behavioral_report, malware_config, capability_map, c2_indicators] references:
- references/static-triage-capa.md
- references/unpacking-deobfuscation.md
- references/dynamic-fileless-memory.md
- references/config-c2-extraction.md
- references/network-c2-detection.md
- references/yara-detection-engineering.md scripts:
- scripts/triage.py
- scripts/auto_unpack.py
- scripts/frida_unpack.js
- scripts/cs_config_extract.py
- scripts/mem_triage.py
- scripts/beacon_profiler.py
- scripts/yara_gen.py
Malware Analysis
When to Activate
- Triaging an unknown binary/script: identity, packing verdict, capability map, IOCs, go/no-go for detonation.
- Recovering the real payload from a packed/crypted/obfuscated loader (commodity loaders, RAT chains, .NET).
- Detonating safely and recovering fileless / in-memory artifacts (injection, AMSI/ETW patching, WMI persistence).
- Extracting malware configuration (C2, keys, sleep/jitter, campaign IDs) for threat intel and detection.
- Detecting/characterizing C2 on the wire (beacon cadence, JA4+ fingerprints, tunneled/DoH channels).
- Writing durable, low-FP YARA-X detection from analysis findings; incident-response scoping.
Technique Map
| Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | Hash/imphash/Rich/ssdeep/TLSH triage + PE anomalies | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | | Per-section entropy + packer/RWX/EP heuristics | T1027.002 | CWE-1066 | references/static-triage-capa.md | scripts/triage.py | | Obfuscated string recovery (FLOSS) | T1140, T1027.013 | CWE-656 | references/static-triage-capa.md | scripts/triage.py | | Capability detection → ATT&CK (capa, static+dynamic) | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | | Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling) | T1140, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/auto_unpack.py | | DBI unpacking via API hooks (Frida) | T1055, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js | | .NET deobfuscation/unpacking (de4dot/dnSpyEx) | T1027, T1140 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js | | Sandbox detonation + behavioral capture | T1497 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | | Memory injection/hollowing/ghosting analysis (Vol3) | T1055, T1055.012 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | | AMSI/ETW in-memory patch + patchless detection | T1562.001 | CWE-693 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | | Fileless WMI/registry/PowerShell persistence | T1546.003, T1547.001, T1059.001 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | | Cobalt Strike / AdaptixC2 config extraction | T1071.001, T1573 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py | | Config framework at scale (MACO/CAPE) | T1071.001 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py | | Generic unknown-C2 protocol RE + decoder | T1573, T1071.004 | CWE-311 | references/config-c2-extraction.md | scripts/cs_config_extract.py | | Beacon cadence/jitter detection (PCAP/Zeek) | T1071.001, T1029 | CWE-778 | references/network-c2-detection.md | scripts/beacon_profiler.py | | JA4+ TLS/HTTP/cert fingerprinting (Sliver/Havoc JA4X) | T1071.001, T1573 | CWE-295 | references/network-c2-detection.md | scripts/beacon_profiler.py | | Tunneled/DoH C2 surfacing (cloudflared/chisel) | T1572, T1568.002, T1071.004 | CWE-441 | references/network-c2-detection.md | scripts/beacon_profiler.py | | YARA-X family rule authoring + FP validation | T1027 | CWE-506 | references/yara-detection-engineering.md | scripts/yara_gen.py |
Quick Start
# 1. Static triage: hashes + PE anomalies + capability combos + FLOSS/capa/YARA-X
python3 scripts/triage.py sample.exe --floss --capa --yara rules/family.yar --json out/triage.json
capa -j sample.exe > out/capa.json # capabilities -> ATT&CK
# 2. Unpack (try emulation first; DBI fallback in isolated VM)
python3 scripts/auto_unpack.py sample.exe -o out/dumps/ # static emulation, no detonation
frida -f C:\sample.exe -l scripts/frida_unpack.js --no-pause # DBI, isolated VM only
de4dot sample.exe -o cleaned.exe # .NET layer
# 3. Dynamic + memory (capture mem BEFORE remediation)
python3 scripts/mem_triage.py -f mem.raw --vol vol --patch-hunt --json out/mem.json
# 4. Config + C2 extraction
python3 scripts/cs_config_extract.py beacon.bin --json # Cobalt Strike
python3 1768.py -S beacon.bin # full CS incl. runtime/heap config
configextractor sample.bin # MACO/MWCP/CAPE at scale
# 5. Network C2 detection
python3 scripts/beacon_profiler.py capture.pcap --min-beacons 6 # cadence/jitter
zeek -r capture.pcap LOCAL ja4 && zeek-cut ja4 ja4s ja4x < ja4.log # JA4+ pivots
# 6. Detection engineering
python3 scripts/yara_gen.py --family samples/fam/ --name Fam --goodware /usr/bin --out rules/fam.yar
yara-x fmt rules/fam.yar && yara-x scan rules/fam.yar /corpus/
OPSEC & Detection (summary)
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note | |-----------|---------------|------------------------|------------| | Static triage | None (offline) | n/a — feeds YARA/imphash hunting | Read-only, no execution; isolate sample dir | | Emulation unpack | None (no detonation) | n/a | Preferred first pass; safe, no network | | DBI/manual unpack | Sysmon 8/10 (CallTrace UNKNOWN), RWX commit | EDR memory scan; RWX-then-exec Sigma | DETONATES — isolated VM, snapshot, FakeNet; loaders self-delete, dump first | | Injection/hollowing | malfind/hollowprocesses; EID 8/10 | Vol3 hollow/ghosting/pebmasquerade; CreateRemoteThread | Capture memory pre-remediation | | AMSI/ETW patch | amsi.dll load + patched prologue; B8 00..C3 stub | Sigma T1562.001; debug-reg+VEH for patchless | Patchless evades byte scans — watch Dr0-Dr7 | | Fileless persistence | WMI consumers; PS 4104; Run-key blobs | Vol3 registry/wmi; Sysmon 13/22 | Lives in WMI/registry/memory — no disk file | | Config extraction | C2 host/UA/pipe/watermark | YARA config table; Suricata on C2 URI/SNI | Offline; handle watermark/keys per ROE | | Beacon detection | Periodic outbound deltas | beacon_profiler CV score; Suricata threshold | Passive on captured traffic | | JA4+ fingerprint | JA4/JA4S/JA4X/JA4H tuples | Zeek ja4 watchlist (Sliver/Havoc JA4X) | JA4X needs TLS1.3 cert visibility at proxy | | YARA-X authoring | None | The rules themselves | Validate 0-FP on goodware before deploy |
Deep Dives
- references/static-triage-capa.md — Identity/code hashes, Rich header, entropy/packer heuristics, FLOSS, capa (PE/ELF/.NET/shellcode + dynamic capa over CAPE, Android rules, capa Explorer Web), FLARE-VM 2025.
- references/unpacking-deobfuscation.md — Self-modifying-stub oracle, emulation (auto_unpack/unipacker/Speakeasy/Qiling), Frida DBI hooks, x64dbg→OEP→Scylla, .NET (de4dot/dnSpyEx), Latrodectus 1.4 AES strings, AsyncRAT fileless loaders, garble/pyc.
- references/dynamic-fileless-memory.md — Sandbox build, Volatility 3 injection playbook + 2025 contest plugins (PEScan/Fileless Hunter), AMSI/ETW patch IOCs + patchless VEH bypass, WMI/registry/PS fileless persistence.
- references/config-c2-extraction.md — Cobalt Strike (1768.py runtime config, CobaltStrikeParser XOR 0x69/0x2e), AdaptixC2 (Unit 42, 2025), MACO/configextractor-py/CAPEv2 at scale, generic unknown-C2 decoder methodology.
- references/network-c2-detection.md — Beacon cadence/CV scoring, JA4+ suite (JA4X for randomized-cert Sliver/Havoc, Zeek/TheHive 2025-26), tunneled/DoH C2 (cloudflared/TryCloudflare/chisel), Suricata/Sigma + ransomware 2025 tradecraft.
- references/yara-detection-engineering.md — YARA-X 1.0 (Rust, 99% compat, fmt/WASM, perf caveats), code/byte > string rules, pe/math modules, threshold logic, goodware FP validation, memory+disk scanning, capa pairing.
Related Skills
ai-job-search
45.0kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
