{"slug":"malware-analyst","title":"malware-analyst","summary":"Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.","platform":"ChatGPT","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-16T13:38:39.778864Z","repo":{"url":"https://github.com/sickn33/agentic-awesome-skills","stars":46883,"forks":6831,"license":"MIT","updatedAt":"2026-09-25T05:43:16Z"},"bodyHtml":"<hr>\n<h2>name: malware-analyst\ndescription: Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.\nrisk: critical\nsource: community\ndate_added: '2026-02-27'</h2>\n<h1>File identification</h1>\n<p>file sample.exe\nsha256sum sample.exe</p>\n<h1>String extraction</h1>\n<p>strings -a sample.exe | head -100\nFLOSS sample.exe  # Obfuscated strings</p>\n<h1>Packer detection</h1>\n<p>diec sample.exe   # Detect It Easy\nexeinfope sample.exe</p>\n<h1>Import analysis</h1>\n<p>rabin2 -i sample.exe\ndumpbin /imports sample.exe</p>\n<pre><code>\n### Phase 3: Static Analysis\n1. **Load in disassembler**: IDA Pro, Ghidra, or Binary Ninja\n2. **Identify main functionality**: Entry point, WinMain, DllMain\n3. **Map execution flow**: Key decision points, loops\n4. **Identify capabilities**: Network, file, registry, process operations\n5. **Extract IOCs**: C2 addresses, file paths, mutex names\n\n### Phase 4: Dynamic Analysis\n</code></pre>\n<ol>\n<li><p>Environment Setup:</p>\n<ul>\n<li>Windows VM with common software installed</li>\n<li>Process Monitor, Wireshark, Regshot</li>\n<li>API Monitor or x64dbg with logging</li>\n<li>INetSim or FakeNet for network simulation</li>\n</ul>\n</li>\n<li><p>Execution:</p>\n<ul>\n<li>Start monitoring tools</li>\n<li>Execute sample</li>\n<li>Observe behavior for 5-10 minutes</li>\n<li>Trigger functionality (connect to network, etc.)</li>\n</ul>\n</li>\n<li><p>Documentation:</p>\n<ul>\n<li>Network connections attempted</li>\n<li>Files created/modified</li>\n<li>Registry changes</li>\n<li>Processes spawned</li>\n<li>Persistence mechanisms</li>\n</ul>\n</li>\n</ol>\n<pre><code>\n## Use this skill when\n\n- Working on file identification tasks or workflows\n- Needing guidance, best practices, or checklists for file identification\n\n## Do not use this skill when\n\n- The task is unrelated to file identification\n- You need a different domain or tool outside this scope\n\n## Instructions\n\n- Clarify goals, constraints, and required inputs.\n- Apply relevant best practices and validate outcomes.\n- Provide actionable steps and verification.\n- If detailed examples are required, open `resources/implementation-playbook.md`.\n\n## Common Malware Techniques\n\n### Persistence Mechanisms\n</code></pre>\n<p>Registry Run keys       - HKCU/HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\nScheduled tasks         - schtasks, Task Scheduler\nServices               - CreateService, sc.exe\nWMI subscriptions      - Event subscriptions for execution\nDLL hijacking          - Plant DLLs in search path\nCOM hijacking          - Registry CLSID modifications\nStartup folder         - %APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\nBoot records           - MBR/VBR modification</p>\n<pre><code>\n### Evasion Techniques\n</code></pre>\n<p>Anti-VM                - CPUID, registry checks, timing\nAnti-debugging         - IsDebuggerPresent, NtQueryInformationProcess\nAnti-sandbox           - Sleep acceleration detection, mouse movement\nPacking                - UPX, Themida, VMProtect, custom packers\nObfuscation           - String encryption, control flow flattening\nProcess hollowing      - Inject into legitimate process\nLiving-off-the-land    - Use built-in tools (PowerShell, certutil)</p>\n<pre><code>\n### C2 Communication\n</code></pre>\n<p>HTTP/HTTPS            - Web traffic to blend in\nDNS tunneling         - Data exfil via DNS queries\nDomain generation     - DGA for resilient C2\nFast flux             - Rapidly changing DNS\nTor/I2P               - Anonymity networks\nSocial media          - Twitter, Pastebin as C2 channels\nCloud services        - Legitimate services as C2</p>\n<pre><code>\n## Tool Proficiency\n\n### Analysis Platforms\n</code></pre>\n<p>Cuckoo Sandbox       - Open-source automated analysis\nANY.RUN              - Interactive cloud sandbox\nHybrid Analysis      - VirusTotal alternative\nJoe Sandbox          - Enterprise sandbox solution\nCAPE                 - Cuckoo fork with enhancements</p>\n<pre><code>\n### Monitoring Tools\n</code></pre>\n<p>Process Monitor      - File, registry, process activity\nProcess Hacker       - Advanced process management\nWireshark            - Network packet capture\nAPI Monitor          - Win32 API call logging\nRegshot              - Registry change comparison</p>\n<pre><code>\n### Unpacking Tools\n</code></pre>\n<p>Unipacker            - Automated unpacking framework\nx64dbg + plugins     - Scylla for IAT reconstruction\nOllyDumpEx           - Memory dump and rebuild\nPE-sieve             - Detect hollowed processes\nUPX                  - For UPX-packed samples</p>\n<pre><code>\n## IOC Extraction\n\n### Indicators to Extract\n```yaml\nNetwork:\n  - IP addresses (C2 servers)\n  - Domain names\n  - URLs\n  - User-Agent strings\n  - JA3/JA3S fingerprints\n\nFile System:\n  - File paths created\n  - File hashes (MD5, SHA1, SHA256)\n  - File names\n  - Mutex names\n\nRegistry:\n  - Registry keys modified\n  - Persistence locations\n\nProcess:\n  - Process names\n  - Command line arguments\n  - Injected processes\n</code></pre>\n<h3>YARA Rules</h3>\n<pre><code>rule Malware_Generic_Packer\n{\n    meta:\n        description = \"Detects common packer characteristics\"\n        author = \"Security Analyst\"\n\n    strings:\n        $mz = { 4D 5A }\n        $upx = \"UPX!\" ascii\n        $section = \".packed\" ascii\n\n    condition:\n        $mz at 0 and ($upx or $section)\n}\n</code></pre>\n<h2>Reporting Framework</h2>\n<h3>Analysis Report Structure</h3>\n<pre><code># Malware Analysis Report\n\n## Executive Summary\n- Sample identification\n- Key findings\n- Threat level assessment\n\n## Sample Information\n- Hashes (MD5, SHA1, SHA256)\n- File type and size\n- Compilation timestamp\n- Packer information\n\n## Static Analysis\n- Imports and exports\n- Strings of interest\n- Code analysis findings\n\n## Dynamic Analysis\n- Execution behavior\n- Network activity\n- Persistence mechanisms\n- Evasion techniques\n\n## Indicators of Compromise\n- Network IOCs\n- File system IOCs\n- Registry IOCs\n\n## Recommendations\n- Detection rules\n- Mitigation steps\n- Remediation guidance\n</code></pre>\n<h2>Ethical Guidelines</h2>\n<h3>Appropriate Use</h3>\n<ul>\n<li>Incident response and forensics</li>\n<li>Threat intelligence research</li>\n<li>Security product development</li>\n<li>Academic research</li>\n<li>CTF competitions</li>\n</ul>\n<h3>Never Assist With</h3>\n<ul>\n<li>Creating or distributing malware</li>\n<li>Attacking systems without authorization</li>\n<li>Evading security products maliciously</li>\n<li>Building botnets or C2 infrastructure</li>\n<li>Any offensive operations without proper authorization</li>\n</ul>\n<h2>Response Approach</h2>\n<ol>\n<li><strong>Verify context</strong>: Ensure defensive/authorized purpose</li>\n<li><strong>Assess sample</strong>: Quick triage to understand what we're dealing with</li>\n<li><strong>Recommend approach</strong>: Appropriate analysis methodology</li>\n<li><strong>Guide analysis</strong>: Step-by-step instructions with safety considerations</li>\n<li><strong>Extract value</strong>: IOCs, detection rules, understanding</li>\n<li><strong>Document findings</strong>: Clear reporting for stakeholders</li>\n</ol>\n<h2>Limitations</h2>\n<ul>\n<li>Use this skill only when the task clearly matches the scope described above.</li>\n<li>Do not treat the output as a substitute for environment-specific validation, testing, or expert review.</li>\n<li>Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.</li>\n</ul>\n","files":[{"path":"SKILL.md","sizeBytes":6820,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"human-reviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"human-reviewed","screen":{"ran":true,"outcome":"flagged-cleared-by-moderator","suspicious":2,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-16T13:43:14.928593Z","sha256":"3C2CB730DF3D382EC1B97EFA3D30D1AA502344C006117D8737020FA8B4B044CD","sizeBytes":3208},"review":null,"source":{"repositoryUrl":"https://github.com/sickn33/agentic-awesome-skills","path":"skills/malware-analyst","license":"MIT","commit":"f2bba339de74414b0771234cbe4f6a15258e32a3","subtreeSha":"ED34C9073AB36A760522783DFE8F87C4E3A3AA72340300B77E0127CED30BAFA2","lastSyncedAt":"2026-09-25T06:48:39.853703Z"},"reviewedAt":"2026-08-16T13:56:04.651671Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analyst"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install sickn33-agentic-awesome-skills@llmmart"},{"target":"git","command":"git clone https://github.com/sickn33/agentic-awesome-skills.git"}]}