Creator · Masriyan
Last updated · Sep 5, 2026
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Creator · Masriyan
Last updated · Sep 5, 2026
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Creator · Masriyan
Last updated · Sep 5, 2026
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Creator · Masriyan
Last updated · Sep 5, 2026
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Sandbox only
Install targets
Codex install prompt
Install the "Malware Analysis & Sandboxing" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/05-malware-analysis. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-malware-analysis-sandboxing","task":"Install Malware Analysis & Sandboxing","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 73/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
Agent should check
Copy prompt
Task: Use Malware Analysis & Sandboxing in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
LLM text format
/api/skills/masriyan-malware-analysis-sandboxing/install?format=text
Find alternatives
/api/skills/search?q=Malware%20Analysis%20%26%20Sandboxing&limit=3
Agent prompt
Use Malware Analysis & Sandboxing for this task. Review https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-malware-analysis-sandboxing
LLM text
/api/registry/manifest/masriyan-malware-analysis-sandboxing?format=text
Install alias
/api/registry/install/masriyan-malware-analysis-sandboxing
Recommend
/api/registry/recommend?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Malware Analysis & Sandboxing description: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification version: 3.0.0 author: Masriyan tags: [cybersecurity, malware, analysis, yara, sandbox, threat, static-analysis, behavioral] ---
# Malware Analysis & Sandboxing
## Purpose
Enable Claude to assist with malware analysis workflows including static analysis of file properties and code, dynamic behavioral analysis interpretation, YARA rule generation, sandbox configuration, and malware family identification. Claude analyzes provided artifacts directly and orchestrates scripts for automated processing.
> **Safety Warning**: Never execute suspicious files outside of isolated, controlled environments. Use dedicated VMs or sandboxes with network isolation and snapshot capability.
---
## Activation Triggers
This skill activates when the user asks about: - Analyzing a suspicious file, binary, or script - Generating YARA rules for malware detection - Setting up a malware analysis sandbox - Interpreting Cuckoo/CAPE/AnyRun sandbox reports - Identifying malware family or behavior - Creating IOCs from malware samples - Static analysis of PE/ELF files - Memory forensics for malware artifacts - Behavioral analysis (process creation, network, registry, file changes)
---
## Prerequisites
```bash pip install yara-python pefile python-magic requests ssdeep ```
**Recommended analysis tools:** - `Cuckoo Sandbox / CAPE` — Automated dynamic analysis - `VirusTotal API` — Multi-engine scanning and intel - `YARA` — Pattern matching engine - `Ghidra / IDA Pro` — Deep binary analysis (→ Skill 04) - `Volatility 3` — Memory forensics - `DIE (Detect-It-Easy)` — Packer/compiler detection - `Pestudio` — Windows PE static analysis
---
## Core Capabilities
### 1. Static Malware Analysis
**When the user provides a suspicious file or hash for analysis:**
Claude performs analysis in this order:
**Step 1 — File Identification:** ```bash file malware.exe # File type from magic bytes md5sum malware.exe # MD5 hash (legacy, for lookups) sha256sum malware.exe # SHA-256 (primary identifier) python scripts/static_analyzer.py --file malware.exe --hashes ```
**Step 2 — Threat Intelligence Lookup:** - Query VirusTotal (requires API key or paste hash in browser) - Check MalwareBazaar, AbuseIPDB, URLhaus - Search for existing analysis reports ```bash # VirusTotal hash lookup via API curl "https://www.virustotal.com/api/v3/files/<sha256>" -H "x-apikey: YOUR_KEY" ```
**Step 3 — PE Analysis (Windows executables):** ```bash python scripts/static_analyzer.py --file malware.exe --strings --imports --output report.json ```
Look for these indicators in the output:
**Suspicious Import Functions:** | Category | Suspicious APIs | |----------|----------------| | Process Injection | `CreateRemoteThread`, `WriteProcessMemory`, `VirtualAllocEx`, `NtMapViewOfSection`, `RtlCreateUserThread` | | Persistence | `RegSetValueEx`, `CreateService`, `SHFileOperation`, `ITaskScheduler` | | Anti-Analysis | `IsDebuggerPresent`, `CheckRemoteDebuggerPresent`, `GetTickCount`, `QueryPerformanceCounter`, `GetSystemInfo` | | Network C2 | `InternetOpenUrl`, `HttpSendRequest`, `WSAStartup`, `socket`, `URLDownloadToFile`, `WinHttpOpen` | | Crypto Operations | `CryptEncrypt`, `CryptDecrypt`, `BCryptEncrypt`, `CryptHashData` | | Credential Access | `SamOpenDatabase`, `LsaOpenPolicy`, `NtlmGetUserInfo` | | Keylogging | `SetWindowsHookEx`, `GetAsyncKeyState`, `GetKeyboardState` | | Defense Evasion | `VirtualProtect`, `NtSetInformationProcess`, `Wow64DisableWow64FsRedirection` |
**Step 4 — String Extraction & Analysis:** ```bash strings -a malware.exe | grep -E "(http|ftp|/[a-z]|[0-9]{1,3}\.[0-9]{1,3}|HKEY|reg|cmd|powershell)" ```
Categorize extracted strings: - **Network indicators**: URLs, IPs, domains, user agents - **File system**: paths, filenames, registry keys - **Crypto**: base64 blobs, hex strings (potential keys/payloads) - **Anti-analysis**: VM/sandbox detection strings (VMware, VirtualBox, Sandboxie) - **Mutex names**: unique identifiers preventing double-infection
**Step 5 — Entropy Analysis:** ```bash python scripts/static_analyzer.py --file malware.exe --entropy ```
| Entropy Range | Interpretation | |---------------|---------------| | 0.0 – 1.0 | Near-empty or all-zeros section | | 1.0 – 5.0 | Normal code/data section | | 5.0 – 7.0 | Compressed data or code | | 7.0 – 8.0 | Encrypted or packed data — investigate | | 7.9 – 8.0 | Highly suspicious — likely encrypted payload |
### 2. YARA Rule Generation
**When the user asks to create YARA rules from a sample or indicators:**
Claude generates YARA rules following this methodology:
1. **Select stable, unique indicators** — Avoid generic patterns; choose bytes/strings unique to this family 2. **Prefer structural patterns** — Header magic bytes, specific offsets, section names 3. **Balance specificity vs. coverage** — Avoid rules that are too specific (catch only one sample) or too broad (false positives) 4. **Test against benign files** — Rule should NOT match clean Windows system files
**YARA Rule Templates:**
```yara // Tier 1: Specific sample (hash-based) rule MalwareFamily_Variant_Hash { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] [Variant] — specific sample" sha256 = "aabbcc..." tlp = "GREEN" reference = "https://example.com/analysis" condition: hash.sha256(0, filesize) == "aabbcc..." }
// Tier 2: Family-level detection (behavioral strings) rule MalwareFamily_Generic { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] family by strings and structure" tlp = "GREEN" strings: // C2 patterns $c2_ua = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" ascii $c2_uri = "/gate.php?id=" ascii // Crypto constants $rc4_key = { 52 43 34 5F 4B 45 59 } // "RC4_KEY" hex // Mutex $mutex = "Global\\MSDTC_MUTEX_" ascii wide // Registry persistence key $reg_key = "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide nocase // Anti-analysis check $vm_check = "VBOX" ascii wide nocase condition: uint16(0) == 0x5A4D and // MZ header (PE file) filesize < 2MB and ( (2 of ($c2_*)) or ($mutex and 1 of ($reg_key, $rc4_key)) ) and not $vm_check // Exclude sandbox-aware variants }
// Tier 3: Network IOC detection (for NIDS integration) rule MalwareFamily_Network_C2 { meta: description = "Detects [MalwareFamily] C2 communication patterns" type = "network" strings: $beacon_path = "/api/v1/ping?uid=" ascii $beacon_ua = "MalBot/1.0" ascii $checkin_hdr = "X-Command-Key: " ascii condition: any of them } ```
```bash # Generate YARA rules using the script python scripts/yara_generator.py --samples ./malware_samples/ --output rules.yar python scripts/yara_generator.py --file single_sample.exe --rule-name "MalwareFamily" --output rule.yar
# Test rules against benign files yara -r generated_rule.yar /usr/bin/ 2>/dev/null | wc -l # Should be 0 yara generated_rule.yar malware.exe # Should match ```
### 3. Dynamic/Behavioral Analysis
**When the user provides sandbox analysis output or asks about dynamic analysis:**
**Interpreting Cuckoo/CAPE Sandbox Reports:**
Claude analyzes behavioral reports looking for:
1. **Process Tree Analysis:** - Unusual parent-child relationships (Word.exe → PowerShell.exe → cmd.exe) - Process injection indicators (process spawning with different credentials) - Hollowing patterns (legitimate process with suspicious memory)
2. **Network Indicators:** - DNS queries: DGA patterns (random-looking domains), fast-flux - HTTP: Unusual user agents, encoded POST data, beaconing intervals - C2 beaconing detection: Regular interval callbacks (check timing consistency)
3. **File System Changes:** - Shadow copy deletion: `vssadmin delete shadows` → ransomware indicator - Startup persistence: `\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\` - Dropped secondary payloads in temp directories
4. **Registry Modifications:** - Run keys: `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - Service installation: `HKLM\SYSTEM\CurrentControlSet\Services\` - Security policy changes: Disabling UAC, Windows Defender
5. **MITRE ATT&CK Mapping:**
| Observed Behavior | MITRE Technique | |-------------------|----------------| | PowerShell download cradle | T1059.001 — PowerShell | | `cmd /c vssadmin delete shadows` | T1490 — Inhibit System Recovery | | Registry Run key persistence | T1547.001 — Registry Run Keys | | CreateRemoteThread injection | T1055.001 — DLL Injection | | Scheduled task creation | T1053.005 — Scheduled Task | | `netsh advfirewall set allprofiles state off` | T1562.004 — Disable Host Firewall | | UAC bypass (fodhelper.exe) | T1548.002 — Bypass UAC | | LSASS memory access | T1003.001 — LSASS Memory |
### 4. Malware Family Classification
**When the user asks to identify or classify a malware sample:**
**Classification by behavioral patterns:**
| Family Indicators | Likely Family Category | |------------------|----------------------| | Shadow copies deleted + file encryption + ransom note | Ransomware | | Regular HTTP beaconing + command execution + lateral movement | RAT/Botnet | | Browser credential theft + banking overlay | Banking Trojan | | Keylogging + screenshot capture + data exfiltration | Spyware/Infostealer | | Process hollowing + covert persistence | Rootkit/Backdoor | | Cryptocurrency mining process spawning | Cryptominer | | Worm propagation via network shares | Worm | | Document with macro downloading payload | Dropper/Downloader |
**Similarity analysis:** ```bash # SSDeep fuzzy hash comparison ssdeep -l malware.exe > hash.txt ssdeep -m hash.txt similar_sample.exe # Similarity > 70% → likely same family/variant ```
### 5. Sandbox Environment Setup
**When the user asks to set up a malware analysis environment:**
**Minimum isolation requirements:** 1. Dedicated VM (VirtualBox, VMware, KVM) — NEVER use your main machine 2. Host-only or isolated network adapter (NO internet access by default) 3. Snapshot before analysis — restore after each sample 4. Disable shared folders and clipboard (data exfiltration prevention)
**Recommended sandbox stack:** ``` Analysis VM (Windows 10/11 or Ubuntu): ├── FakeNet-NG or INetSim — Simulate network services ├── Wireshark — Capture network traffic ├── ProcessMonitor (Windows) / strace (Linux) — Monitor syscalls ├── Regshot (Windows) — Compare registry before/after ├── Autoruns (Windows) — Monitor persistence locations └── Cuckoo/CAPE Agent — Automated collection
Network Layer: └── Host-only adapter → no real internet → INetSim captures C2 attempts ```
**Anti-anti-VM measures:** - Install VMware Tools (some malware checks for missing tools) - Set reasonable RAM (4GB+) and CPU count (2+) - Add some benign user files and browser history - Set realistic screen resolution (1920x1080) - Remove obvious VM artifacts (registry keys, device names)
---
## IOC Extraction & Output Format
For every analyzed sample, produce:
```markdown ## Malware Analysis Report — [Sample Name]
**Hashes:** - MD5: [hash] - SHA1: [hash] - SHA256: [hash] - SSDeep: [fuzzy hash]
**Classification:** [Ransomware / RAT / Infostealer / etc.] **Confidence:** [High / Medium / Low] **Family:** [Family Name, if identified] **First Seen:** [Date from TI sources]
**Network IOCs:** - IPs: [list] - Domains: [list] - URLs: [list] - User-Agent: [string]
**Host IOCs:
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Malware Analysis & Sandboxing, ready for a manual X post.
Malware Analysis & Sandboxing: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral... 397 stars https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x
Listing + install path for Malware Analysis & Sandboxing: https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing/audit)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsSandbox only
Install targets
Codex install prompt
Install the "Malware Analysis & Sandboxing" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/05-malware-analysis. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-malware-analysis-sandboxing","task":"Install Malware Analysis & Sandboxing","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 73/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
Agent should check
Copy prompt
Task: Use Malware Analysis & Sandboxing in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
LLM text format
/api/skills/masriyan-malware-analysis-sandboxing/install?format=text
Find alternatives
/api/skills/search?q=Malware%20Analysis%20%26%20Sandboxing&limit=3
Agent prompt
Use Malware Analysis & Sandboxing for this task. Review https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-malware-analysis-sandboxing
LLM text
/api/registry/manifest/masriyan-malware-analysis-sandboxing?format=text
Install alias
/api/registry/install/masriyan-malware-analysis-sandboxing
Recommend
/api/registry/recommend?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Malware Analysis & Sandboxing description: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification version: 3.0.0 author: Masriyan tags: [cybersecurity, malware, analysis, yara, sandbox, threat, static-analysis, behavioral] ---
# Malware Analysis & Sandboxing
## Purpose
Enable Claude to assist with malware analysis workflows including static analysis of file properties and code, dynamic behavioral analysis interpretation, YARA rule generation, sandbox configuration, and malware family identification. Claude analyzes provided artifacts directly and orchestrates scripts for automated processing.
> **Safety Warning**: Never execute suspicious files outside of isolated, controlled environments. Use dedicated VMs or sandboxes with network isolation and snapshot capability.
---
## Activation Triggers
This skill activates when the user asks about: - Analyzing a suspicious file, binary, or script - Generating YARA rules for malware detection - Setting up a malware analysis sandbox - Interpreting Cuckoo/CAPE/AnyRun sandbox reports - Identifying malware family or behavior - Creating IOCs from malware samples - Static analysis of PE/ELF files - Memory forensics for malware artifacts - Behavioral analysis (process creation, network, registry, file changes)
---
## Prerequisites
```bash pip install yara-python pefile python-magic requests ssdeep ```
**Recommended analysis tools:** - `Cuckoo Sandbox / CAPE` — Automated dynamic analysis - `VirusTotal API` — Multi-engine scanning and intel - `YARA` — Pattern matching engine - `Ghidra / IDA Pro` — Deep binary analysis (→ Skill 04) - `Volatility 3` — Memory forensics - `DIE (Detect-It-Easy)` — Packer/compiler detection - `Pestudio` — Windows PE static analysis
---
## Core Capabilities
### 1. Static Malware Analysis
**When the user provides a suspicious file or hash for analysis:**
Claude performs analysis in this order:
**Step 1 — File Identification:** ```bash file malware.exe # File type from magic bytes md5sum malware.exe # MD5 hash (legacy, for lookups) sha256sum malware.exe # SHA-256 (primary identifier) python scripts/static_analyzer.py --file malware.exe --hashes ```
**Step 2 — Threat Intelligence Lookup:** - Query VirusTotal (requires API key or paste hash in browser) - Check MalwareBazaar, AbuseIPDB, URLhaus - Search for existing analysis reports ```bash # VirusTotal hash lookup via API curl "https://www.virustotal.com/api/v3/files/<sha256>" -H "x-apikey: YOUR_KEY" ```
**Step 3 — PE Analysis (Windows executables):** ```bash python scripts/static_analyzer.py --file malware.exe --strings --imports --output report.json ```
Look for these indicators in the output:
**Suspicious Import Functions:** | Category | Suspicious APIs | |----------|----------------| | Process Injection | `CreateRemoteThread`, `WriteProcessMemory`, `VirtualAllocEx`, `NtMapViewOfSection`, `RtlCreateUserThread` | | Persistence | `RegSetValueEx`, `CreateService`, `SHFileOperation`, `ITaskScheduler` | | Anti-Analysis | `IsDebuggerPresent`, `CheckRemoteDebuggerPresent`, `GetTickCount`, `QueryPerformanceCounter`, `GetSystemInfo` | | Network C2 | `InternetOpenUrl`, `HttpSendRequest`, `WSAStartup`, `socket`, `URLDownloadToFile`, `WinHttpOpen` | | Crypto Operations | `CryptEncrypt`, `CryptDecrypt`, `BCryptEncrypt`, `CryptHashData` | | Credential Access | `SamOpenDatabase`, `LsaOpenPolicy`, `NtlmGetUserInfo` | | Keylogging | `SetWindowsHookEx`, `GetAsyncKeyState`, `GetKeyboardState` | | Defense Evasion | `VirtualProtect`, `NtSetInformationProcess`, `Wow64DisableWow64FsRedirection` |
**Step 4 — String Extraction & Analysis:** ```bash strings -a malware.exe | grep -E "(http|ftp|/[a-z]|[0-9]{1,3}\.[0-9]{1,3}|HKEY|reg|cmd|powershell)" ```
Categorize extracted strings: - **Network indicators**: URLs, IPs, domains, user agents - **File system**: paths, filenames, registry keys - **Crypto**: base64 blobs, hex strings (potential keys/payloads) - **Anti-analysis**: VM/sandbox detection strings (VMware, VirtualBox, Sandboxie) - **Mutex names**: unique identifiers preventing double-infection
**Step 5 — Entropy Analysis:** ```bash python scripts/static_analyzer.py --file malware.exe --entropy ```
| Entropy Range | Interpretation | |---------------|---------------| | 0.0 – 1.0 | Near-empty or all-zeros section | | 1.0 – 5.0 | Normal code/data section | | 5.0 – 7.0 | Compressed data or code | | 7.0 – 8.0 | Encrypted or packed data — investigate | | 7.9 – 8.0 | Highly suspicious — likely encrypted payload |
### 2. YARA Rule Generation
**When the user asks to create YARA rules from a sample or indicators:**
Claude generates YARA rules following this methodology:
1. **Select stable, unique indicators** — Avoid generic patterns; choose bytes/strings unique to this family 2. **Prefer structural patterns** — Header magic bytes, specific offsets, section names 3. **Balance specificity vs. coverage** — Avoid rules that are too specific (catch only one sample) or too broad (false positives) 4. **Test against benign files** — Rule should NOT match clean Windows system files
**YARA Rule Templates:**
```yara // Tier 1: Specific sample (hash-based) rule MalwareFamily_Variant_Hash { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] [Variant] — specific sample" sha256 = "aabbcc..." tlp = "GREEN" reference = "https://example.com/analysis" condition: hash.sha256(0, filesize) == "aabbcc..." }
// Tier 2: Family-level detection (behavioral strings) rule MalwareFamily_Generic { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] family by strings and structure" tlp = "GREEN" strings: // C2 patterns $c2_ua = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" ascii $c2_uri = "/gate.php?id=" ascii // Crypto constants $rc4_key = { 52 43 34 5F 4B 45 59 } // "RC4_KEY" hex // Mutex $mutex = "Global\\MSDTC_MUTEX_" ascii wide // Registry persistence key $reg_key = "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide nocase // Anti-analysis check $vm_check = "VBOX" ascii wide nocase condition: uint16(0) == 0x5A4D and // MZ header (PE file) filesize < 2MB and ( (2 of ($c2_*)) or ($mutex and 1 of ($reg_key, $rc4_key)) ) and not $vm_check // Exclude sandbox-aware variants }
// Tier 3: Network IOC detection (for NIDS integration) rule MalwareFamily_Network_C2 { meta: description = "Detects [MalwareFamily] C2 communication patterns" type = "network" strings: $beacon_path = "/api/v1/ping?uid=" ascii $beacon_ua = "MalBot/1.0" ascii $checkin_hdr = "X-Command-Key: " ascii condition: any of them } ```
```bash # Generate YARA rules using the script python scripts/yara_generator.py --samples ./malware_samples/ --output rules.yar python scripts/yara_generator.py --file single_sample.exe --rule-name "MalwareFamily" --output rule.yar
# Test rules against benign files yara -r generated_rule.yar /usr/bin/ 2>/dev/null | wc -l # Should be 0 yara generated_rule.yar malware.exe # Should match ```
### 3. Dynamic/Behavioral Analysis
**When the user provides sandbox analysis output or asks about dynamic analysis:**
**Interpreting Cuckoo/CAPE Sandbox Reports:**
Claude analyzes behavioral reports looking for:
1. **Process Tree Analysis:** - Unusual parent-child relationships (Word.exe → PowerShell.exe → cmd.exe) - Process injection indicators (process spawning with different credentials) - Hollowing patterns (legitimate process with suspicious memory)
2. **Network Indicators:** - DNS queries: DGA patterns (random-looking domains), fast-flux - HTTP: Unusual user agents, encoded POST data, beaconing intervals - C2 beaconing detection: Regular interval callbacks (check timing consistency)
3. **File System Changes:** - Shadow copy deletion: `vssadmin delete shadows` → ransomware indicator - Startup persistence: `\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\` - Dropped secondary payloads in temp directories
4. **Registry Modifications:** - Run keys: `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - Service installation: `HKLM\SYSTEM\CurrentControlSet\Services\` - Security policy changes: Disabling UAC, Windows Defender
5. **MITRE ATT&CK Mapping:**
| Observed Behavior | MITRE Technique | |-------------------|----------------| | PowerShell download cradle | T1059.001 — PowerShell | | `cmd /c vssadmin delete shadows` | T1490 — Inhibit System Recovery | | Registry Run key persistence | T1547.001 — Registry Run Keys | | CreateRemoteThread injection | T1055.001 — DLL Injection | | Scheduled task creation | T1053.005 — Scheduled Task | | `netsh advfirewall set allprofiles state off` | T1562.004 — Disable Host Firewall | | UAC bypass (fodhelper.exe) | T1548.002 — Bypass UAC | | LSASS memory access | T1003.001 — LSASS Memory |
### 4. Malware Family Classification
**When the user asks to identify or classify a malware sample:**
**Classification by behavioral patterns:**
| Family Indicators | Likely Family Category | |------------------|----------------------| | Shadow copies deleted + file encryption + ransom note | Ransomware | | Regular HTTP beaconing + command execution + lateral movement | RAT/Botnet | | Browser credential theft + banking overlay | Banking Trojan | | Keylogging + screenshot capture + data exfiltration | Spyware/Infostealer | | Process hollowing + covert persistence | Rootkit/Backdoor | | Cryptocurrency mining process spawning | Cryptominer | | Worm propagation via network shares | Worm | | Document with macro downloading payload | Dropper/Downloader |
**Similarity analysis:** ```bash # SSDeep fuzzy hash comparison ssdeep -l malware.exe > hash.txt ssdeep -m hash.txt similar_sample.exe # Similarity > 70% → likely same family/variant ```
### 5. Sandbox Environment Setup
**When the user asks to set up a malware analysis environment:**
**Minimum isolation requirements:** 1. Dedicated VM (VirtualBox, VMware, KVM) — NEVER use your main machine 2. Host-only or isolated network adapter (NO internet access by default) 3. Snapshot before analysis — restore after each sample 4. Disable shared folders and clipboard (data exfiltration prevention)
**Recommended sandbox stack:** ``` Analysis VM (Windows 10/11 or Ubuntu): ├── FakeNet-NG or INetSim — Simulate network services ├── Wireshark — Capture network traffic ├── ProcessMonitor (Windows) / strace (Linux) — Monitor syscalls ├── Regshot (Windows) — Compare registry before/after ├── Autoruns (Windows) — Monitor persistence locations └── Cuckoo/CAPE Agent — Automated collection
Network Layer: └── Host-only adapter → no real internet → INetSim captures C2 attempts ```
**Anti-anti-VM measures:** - Install VMware Tools (some malware checks for missing tools) - Set reasonable RAM (4GB+) and CPU count (2+) - Add some benign user files and browser history - Set realistic screen resolution (1920x1080) - Remove obvious VM artifacts (registry keys, device names)
---
## IOC Extraction & Output Format
For every analyzed sample, produce:
```markdown ## Malware Analysis Report — [Sample Name]
**Hashes:** - MD5: [hash] - SHA1: [hash] - SHA256: [hash] - SSDeep: [fuzzy hash]
**Classification:** [Ransomware / RAT / Infostealer / etc.] **Confidence:** [High / Medium / Low] **Family:** [Family Name, if identified] **First Seen:** [Date from TI sources]
**Network IOCs:** - IPs: [list] - Domains: [list] - URLs: [list] - User-Agent: [string]
**Host IOCs:
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Malware Analysis & Sandboxing, ready for a manual X post.
Malware Analysis & Sandboxing: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral... 397 stars https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x
Listing + install path for Malware Analysis & Sandboxing: https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing/audit)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsSandbox only
Install targets
Codex install prompt
Install the "Malware Analysis & Sandboxing" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/05-malware-analysis. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-malware-analysis-sandboxing","task":"Install Malware Analysis & Sandboxing","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 73/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
Agent should check
Copy prompt
Task: Use Malware Analysis & Sandboxing in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
LLM text format
/api/skills/masriyan-malware-analysis-sandboxing/install?format=text
Find alternatives
/api/skills/search?q=Malware%20Analysis%20%26%20Sandboxing&limit=3
Agent prompt
Use Malware Analysis & Sandboxing for this task. Review https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-malware-analysis-sandboxing
LLM text
/api/registry/manifest/masriyan-malware-analysis-sandboxing?format=text
Install alias
/api/registry/install/masriyan-malware-analysis-sandboxing
Recommend
/api/registry/recommend?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Malware Analysis & Sandboxing description: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification version: 3.0.0 author: Masriyan tags: [cybersecurity, malware, analysis, yara, sandbox, threat, static-analysis, behavioral] ---
# Malware Analysis & Sandboxing
## Purpose
Enable Claude to assist with malware analysis workflows including static analysis of file properties and code, dynamic behavioral analysis interpretation, YARA rule generation, sandbox configuration, and malware family identification. Claude analyzes provided artifacts directly and orchestrates scripts for automated processing.
> **Safety Warning**: Never execute suspicious files outside of isolated, controlled environments. Use dedicated VMs or sandboxes with network isolation and snapshot capability.
---
## Activation Triggers
This skill activates when the user asks about: - Analyzing a suspicious file, binary, or script - Generating YARA rules for malware detection - Setting up a malware analysis sandbox - Interpreting Cuckoo/CAPE/AnyRun sandbox reports - Identifying malware family or behavior - Creating IOCs from malware samples - Static analysis of PE/ELF files - Memory forensics for malware artifacts - Behavioral analysis (process creation, network, registry, file changes)
---
## Prerequisites
```bash pip install yara-python pefile python-magic requests ssdeep ```
**Recommended analysis tools:** - `Cuckoo Sandbox / CAPE` — Automated dynamic analysis - `VirusTotal API` — Multi-engine scanning and intel - `YARA` — Pattern matching engine - `Ghidra / IDA Pro` — Deep binary analysis (→ Skill 04) - `Volatility 3` — Memory forensics - `DIE (Detect-It-Easy)` — Packer/compiler detection - `Pestudio` — Windows PE static analysis
---
## Core Capabilities
### 1. Static Malware Analysis
**When the user provides a suspicious file or hash for analysis:**
Claude performs analysis in this order:
**Step 1 — File Identification:** ```bash file malware.exe # File type from magic bytes md5sum malware.exe # MD5 hash (legacy, for lookups) sha256sum malware.exe # SHA-256 (primary identifier) python scripts/static_analyzer.py --file malware.exe --hashes ```
**Step 2 — Threat Intelligence Lookup:** - Query VirusTotal (requires API key or paste hash in browser) - Check MalwareBazaar, AbuseIPDB, URLhaus - Search for existing analysis reports ```bash # VirusTotal hash lookup via API curl "https://www.virustotal.com/api/v3/files/<sha256>" -H "x-apikey: YOUR_KEY" ```
**Step 3 — PE Analysis (Windows executables):** ```bash python scripts/static_analyzer.py --file malware.exe --strings --imports --output report.json ```
Look for these indicators in the output:
**Suspicious Import Functions:** | Category | Suspicious APIs | |----------|----------------| | Process Injection | `CreateRemoteThread`, `WriteProcessMemory`, `VirtualAllocEx`, `NtMapViewOfSection`, `RtlCreateUserThread` | | Persistence | `RegSetValueEx`, `CreateService`, `SHFileOperation`, `ITaskScheduler` | | Anti-Analysis | `IsDebuggerPresent`, `CheckRemoteDebuggerPresent`, `GetTickCount`, `QueryPerformanceCounter`, `GetSystemInfo` | | Network C2 | `InternetOpenUrl`, `HttpSendRequest`, `WSAStartup`, `socket`, `URLDownloadToFile`, `WinHttpOpen` | | Crypto Operations | `CryptEncrypt`, `CryptDecrypt`, `BCryptEncrypt`, `CryptHashData` | | Credential Access | `SamOpenDatabase`, `LsaOpenPolicy`, `NtlmGetUserInfo` | | Keylogging | `SetWindowsHookEx`, `GetAsyncKeyState`, `GetKeyboardState` | | Defense Evasion | `VirtualProtect`, `NtSetInformationProcess`, `Wow64DisableWow64FsRedirection` |
**Step 4 — String Extraction & Analysis:** ```bash strings -a malware.exe | grep -E "(http|ftp|/[a-z]|[0-9]{1,3}\.[0-9]{1,3}|HKEY|reg|cmd|powershell)" ```
Categorize extracted strings: - **Network indicators**: URLs, IPs, domains, user agents - **File system**: paths, filenames, registry keys - **Crypto**: base64 blobs, hex strings (potential keys/payloads) - **Anti-analysis**: VM/sandbox detection strings (VMware, VirtualBox, Sandboxie) - **Mutex names**: unique identifiers preventing double-infection
**Step 5 — Entropy Analysis:** ```bash python scripts/static_analyzer.py --file malware.exe --entropy ```
| Entropy Range | Interpretation | |---------------|---------------| | 0.0 – 1.0 | Near-empty or all-zeros section | | 1.0 – 5.0 | Normal code/data section | | 5.0 – 7.0 | Compressed data or code | | 7.0 – 8.0 | Encrypted or packed data — investigate | | 7.9 – 8.0 | Highly suspicious — likely encrypted payload |
### 2. YARA Rule Generation
**When the user asks to create YARA rules from a sample or indicators:**
Claude generates YARA rules following this methodology:
1. **Select stable, unique indicators** — Avoid generic patterns; choose bytes/strings unique to this family 2. **Prefer structural patterns** — Header magic bytes, specific offsets, section names 3. **Balance specificity vs. coverage** — Avoid rules that are too specific (catch only one sample) or too broad (false positives) 4. **Test against benign files** — Rule should NOT match clean Windows system files
**YARA Rule Templates:**
```yara // Tier 1: Specific sample (hash-based) rule MalwareFamily_Variant_Hash { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] [Variant] — specific sample" sha256 = "aabbcc..." tlp = "GREEN" reference = "https://example.com/analysis" condition: hash.sha256(0, filesize) == "aabbcc..." }
// Tier 2: Family-level detection (behavioral strings) rule MalwareFamily_Generic { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] family by strings and structure" tlp = "GREEN" strings: // C2 patterns $c2_ua = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" ascii $c2_uri = "/gate.php?id=" ascii // Crypto constants $rc4_key = { 52 43 34 5F 4B 45 59 } // "RC4_KEY" hex // Mutex $mutex = "Global\\MSDTC_MUTEX_" ascii wide // Registry persistence key $reg_key = "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide nocase // Anti-analysis check $vm_check = "VBOX" ascii wide nocase condition: uint16(0) == 0x5A4D and // MZ header (PE file) filesize < 2MB and ( (2 of ($c2_*)) or ($mutex and 1 of ($reg_key, $rc4_key)) ) and not $vm_check // Exclude sandbox-aware variants }
// Tier 3: Network IOC detection (for NIDS integration) rule MalwareFamily_Network_C2 { meta: description = "Detects [MalwareFamily] C2 communication patterns" type = "network" strings: $beacon_path = "/api/v1/ping?uid=" ascii $beacon_ua = "MalBot/1.0" ascii $checkin_hdr = "X-Command-Key: " ascii condition: any of them } ```
```bash # Generate YARA rules using the script python scripts/yara_generator.py --samples ./malware_samples/ --output rules.yar python scripts/yara_generator.py --file single_sample.exe --rule-name "MalwareFamily" --output rule.yar
# Test rules against benign files yara -r generated_rule.yar /usr/bin/ 2>/dev/null | wc -l # Should be 0 yara generated_rule.yar malware.exe # Should match ```
### 3. Dynamic/Behavioral Analysis
**When the user provides sandbox analysis output or asks about dynamic analysis:**
**Interpreting Cuckoo/CAPE Sandbox Reports:**
Claude analyzes behavioral reports looking for:
1. **Process Tree Analysis:** - Unusual parent-child relationships (Word.exe → PowerShell.exe → cmd.exe) - Process injection indicators (process spawning with different credentials) - Hollowing patterns (legitimate process with suspicious memory)
2. **Network Indicators:** - DNS queries: DGA patterns (random-looking domains), fast-flux - HTTP: Unusual user agents, encoded POST data, beaconing intervals - C2 beaconing detection: Regular interval callbacks (check timing consistency)
3. **File System Changes:** - Shadow copy deletion: `vssadmin delete shadows` → ransomware indicator - Startup persistence: `\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\` - Dropped secondary payloads in temp directories
4. **Registry Modifications:** - Run keys: `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - Service installation: `HKLM\SYSTEM\CurrentControlSet\Services\` - Security policy changes: Disabling UAC, Windows Defender
5. **MITRE ATT&CK Mapping:**
| Observed Behavior | MITRE Technique | |-------------------|----------------| | PowerShell download cradle | T1059.001 — PowerShell | | `cmd /c vssadmin delete shadows` | T1490 — Inhibit System Recovery | | Registry Run key persistence | T1547.001 — Registry Run Keys | | CreateRemoteThread injection | T1055.001 — DLL Injection | | Scheduled task creation | T1053.005 — Scheduled Task | | `netsh advfirewall set allprofiles state off` | T1562.004 — Disable Host Firewall | | UAC bypass (fodhelper.exe) | T1548.002 — Bypass UAC | | LSASS memory access | T1003.001 — LSASS Memory |
### 4. Malware Family Classification
**When the user asks to identify or classify a malware sample:**
**Classification by behavioral patterns:**
| Family Indicators | Likely Family Category | |------------------|----------------------| | Shadow copies deleted + file encryption + ransom note | Ransomware | | Regular HTTP beaconing + command execution + lateral movement | RAT/Botnet | | Browser credential theft + banking overlay | Banking Trojan | | Keylogging + screenshot capture + data exfiltration | Spyware/Infostealer | | Process hollowing + covert persistence | Rootkit/Backdoor | | Cryptocurrency mining process spawning | Cryptominer | | Worm propagation via network shares | Worm | | Document with macro downloading payload | Dropper/Downloader |
**Similarity analysis:** ```bash # SSDeep fuzzy hash comparison ssdeep -l malware.exe > hash.txt ssdeep -m hash.txt similar_sample.exe # Similarity > 70% → likely same family/variant ```
### 5. Sandbox Environment Setup
**When the user asks to set up a malware analysis environment:**
**Minimum isolation requirements:** 1. Dedicated VM (VirtualBox, VMware, KVM) — NEVER use your main machine 2. Host-only or isolated network adapter (NO internet access by default) 3. Snapshot before analysis — restore after each sample 4. Disable shared folders and clipboard (data exfiltration prevention)
**Recommended sandbox stack:** ``` Analysis VM (Windows 10/11 or Ubuntu): ├── FakeNet-NG or INetSim — Simulate network services ├── Wireshark — Capture network traffic ├── ProcessMonitor (Windows) / strace (Linux) — Monitor syscalls ├── Regshot (Windows) — Compare registry before/after ├── Autoruns (Windows) — Monitor persistence locations └── Cuckoo/CAPE Agent — Automated collection
Network Layer: └── Host-only adapter → no real internet → INetSim captures C2 attempts ```
**Anti-anti-VM measures:** - Install VMware Tools (some malware checks for missing tools) - Set reasonable RAM (4GB+) and CPU count (2+) - Add some benign user files and browser history - Set realistic screen resolution (1920x1080) - Remove obvious VM artifacts (registry keys, device names)
---
## IOC Extraction & Output Format
For every analyzed sample, produce:
```markdown ## Malware Analysis Report — [Sample Name]
**Hashes:** - MD5: [hash] - SHA1: [hash] - SHA256: [hash] - SSDeep: [fuzzy hash]
**Classification:** [Ransomware / RAT / Infostealer / etc.] **Confidence:** [High / Medium / Low] **Family:** [Family Name, if identified] **First Seen:** [Date from TI sources]
**Network IOCs:** - IPs: [list] - Domains: [list] - URLs: [list] - User-Agent: [string]
**Host IOCs:
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Malware Analysis & Sandboxing, ready for a manual X post.
Malware Analysis & Sandboxing: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral... 397 stars https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x
Listing + install path for Malware Analysis & Sandboxing: https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing/audit)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsSandbox only
Install targets
Codex install prompt
Install the "Malware Analysis & Sandboxing" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/05-malware-analysis. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-malware-analysis-sandboxing","task":"Install Malware Analysis & Sandboxing","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 73/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
Agent should check
Copy prompt
Task: Use Malware Analysis & Sandboxing in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & Sandboxing
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-malware-analysis-sandboxing/install
LLM text format
/api/skills/masriyan-malware-analysis-sandboxing/install?format=text
Find alternatives
/api/skills/search?q=Malware%20Analysis%20%26%20Sandboxing&limit=3
Agent prompt
Use Malware Analysis & Sandboxing for this task. Review https://www.openagentskill.com/api/skills/masriyan-malware-analysis-sandboxing/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis & SandboxingRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-malware-analysis-sandboxing
LLM text
/api/registry/manifest/masriyan-malware-analysis-sandboxing?format=text
Install alias
/api/registry/install/masriyan-malware-analysis-sandboxing
Recommend
/api/registry/recommend?task=Use%20Malware%20Analysis%20%26%20Sandboxing%20in%20an%20agent%20workflow&limit=3
Agent fit
Workflow automation
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Workflow automation
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Run multimodal agents that operate desktop interfaces
Connect agents to hundreds of workflow automations
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
--- name: Malware Analysis & Sandboxing description: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification version: 3.0.0 author: Masriyan tags: [cybersecurity, malware, analysis, yara, sandbox, threat, static-analysis, behavioral] ---
# Malware Analysis & Sandboxing
## Purpose
Enable Claude to assist with malware analysis workflows including static analysis of file properties and code, dynamic behavioral analysis interpretation, YARA rule generation, sandbox configuration, and malware family identification. Claude analyzes provided artifacts directly and orchestrates scripts for automated processing.
> **Safety Warning**: Never execute suspicious files outside of isolated, controlled environments. Use dedicated VMs or sandboxes with network isolation and snapshot capability.
---
## Activation Triggers
This skill activates when the user asks about: - Analyzing a suspicious file, binary, or script - Generating YARA rules for malware detection - Setting up a malware analysis sandbox - Interpreting Cuckoo/CAPE/AnyRun sandbox reports - Identifying malware family or behavior - Creating IOCs from malware samples - Static analysis of PE/ELF files - Memory forensics for malware artifacts - Behavioral analysis (process creation, network, registry, file changes)
---
## Prerequisites
```bash pip install yara-python pefile python-magic requests ssdeep ```
**Recommended analysis tools:** - `Cuckoo Sandbox / CAPE` — Automated dynamic analysis - `VirusTotal API` — Multi-engine scanning and intel - `YARA` — Pattern matching engine - `Ghidra / IDA Pro` — Deep binary analysis (→ Skill 04) - `Volatility 3` — Memory forensics - `DIE (Detect-It-Easy)` — Packer/compiler detection - `Pestudio` — Windows PE static analysis
---
## Core Capabilities
### 1. Static Malware Analysis
**When the user provides a suspicious file or hash for analysis:**
Claude performs analysis in this order:
**Step 1 — File Identification:** ```bash file malware.exe # File type from magic bytes md5sum malware.exe # MD5 hash (legacy, for lookups) sha256sum malware.exe # SHA-256 (primary identifier) python scripts/static_analyzer.py --file malware.exe --hashes ```
**Step 2 — Threat Intelligence Lookup:** - Query VirusTotal (requires API key or paste hash in browser) - Check MalwareBazaar, AbuseIPDB, URLhaus - Search for existing analysis reports ```bash # VirusTotal hash lookup via API curl "https://www.virustotal.com/api/v3/files/<sha256>" -H "x-apikey: YOUR_KEY" ```
**Step 3 — PE Analysis (Windows executables):** ```bash python scripts/static_analyzer.py --file malware.exe --strings --imports --output report.json ```
Look for these indicators in the output:
**Suspicious Import Functions:** | Category | Suspicious APIs | |----------|----------------| | Process Injection | `CreateRemoteThread`, `WriteProcessMemory`, `VirtualAllocEx`, `NtMapViewOfSection`, `RtlCreateUserThread` | | Persistence | `RegSetValueEx`, `CreateService`, `SHFileOperation`, `ITaskScheduler` | | Anti-Analysis | `IsDebuggerPresent`, `CheckRemoteDebuggerPresent`, `GetTickCount`, `QueryPerformanceCounter`, `GetSystemInfo` | | Network C2 | `InternetOpenUrl`, `HttpSendRequest`, `WSAStartup`, `socket`, `URLDownloadToFile`, `WinHttpOpen` | | Crypto Operations | `CryptEncrypt`, `CryptDecrypt`, `BCryptEncrypt`, `CryptHashData` | | Credential Access | `SamOpenDatabase`, `LsaOpenPolicy`, `NtlmGetUserInfo` | | Keylogging | `SetWindowsHookEx`, `GetAsyncKeyState`, `GetKeyboardState` | | Defense Evasion | `VirtualProtect`, `NtSetInformationProcess`, `Wow64DisableWow64FsRedirection` |
**Step 4 — String Extraction & Analysis:** ```bash strings -a malware.exe | grep -E "(http|ftp|/[a-z]|[0-9]{1,3}\.[0-9]{1,3}|HKEY|reg|cmd|powershell)" ```
Categorize extracted strings: - **Network indicators**: URLs, IPs, domains, user agents - **File system**: paths, filenames, registry keys - **Crypto**: base64 blobs, hex strings (potential keys/payloads) - **Anti-analysis**: VM/sandbox detection strings (VMware, VirtualBox, Sandboxie) - **Mutex names**: unique identifiers preventing double-infection
**Step 5 — Entropy Analysis:** ```bash python scripts/static_analyzer.py --file malware.exe --entropy ```
| Entropy Range | Interpretation | |---------------|---------------| | 0.0 – 1.0 | Near-empty or all-zeros section | | 1.0 – 5.0 | Normal code/data section | | 5.0 – 7.0 | Compressed data or code | | 7.0 – 8.0 | Encrypted or packed data — investigate | | 7.9 – 8.0 | Highly suspicious — likely encrypted payload |
### 2. YARA Rule Generation
**When the user asks to create YARA rules from a sample or indicators:**
Claude generates YARA rules following this methodology:
1. **Select stable, unique indicators** — Avoid generic patterns; choose bytes/strings unique to this family 2. **Prefer structural patterns** — Header magic bytes, specific offsets, section names 3. **Balance specificity vs. coverage** — Avoid rules that are too specific (catch only one sample) or too broad (false positives) 4. **Test against benign files** — Rule should NOT match clean Windows system files
**YARA Rule Templates:**
```yara // Tier 1: Specific sample (hash-based) rule MalwareFamily_Variant_Hash { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] [Variant] — specific sample" sha256 = "aabbcc..." tlp = "GREEN" reference = "https://example.com/analysis" condition: hash.sha256(0, filesize) == "aabbcc..." }
// Tier 2: Family-level detection (behavioral strings) rule MalwareFamily_Generic { meta: author = "Analyst Name" date = "2025-05-28" description = "Detects [MalwareFamily] family by strings and structure" tlp = "GREEN" strings: // C2 patterns $c2_ua = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" ascii $c2_uri = "/gate.php?id=" ascii // Crypto constants $rc4_key = { 52 43 34 5F 4B 45 59 } // "RC4_KEY" hex // Mutex $mutex = "Global\\MSDTC_MUTEX_" ascii wide // Registry persistence key $reg_key = "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide nocase // Anti-analysis check $vm_check = "VBOX" ascii wide nocase condition: uint16(0) == 0x5A4D and // MZ header (PE file) filesize < 2MB and ( (2 of ($c2_*)) or ($mutex and 1 of ($reg_key, $rc4_key)) ) and not $vm_check // Exclude sandbox-aware variants }
// Tier 3: Network IOC detection (for NIDS integration) rule MalwareFamily_Network_C2 { meta: description = "Detects [MalwareFamily] C2 communication patterns" type = "network" strings: $beacon_path = "/api/v1/ping?uid=" ascii $beacon_ua = "MalBot/1.0" ascii $checkin_hdr = "X-Command-Key: " ascii condition: any of them } ```
```bash # Generate YARA rules using the script python scripts/yara_generator.py --samples ./malware_samples/ --output rules.yar python scripts/yara_generator.py --file single_sample.exe --rule-name "MalwareFamily" --output rule.yar
# Test rules against benign files yara -r generated_rule.yar /usr/bin/ 2>/dev/null | wc -l # Should be 0 yara generated_rule.yar malware.exe # Should match ```
### 3. Dynamic/Behavioral Analysis
**When the user provides sandbox analysis output or asks about dynamic analysis:**
**Interpreting Cuckoo/CAPE Sandbox Reports:**
Claude analyzes behavioral reports looking for:
1. **Process Tree Analysis:** - Unusual parent-child relationships (Word.exe → PowerShell.exe → cmd.exe) - Process injection indicators (process spawning with different credentials) - Hollowing patterns (legitimate process with suspicious memory)
2. **Network Indicators:** - DNS queries: DGA patterns (random-looking domains), fast-flux - HTTP: Unusual user agents, encoded POST data, beaconing intervals - C2 beaconing detection: Regular interval callbacks (check timing consistency)
3. **File System Changes:** - Shadow copy deletion: `vssadmin delete shadows` → ransomware indicator - Startup persistence: `\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\` - Dropped secondary payloads in temp directories
4. **Registry Modifications:** - Run keys: `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - Service installation: `HKLM\SYSTEM\CurrentControlSet\Services\` - Security policy changes: Disabling UAC, Windows Defender
5. **MITRE ATT&CK Mapping:**
| Observed Behavior | MITRE Technique | |-------------------|----------------| | PowerShell download cradle | T1059.001 — PowerShell | | `cmd /c vssadmin delete shadows` | T1490 — Inhibit System Recovery | | Registry Run key persistence | T1547.001 — Registry Run Keys | | CreateRemoteThread injection | T1055.001 — DLL Injection | | Scheduled task creation | T1053.005 — Scheduled Task | | `netsh advfirewall set allprofiles state off` | T1562.004 — Disable Host Firewall | | UAC bypass (fodhelper.exe) | T1548.002 — Bypass UAC | | LSASS memory access | T1003.001 — LSASS Memory |
### 4. Malware Family Classification
**When the user asks to identify or classify a malware sample:**
**Classification by behavioral patterns:**
| Family Indicators | Likely Family Category | |------------------|----------------------| | Shadow copies deleted + file encryption + ransom note | Ransomware | | Regular HTTP beaconing + command execution + lateral movement | RAT/Botnet | | Browser credential theft + banking overlay | Banking Trojan | | Keylogging + screenshot capture + data exfiltration | Spyware/Infostealer | | Process hollowing + covert persistence | Rootkit/Backdoor | | Cryptocurrency mining process spawning | Cryptominer | | Worm propagation via network shares | Worm | | Document with macro downloading payload | Dropper/Downloader |
**Similarity analysis:** ```bash # SSDeep fuzzy hash comparison ssdeep -l malware.exe > hash.txt ssdeep -m hash.txt similar_sample.exe # Similarity > 70% → likely same family/variant ```
### 5. Sandbox Environment Setup
**When the user asks to set up a malware analysis environment:**
**Minimum isolation requirements:** 1. Dedicated VM (VirtualBox, VMware, KVM) — NEVER use your main machine 2. Host-only or isolated network adapter (NO internet access by default) 3. Snapshot before analysis — restore after each sample 4. Disable shared folders and clipboard (data exfiltration prevention)
**Recommended sandbox stack:** ``` Analysis VM (Windows 10/11 or Ubuntu): ├── FakeNet-NG or INetSim — Simulate network services ├── Wireshark — Capture network traffic ├── ProcessMonitor (Windows) / strace (Linux) — Monitor syscalls ├── Regshot (Windows) — Compare registry before/after ├── Autoruns (Windows) — Monitor persistence locations └── Cuckoo/CAPE Agent — Automated collection
Network Layer: └── Host-only adapter → no real internet → INetSim captures C2 attempts ```
**Anti-anti-VM measures:** - Install VMware Tools (some malware checks for missing tools) - Set reasonable RAM (4GB+) and CPU count (2+) - Add some benign user files and browser history - Set realistic screen resolution (1920x1080) - Remove obvious VM artifacts (registry keys, device names)
---
## IOC Extraction & Output Format
For every analyzed sample, produce:
```markdown ## Malware Analysis Report — [Sample Name]
**Hashes:** - MD5: [hash] - SHA1: [hash] - SHA256: [hash] - SSDeep: [fuzzy hash]
**Classification:** [Ransomware / RAT / Infostealer / etc.] **Confidence:** [High / Medium / Low] **Family:** [Family Name, if identified] **First Seen:** [Date from TI sources]
**Network IOCs:** - IPs: [list] - Domains: [list] - URLs: [list] - User-Agent: [string]
**Host IOCs:
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Malware Analysis & Sandboxing, ready for a manual X post.
Malware Analysis & Sandboxing: Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral... 397 stars https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x
Listing + install path for Malware Analysis & Sandboxing: https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Malware Analysis...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing/audit)
[](https://www.openagentskill.com/skills/masriyan-malware-analysis-sandboxing?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K Starsn8n
Connect agents to hundreds of workflow automations
194.1K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsTasmota
Alternative firmware for ESP8266 and ESP32 based devices with easy configuration using webUI, OTA updates, automation using timers or rules, expandability and entirely local control over MQTT, HTTP, Serial or KNX. Full documentation at
24.7K StarsPermission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness