malware-analysis

Dissect malware samples to produce threat intelligence and IOCs.

338|59|Updated May 19, 2026
One-click install
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill malware-analysis-hypnguyen1209
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: malware-analysis
Source: https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/malware-analysis
Command: npx skills add https://github.com/hypnguyen1209/offensive-claude --skill malware-analysis-hypnguyen1209

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Analyzing malware samples is complex and time-consuming, needing structured workflows to identify capabilities, evasion techniques, and indicators of compromise.

Core Features & Use Cases

  • Static and dynamic analysis workflows for malware samples
  • YARA rule creation, sandbox evasion detection, and behavioral profiling
  • Unpacking techniques and anti-analysis bypass strategies
  • Producing actionable threat intelligence and IOCs for SOC

Quick Start

Load a suspicious sample into the analysis environment and begin the static analysis phase to generate YARA rules and behavioral profiles.

Frequently Asked Questions about malware-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform static and dynamic malware analysis on a suspicious sample?

Static and dynamic malware analysis dissects suspicious samples by applying unpacking techniques and behavioral profiling to identify capabilities, evasion techniques, and indicators of compromise for incident response.

What is sandbox evasion detection in malware forensics?

Sandbox evasion detection in malware forensics identifies anti-analysis bypass strategies used by malware samples to avoid triggering behavioral profiling, ensuring accurate threat intelligence and detailed behavioral reports for SOC teams.

How do I create YARA rules from malware samples?

Creating YARA rules from malware samples involves loading suspicious files into an analysis environment and beginning the static analysis phase to generate rules and behavioral profiles that support incident response workflows.

Can I extract actionable IOCs for SOC operations from malware analysis?

Extracting actionable IOCs for SOC operations is supported by structured malware analysis workflows that produce detailed indicators of compromise and threat intelligence across multiple malware families.

What is the best way to unpack malware and bypass anti-analysis techniques?

Unpacking malware and bypassing anti-analysis techniques requires structured workflows that dissect malware samples, identifying evasion techniques and capabilities to produce actionable threat intelligence for incident response.

When do I need behavioral profiling for incident response?

Behavioral profiling for incident response is needed when analyzing malware samples to identify sandbox evasion detection, unpacking techniques, and anti-analysis bypass strategies, producing structured threat intelligence and IOCs.