triage-malware

Triage malware hashes with GTI and SIEM enrichment for classification and containment.

120|34|Updated May 9, 2025
One-click install
npx skills add https://github.com/dandye/ai-runbooks --skill triage-malware
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-malware
Source: https://github.com/dandye/ai-runbooks/tree/main/skills/triage-malware
Command: npx skills add https://github.com/dandye/ai-runbooks --skill triage-malware

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage a suspected malicious file hash to quickly determine GTI classification, observed behavior, affected hosts, and recommended containment actions.

Core Features & Use Cases

  • GTI file report enrichment and malware family classification
  • Behavioral indicators extraction (network IOCs, file/registry changes)
  • SIEM context enrichment and case linkage for related investigations

Quick Start

Provide a malware hash to initiate the triage workflow and generate actionable containment recommendations.

Frequently Asked Questions about triage-malware

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage a malware hash to determine containment actions?

To triage a malware hash, provide the file hash to initiate the workflow, which determines GTI classification, observed behavior, affected hosts, and recommended containment actions. It applies during malware alerts or investigations to quickly contextualize events and prioritize remediation.

What malware triage steps extract network IOCs and file behavior indicators?

Malware triage extracts behavioral indicators by applying GTI file report enrichment and analyzing observed behavior. This process identifies network IOCs, file modifications, and registry changes to quickly contextualize malicious events and guide remediation efforts.

How does SIEM context enrichment work during a malware investigation?

SIEM context enrichment works by linking malware hash triage data to related cases and existing security alerts. This integration applies during malware investigations to identify affected hosts, correlate related case information, and produce structured outputs for prioritized remediation.

Can I use this malware triage workflow to identify affected hosts and related cases?

Yes, you can use the malware triage workflow to identify affected hosts and related cases. By providing a suspected malicious file hash, the workflow applies SIEM context enrichment and case linkage to generate structured containment recommendations and prioritize remediation.

What is the best way to prioritize remediation during a malware alert?

The best way to prioritize remediation during a malware alert is to triage the suspected malicious file hash using GTI classification and behavioral indicators. This quickly contextualizes the event, identifies affected hosts, and generates actionable containment recommendations.

Do I need a specific hash format to start the malware triage process?

You need to provide a suspected malware hash to start the triage process. The workflow uses this hash to determine GTI classification, extract behavioral indicators like network IOCs, and recommend containment actions, requiring no additional dependencies.