malware-triage

v2026.09.25

Safely triage unknown malware samples — static indicators, sandbox execution, behavior extraction, and reporting. Use when analyzing suspicious files during investigations.

GitHub
安装命令
npx skhub add securityskills/malware-triage
Markdown
SKILL.md

Malware Triage

Analyze suspicious samples safely and extract actionable indicators fast.

Safety First

  • Isolated VM or dedicated sandbox (Cuckoo/ANY.RUN/vendor sandbox), network simulated or sinkholed
  • Samples stored in password-protected archives, hash-named; never opened on analysis-adjacent hosts
  • Work from snapshots; revert after every detonation

1. Static Triage

  • Hashes (MD5/SHA256), file type, entropy (file, pestudio-style overview)
  • Strings: URLs, mutexes, registry paths, PDB paths, C2 patterns
  • PE specifics: imports of interest (network, process injection, crypto APIs), digital signature validity, packer detection (entropy + section names)
  • Document metadata (Office macros, embedded objects, remote templates)

2. Dynamic Detonation

  • Execute in sandbox with monitoring: file, registry, network, process activity
  • Capture: dropped files, persistence mechanism, C2 beacons (domains/IPs with ports/protocols)
  • Trigger-dependent malware: require user interaction simulation, geo/fate checks, or debugger awareness — escalate to debugging if silent

3. Behavior Extraction

  • Persistence: Run keys, services, scheduled tasks, WMI subscriptions
  • Injection: process hollowing, APC, SetWindowsHookEx targets
  • Exfiltration: DNS tunneling patterns, HTTP POST shapes, known protocol beacons
  • Defense evasion: AV service stops, AMSI/ETW patching, timestamp manipulation

4. Classification and Reporting

  • Family attribution via YARA rules against sample set; note confidence
  • Map observed behavior to ATT&CK techniques
  • Produce: IOCs (machine-readable, STIX if required), detection guidance (YARA + behavioral), and a one-page triage summary

Escalation Criteria

Deep-dive reversing (IDA/Ghidra) only when: C2 protocol reconstruction, config extraction, or unpacking is required for detection/response — not for curiosity.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

2026年9月25日

分类

未分类

许可证

未指定

源路径

malware-analysis/malware-triage

默认分支

main

最新提交

b2b6b52

Tree SHA

8db485b