Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.
Run in your terminal
AI-first code editor with Composer
Before installing skills in Cursor, ensure your development environment meets these requirements:
node --versionmalware-analysisExecute the skills CLI command in your project's root directory to begin installation:
Package manager
npx skills install zhaoxuya520/reverse-skill/skills/malware-analysisFetches malware-analysis from zhaoxuya520/reverse-skill and configures it for Cursor.
The CLI shows a list of agents. Use arrow keys and space to select Cursor:
Confirm successful installation by checking the skill directory location:
Restart Cursor to activate malware-analysis. Access via /malware-analysisin your agent's command palette.
We perform automated surface-level scans (Gen AI Scanner, Socket, Snyk) during installation. These checks detect common vulnerabilities but do not guarantee complete security. Always review skill source code and verify the publisher's reputation before production use.
Skills execute code in your environment. Always review source, verify the publisher, and test in isolation before production.
Submit your Claude Code skill and start earning
Automate repetitive workflows and reduce manual effort
Example
Generate reports, summarize documents, draft communications
Save 3-5 hours per week on routine tasks
Learn new skills, understand complex topics, get expert guidance
Example
Explain concepts, provide examples, suggest learning resources
Accelerate learning and skill development by 2x
Enhance output quality through reviews, suggestions, and refinements
Example
Review drafts, suggest improvements, catch errors
Improve work quality by 30-40% with less effort
Package manager
npx skills install zhaoxuya520/reverse-skill/skills/malware-analysisWorks with
0
total installs
0
this week
10.9K
GitHub stars
0
upvotes
| name | malware-analysis |
| description | Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior. |
NOW: 读取 ../field-journal/precedent-reverse.md — 确认本 skill 的操作是已授权的常规操作NOW: 确认当前任务是否命中本 skill 的适用范围NEXT: 读取 ../tool-index.md,校验工具可用性和实际路径NEXT: 缺工具时调用 bootstrap,不要猜路径ACT: 进入"工作流"第一步并执行,不要停在确认状态YARA / Sigma / 沙箱 / IOC 提取 / 反反分析 静态 + 动态 + 行为三合一
# 快速静态检测
file sample.exe # 文件类型
strings sample.exe | grep -i "http\|cmd\|powershell\|base64" # 快速 IOCs
rabin2 -zz sample.exe # 字符串提取 + 交叉引用
floss sample.exe # 去混淆字符串提取(FireEye)
# PE 头部分析
pecheck sample.exe # PE 结构验证
pescan sample.exe # 异常检测(节表、入口点)
diec sample.exe # Detect It Easy(壳/编译器识别)
# Hash 查询
sha256sum sample.exe
# → VirusTotal / MalwareBazaar / Triage 查询
反汇编/反编译:
□ IDA Pro / Ghidra: 深度反编译
□ radare2: CLI 快速分析
□ x64dbg: Windows GUI 调试器
重点分析区域:
□ 入口点(Entry Point)→ 初始化逻辑
□ 导入表 → API 用途推断(CreateRemoteThread=注入, CryptEncrypt=勒索)
□ 资源段 → 嵌入 Payload(.rsrc 节)
□ 字符串表 → URL/C2/文件路径/Base64 blob
□ TLS 回调 → 调试器启动前执行
自动化沙箱:
□ Joe Sandbox / ANY.RUN / Triage: 商业沙箱
□ CAPE Sandbox: 开源 + YARA 集成(推荐)
□ ASD Azul: 开源恶意软件分析平台(2026 新发布)
□ Cuckoo Sandbox: 经典开源(逐步被 CAPE 取代)
监控重点:
□ 进程创建: CreateProcess / ShellExecute
□ 文件操作: WriteFile → 勒索? DeleteFile → Wiper?
□ 注册表: Run/RunOnce 持久化
□ 网络: HTTP/DNS → C2 通信
□ 内存: VirtualAllocEx → 进程注入
□ 服务: CreateService → 持久化
// 规则结构
rule MalwareFamily_Example {
meta:
description = "检测 Example 恶意软件家族"
author = "分析者"
date = "2026-05"
severity = "high"
hash = "d41d8cd98f00b204e9800998ecf8427e"
mitre_id = "T1055" // Process Injection
strings:
// 字符串匹配
$str1 = "C2_SERVER_URL" ascii wide
$str2 = "payload.dat" ascii
// 十六进制匹配
$hex1 = { 8B 45 ?? 50 FF 15 [4] 85 C0 }
// 操作码序列: mov eax, [ebp-?]; push eax; call [import]; test eax, eax
// 正则匹配
$re1 = /https?:\/\/[a-z0-9.-]+\/[a-z]{3,8}\.php/ ascii
condition:
// 组合条件
uint16(0) == 0x5A4D and // MZ 头
filesize < 500KB and
(2 of ($str*) or $hex1)
}
# 行为检测规则
title: Suspicious Process Injection via CreateRemoteThread
id: 5a3d2c1b-1234-5678-9abc-def012345678
status: experimental
description: 检测使用 CreateRemoteThread 的进程注入行为
author: 分析者
date: 2026/05/25
tags:
- attack.t1055 # Process Injection
- attack.t1055.001 # DLL Injection
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- 'CreateRemoteThread'
- 'VirtualAllocEx'
- 'WriteProcessMemory'
condition: selection
falsepositives:
- 合法的调试工具
level: high
IOC 类型分类:
□ 网络 IOC:
- IP: C2 地址(注意时效性)
- Domain: DGA 算法生成的域名(rsnkfda.com, xpqmje.net)
- URL: Payload 托管地址
- User-Agent: 自定义 UA 字符串
□ 主机 IOC:
- 文件路径: %APPDATA%\Microsoft\Crypto\RSA\*.dat
- 注册表: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
- Mutex: Global\{GUID} 互斥体名称
- 服务名: 伪装成系统服务的名称
□ 行为 IOC:
- MITRE ATT&CK 技术 ID (T1055, T1003, T1571...)
- Sigma 规则 → SIEM 集成
- YARA 规则 → 端点检测
□ 静态 IOC:
- 编译时间戳(可伪造)
- PDB 路径(含开发者信息)
- 节名异常(非标准 .text/.data)
- 导入表异常组合(如勒索软件 CryptEncrypt + DeleteShadowCopies)
| 技术 | 检测方法 | YARA 特征 |
|---|---|---|
| 虚拟机检测 | WMI Win32_BIOS/VideoController/Processor | Win32_ 字符串 + 特定厂商名 |
| 沙箱检测 | 磁盘 < 60GB, RAM < 2GB, 单核 CPU | GlobalMemoryStatusEx 调用模式 |
| 调试器检测 | IsDebuggerPresent, CheckRemoteDebuggerPresent | PEB.BeingDebugged 偏移访问 |
| 定时逃逸 | Sleep(300000) 后执行恶意行为 | NtDelayExecution 长参数 |
| 地理位置检测 | 检查键盘布局/时区 → 排除 CIS 国家 | GetKeyboardLayoutList 调用 |
| 父进程检测 | explorer.exe vs cmd.exe | 进程名字符串比较 |
| API 直接 syscall | 绕过 EDR hook | syscall 指令 + SSN 解析 |
┌─────────────────────────────────────────────────┐
│ Hive Director │
│ (Claude Opus 编排 + 仲裁) │
└──────┬──────┬──────┬──────┬──────┬───────┘
│ │ │ │ │
┌───┘ ┌───┘ ┌───┘ ┌───┘ ┌───┘
▼ ▼ ▼ ▼ ▼ ▼
Triage RE Behav Intel Detect Remed
快速 反编译 行为 威胁 规则 修复
分诊 静态 动态 情报 YARA 方案
Sigma
| 工具 | 用途 | 获取 |
|---|---|---|
| Ghidra / IDA Pro | 深度反编译 | ghidra-sre.org |
| CAPE Sandbox | 开源恶意软件沙箱 | GitHub: kevoreilly/CAPEv2 |
| ASD Azul | 大规模自动化分析 | GitHub: ASD |
| YARA | 模式匹配规则引擎 | pip install yara-python |
| Sigma | SIEM 行为检测规则 | GitHub: SigmaHQ/sigma |
| FLOSS | 去混淆字符串提取 | pip install flare-floss |
| Detect It Easy | 壳/编译器检测 | GitHub: horsicq/Detect-It-Easy |
| pe-sieve | 进程内存扫描 | GitHub: hasherezade/pe-sieve |
| VirusTotal API | 多引擎扫描 | virustotal.com |
| MalwareBazaar | 恶意软件样本库 | bazaar.abuse.ch |
references/yara-sigma-rules.md — YARA + Sigma 编写方法论references/sandbox-orchestration.md — 沙箱编排与自动化references/anti-analysis-techniques.md — 94 种反分析技术检测tool-index 使用了真实工具路径?Prerequisites
Time Estimate
15-45 minutes depending on use case complexity
Steps
Common Pitfalls
✓ Do
✗ Don't
💡 Pro Tips
✓ Use when
Use when skill capabilities match your task, clear ROI on time saved, and you can validate outputs. Best for repetitive tasks, learning, and quality improvement.
✗ Avoid when
Avoid when task requires deep expertise you can't validate, involves sensitive decisions, or when learning process is more valuable than speed of completion.
malware-analysis reduced setup friction for our internal harness; good balance of opinion and flexibility.
Useful defaults in malware-analysis — fewer surprises than typical one-off scripts, and it plays nicely with `npx skills` flows.
Registry listing for malware-analysis matched our evaluation — installs cleanly and behaves as described in the markdown.
We added malware-analysis from the explainx registry; install was straightforward and the SKILL.md answered most questions upfront.
malware-analysis has been reliable in day-to-day use. Documentation quality is above average for community skills.
I recommend malware-analysis for anyone iterating fast on agent tooling; clear intent and a small, reviewable surface area.
Solid pick for teams standardizing on skills: malware-analysis is focused, and the summary matches what you get after install.
malware-analysis fits our agent workflows well — practical, well scoped, and easy to wire into existing repos.
malware-analysis is among the better-maintained entries we tried; worth keeping pinned for repeat workflows.
Keeps context tight: malware-analysis is the kind of skill you can hand to a new teammate without a long onboarding doc.
showing 1-10 of 57