tag

malware

24 indexed skills · max 10 per page

skills (24)

malware-analyst

sickn33/antigravity-awesome-skills · Productivity

8

file sample.exe sha256sum sample.exe

performing-dynamic-analysis-with-any-run

mukul975/Anthropic-Cybersecurity-Skills · performing-dynamic-analysis-with-any-run

0

Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage.

analyzing-linux-elf-malware

mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-elf-malware

0

Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.

detecting-process-injection-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-process-injection-techniques

0

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.

analyzing-malware-behavior-with-cuckoo-sandbox

mukul975/Anthropic-Cybersecurity-Skills · analyzing-malware-behavior-with-cuckoo-sandbox

0

Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.

analyzing-bootkit-and-rootkit-samples

mukul975/Anthropic-Cybersecurity-Skills · analyzing-bootkit-and-rootkit-samples

0

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.

detecting-fileless-malware-techniques

mukul975/Anthropic-Cybersecurity-Skills · detecting-fileless-malware-techniques

0

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination.

analyzing-network-traffic-of-malware

mukul975/Anthropic-Cybersecurity-Skills · analyzing-network-traffic-of-malware

0

Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.

reverse-engineering-dotnet-malware-with-dnspy

mukul975/Anthropic-Cybersecurity-Skills · reverse-engineering-dotnet-malware-with-dnspy

0

Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis.

reverse-engineering-malware-with-ghidra

mukul975/Anthropic-Cybersecurity-Skills · reverse-engineering-malware-with-ghidra

0

Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals.

prevpage 1 / 3next