tag

malware

24 indexed skills · max 10 per page

skills (24)

analyzing-memory-dumps-with-volatility

mukul975/Anthropic-Cybersecurity-Skills · analyzing-memory-dumps-with-volatility

0

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation.

analyzing-command-and-control-communication

mukul975/Anthropic-Cybersecurity-Skills · analyzing-command-and-control-communication

0

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.

detecting-rootkit-activity

mukul975/Anthropic-Cybersecurity-Skills · detecting-rootkit-activity

0

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.

analyzing-pdf-malware-with-pdfid

mukul975/Anthropic-Cybersecurity-Skills · analyzing-pdf-malware-with-pdfid

0

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.

analyzing-packed-malware-with-upx-unpacker

mukul975/Anthropic-Cybersecurity-Skills · analyzing-packed-malware-with-upx-unpacker

0

Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.

performing-firmware-malware-analysis

mukul975/Anthropic-Cybersecurity-Skills · performing-firmware-malware-analysis

0

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.

analyzing-macro-malware-in-office-documents

mukul975/Anthropic-Cybersecurity-Skills · analyzing-macro-malware-in-office-documents

0

Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.

deobfuscating-javascript-malware

mukul975/Anthropic-Cybersecurity-Skills · deobfuscating-javascript-malware

0

Deobfuscates malicious JavaScript code used in web-based attacks, phishing pages, and dropper scripts by reversing encoding layers, eval chains, string manipulation, and control flow obfuscation to reveal the original malicious logic. Activates for requests involving JavaScript malware analysis, script deobfuscation, web skimmer analysis, or obfuscated dropper investigation.

performing-malware-triage-with-yara

mukul975/Anthropic-Cybersecurity-Skills · performing-malware-triage-with-yara

0

Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.

analyzing-ransomware-encryption-mechanisms

mukul975/Anthropic-Cybersecurity-Skills · analyzing-ransomware-encryption-mechanisms

0

Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.

prevpage 2 / 3next