Agent skill

Malware Analysis

by hypnguyen1209 in hypnguyen1209/offensive-claude

A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

MITAuto-check passedSecurity

Install Malware Analysis

skills CLI
$ npx skills add hypnguyen1209/offensive-claude --skill malware-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hypnguyen1209/offensive-claude malware-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malware-analysis .claude/skills/malware-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
malware-analysis
GitHub stars
388
Token cost
~2.3k tokens
SKILL.md length
538 words
Files
14 (incl. scripts, references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

  • Reverse-engineering
  • SKILL.md covers When to Activate, Technique Map, Quick Start and OPSEC & Detection (summary), plus 1 more section
  • Runs Python and JavaScript scripts from its folder; calls python3
  • Detecting malware — static triage + capa/YARA-X

What it does

Malware Analysis is an agent skill from hypnguyen1209/offensive-claude. Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `references/config-c2-extraction.md`, `references/dynamic-fileless-memory.md` and `references/network-c2-detection.md`).

It sits in Security, covering Reverse engineering and malware. It works with .NET and Frida. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.

When your agent uses it

  • Reverse-engineering
  • Detecting malware — static triage + capa/YARA-X
  • Emulation/DBI/.NET unpacking
  • Dynamic/fileless/Volatility 3 memory analysis

Example prompts

  • “/malware-analysis”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 7 files in scripts/ (Python and JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Malware Analysis loads about 2.3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 538 words, ~2,288 tokens.

Download SKILL.mdSave it as .claude/skills/malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
malware-analysis
description
Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)
metadata.type
defensive
metadata.phase
analysis
metadata.tools
capa, FLOSS, YARA-X, pefile, x64dbg, dnSpyEx, de4dot, Frida, Qiling, Speakeasy, unipacker, Volatility3, FakeNet-NG, INetSim, 1768.py, CobaltStrikeParser…
metadata.mitre
TA0042
kill_chain.phase
weaponize
kill_chain.step
2
kill_chain.attck_tactics
TA0042, TA0005, TA0011
kill_chain.attck_techniques
T1027, T1027.002, T1027.013, T1140, T1055, T1055.012, T1620, T1562.001, T1497, T1547.001, T1546.003, T1059.001, T1071.001, T1071.004, T1573, T1572, T1568.002…
depends_on
reverse-engineering
feeds_into
threat-hunting, incident-response, edr-evasion, network-attack

Malware Analysis

When to Activate

  • Triaging an unknown binary/script: identity, packing verdict, capability map, IOCs, go/no-go for detonation.
  • Recovering the real payload from a packed/crypted/obfuscated loader (commodity loaders, RAT chains, .NET).
  • Detonating safely and recovering fileless / in-memory artifacts (injection, AMSI/ETW patching, WMI persistence).
  • Extracting malware configuration (C2, keys, sleep/jitter, campaign IDs) for threat intel and detection.
  • Detecting/characterizing C2 on the wire (beacon cadence, JA4+ fingerprints, tunneled/DoH channels).
  • Writing durable, low-FP YARA-X detection from analysis findings; incident-response scoping.

Technique Map

TechniqueATT&CKCWEReferenceScript
Hash/imphash/Rich/ssdeep/TLSH triage + PE anomaliesT1027CWE-506references/static-triage-capa.mdscripts/triage.py
Per-section entropy + packer/RWX/EP heuristicsT1027.002CWE-1066references/static-triage-capa.mdscripts/triage.py
Obfuscated string recovery (FLOSS)T1140, T1027.013CWE-656references/static-triage-capa.mdscripts/triage.py
Capability detection → ATT&CK (capa, static+dynamic)T1027CWE-506references/static-triage-capa.mdscripts/triage.py
Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling)T1140, T1620CWE-656references/unpacking-deobfuscation.mdscripts/auto_unpack.py
DBI unpacking via API hooks (Frida)T1055, T1620CWE-656references/unpacking-deobfuscation.mdscripts/frida_unpack.js
.NET deobfuscation/unpacking (de4dot/dnSpyEx)T1027, T1140CWE-656references/unpacking-deobfuscation.mdscripts/frida_unpack.js
Sandbox detonation + behavioral captureT1497CWE-506references/dynamic-fileless-memory.mdscripts/mem_triage.py
Memory injection/hollowing/ghosting analysis (Vol3)T1055, T1055.012CWE-506references/dynamic-fileless-memory.mdscripts/mem_triage.py
AMSI/ETW in-memory patch + patchless detectionT1562.001CWE-693references/dynamic-fileless-memory.mdscripts/mem_triage.py
Fileless WMI/registry/PowerShell persistenceT1546.003, T1547.001, T1059.001CWE-506references/dynamic-fileless-memory.mdscripts/mem_triage.py
Cobalt Strike / AdaptixC2 config extractionT1071.001, T1573CWE-798references/config-c2-extraction.mdscripts/cs_config_extract.py
Config framework at scale (MACO/CAPE)T1071.001CWE-798references/config-c2-extraction.mdscripts/cs_config_extract.py
Generic unknown-C2 protocol RE + decoderT1573, T1071.004CWE-311references/config-c2-extraction.mdscripts/cs_config_extract.py
Beacon cadence/jitter detection (PCAP/Zeek)T1071.001, T1029CWE-778references/network-c2-detection.mdscripts/beacon_profiler.py
JA4+ TLS/HTTP/cert fingerprinting (Sliver/Havoc JA4X)T1071.001, T1573CWE-295references/network-c2-detection.mdscripts/beacon_profiler.py
Tunneled/DoH C2 surfacing (cloudflared/chisel)T1572, T1568.002, T1071.004CWE-441references/network-c2-detection.mdscripts/beacon_profiler.py
YARA-X family rule authoring + FP validationT1027CWE-506references/yara-detection-engineering.mdscripts/yara_gen.py

Quick Start

bash
# 1. Static triage: hashes + PE anomalies + capability combos + FLOSS/capa/YARA-X
python3 scripts/triage.py sample.exe --floss --capa --yara rules/family.yar --json out/triage.json
capa -j sample.exe > out/capa.json                       # capabilities -> ATT&CK

# 2. Unpack (try emulation first; DBI fallback in isolated VM)
python3 scripts/auto_unpack.py sample.exe -o out/dumps/  # static emulation, no detonation
frida -f C:\sample.exe -l scripts/frida_unpack.js --no-pause   # DBI, isolated VM only
de4dot sample.exe -o cleaned.exe                         # .NET layer

# 3. Dynamic + memory (capture mem BEFORE remediation)
python3 scripts/mem_triage.py -f mem.raw --vol vol --patch-hunt --json out/mem.json

# 4. Config + C2 extraction
python3 scripts/cs_config_extract.py beacon.bin --json    # Cobalt Strike
python3 1768.py -S beacon.bin                             # full CS incl. runtime/heap config
configextractor sample.bin                               # MACO/MWCP/CAPE at scale

# 5. Network C2 detection
python3 scripts/beacon_profiler.py capture.pcap --min-beacons 6     # cadence/jitter
zeek -r capture.pcap LOCAL ja4 && zeek-cut ja4 ja4s ja4x < ja4.log  # JA4+ pivots

# 6. Detection engineering
python3 scripts/yara_gen.py --family samples/fam/ --name Fam --goodware /usr/bin --out rules/fam.yar
yara-x fmt rules/fam.yar && yara-x scan rules/fam.yar /corpus/
Show full SKILL.md (288 more words)Show less

OPSEC & Detection (summary)

TechniqueTelemetry/IOCDetection (Sigma/EDR)OPSEC note
Static triageNone (offline)n/a — feeds YARA/imphash huntingRead-only, no execution; isolate sample dir
Emulation unpackNone (no detonation)n/aPreferred first pass; safe, no network
DBI/manual unpackSysmon 8/10 (CallTrace UNKNOWN), RWX commitEDR memory scan; RWX-then-exec SigmaDETONATES — isolated VM, snapshot, FakeNet; loaders self-delete, dump first
Injection/hollowingmalfind/hollowprocesses; EID 8/10Vol3 hollow/ghosting/pebmasquerade; CreateRemoteThreadCapture memory pre-remediation
AMSI/ETW patchamsi.dll load + patched prologue; B8 00..C3 stubSigma T1562.001; debug-reg+VEH for patchlessPatchless evades byte scans — watch Dr0-Dr7
Fileless persistenceWMI consumers; PS 4104; Run-key blobsVol3 registry/wmi; Sysmon 13/22Lives in WMI/registry/memory — no disk file
Config extractionC2 host/UA/pipe/watermarkYARA config table; Suricata on C2 URI/SNIOffline; handle watermark/keys per ROE
Beacon detectionPeriodic outbound deltasbeacon_profiler CV score; Suricata thresholdPassive on captured traffic
JA4+ fingerprintJA4/JA4S/JA4X/JA4H tuplesZeek ja4 watchlist (Sliver/Havoc JA4X)JA4X needs TLS1.3 cert visibility at proxy
YARA-X authoringNoneThe rules themselvesValidate 0-FP on goodware before deploy

Deep Dives

  • references/static-triage-capa.md — Identity/code hashes, Rich header, entropy/packer heuristics, FLOSS, capa (PE/ELF/.NET/shellcode + dynamic capa over CAPE, Android rules, capa Explorer Web), FLARE-VM 2025.
  • references/unpacking-deobfuscation.md — Self-modifying-stub oracle, emulation (auto_unpack/unipacker/Speakeasy/Qiling), Frida DBI hooks, x64dbg→OEP→Scylla, .NET (de4dot/dnSpyEx), Latrodectus 1.4 AES strings, AsyncRAT fileless loaders, garble/pyc.
  • references/dynamic-fileless-memory.md — Sandbox build, Volatility 3 injection playbook + 2025 contest plugins (PEScan/Fileless Hunter), AMSI/ETW patch IOCs + patchless VEH bypass, WMI/registry/PS fileless persistence.
  • references/config-c2-extraction.md — Cobalt Strike (1768.py runtime config, CobaltStrikeParser XOR 0x69/0x2e), AdaptixC2 (Unit 42, 2025), MACO/configextractor-py/CAPEv2 at scale, generic unknown-C2 decoder methodology.
  • references/network-c2-detection.md — Beacon cadence/CV scoring, JA4+ suite (JA4X for randomized-cert Sliver/Havoc, Zeek/TheHive 2025-26), tunneled/DoH C2 (cloudflared/TryCloudflare/chisel), Suricata/Sigma + ransomware 2025 tradecraft.
  • references/yara-detection-engineering.md — YARA-X 1.0 (Rust, 99% compat, fmt/WASM, perf caveats), code/byte > string rules, pe/math modules, threshold logic, goodware FP validation, memory+disk scanning, capa pairing.

© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/malware-analysis of hypnguyen1209/offensive-claude.

  • SKILL.md
  • references/config-c2-extraction.md
  • references/dynamic-fileless-memory.md
  • references/network-c2-detection.md
  • references/static-triage-capa.md
  • references/unpacking-deobfuscation.md
  • references/yara-detection-engineering.md
  • scripts/auto_unpack.py
  • scripts/beacon_profiler.py
  • scripts/cs_config_extract.py
  • scripts/frida_unpack.js
  • scripts/mem_triage.py
  • scripts/triage.py
  • scripts/yara_gen.py

Open the folder on GitHubat commit a506ad3

Compare with similar skills

Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Malware Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Malware Analysis this skillhypnguyen1209/offensive-claude388—~2.3kAutomated safety check: PassMIT
Nes Decompilejonathanpeppers/dotnes780—~1.6kAutomated safety check: PassMIT
Patch Diff AnalyzerHacktronAI/skills115—~2.2kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Rev Unicorn Debugindex-login/MobileRE-Skill144—~1.9kAutomated safety check: PassMIT
Karpathy Guidelinesindex-login/MobileRE-Skill144—~242Automated safety check: PassMIT

Similar skills

  • Nes Decompile

    jonathanpeppers/dotnes

    Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes.

    780 GitHub stars~1.6k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Patch Diff Analyzer

    HacktronAI/skills

    Specialized in reverse-engineering compiled binaries (JARs, DLLs).

    115 GitHub stars~2.2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    144 GitHub stars~1.9k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    144 GitHub stars~242 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed

More from hypnguyen1209/offensive-claude

All 9 skills in this repo
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    388 GitHub stars~2.2k tokensUpdated 11 days ago
    Auto-check passed
  • Incident Response

    hypnguyen1209/offensive-claude

    A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

    388 GitHub stars~2.5k tokensUpdated 11 days ago
    Auto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 11 days ago
    Auto-check passed
  • Threat Hunting

    hypnguyen1209/offensive-claude

    A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…

    388 GitHub stars~2.4k tokensUpdated 11 days ago
    Auto-check passed
  • Threat Model Discipline

    hypnguyen1209/offensive-claude

    A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

    388 GitHub stars~660 tokensUpdated 11 days ago
    Auto-check passed
  • Writing Offensive Skills

    hypnguyen1209/offensive-claude

    A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…

    388 GitHub stars~826 tokensUpdated 11 days ago
    Auto-check passed

Works with

Categories

Questions about Malware Analysis

What does Malware Analysis do?

A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…. Malware Analysis is an agent skill from hypnguyen1209/offensive-claude.

When should I use Malware Analysis?

Malware Analysis fits situations like: reverse-engineering; detecting malware — static triage + capa/YARA-X; emulation/DBI/.NET unpacking; dynamic/fileless/Volatility 3 memory analysis.

How do I install Malware Analysis in Claude Code?

Run `npx skills add hypnguyen1209/offensive-claude --skill malware-analysis -a claude-code`. Or copy the skill folder (skills/malware-analysis in hypnguyen1209/offensive-claude) into .claude/skills/malware-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Malware Analysis in Codex?

Run `npx skills add hypnguyen1209/offensive-claude --skill malware-analysis -a codex`. Or copy the skill folder (skills/malware-analysis in hypnguyen1209/offensive-claude) into .agents/skills/malware-analysis in your project. Codex loads it when a task matches its description.

Can I use Malware Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malware-analysis, .gemini/skills/malware-analysis, .github/skills/malware-analysis and .opencode/skills/malware-analysis in your project.

What does Malware Analysis need to run?

Going by SKILL.md and its folder, Malware Analysis needs Python and JavaScript for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; Node.js.

Does Malware Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Malware Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Malware Analysis use?

Malware Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Malware Analysis use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Malware Analysis?

Skills that share tags, products or a category with Malware Analysis: Nes Decompile (jonathanpeppers/dotnes, 780 stars), Patch Diff Analyzer (HacktronAI/skills, 115 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and Rev Unicorn Debug (index-login/MobileRE-Skill, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Malware Analysis?

hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.

Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.