Agent skill

Ctf Malware

by ljagiello in ljagiello/ctf-skills

Provides malware analysis and network traffic techniques for CTF challenges.

MITAuto-check: notesSecurity

Install Ctf Malware

skills CLI
$ npx skills add ljagiello/ctf-skills --skill ctf-malware -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ljagiello/ctf-skills ctf-malware --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ljagiello/ctf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ctf-malware .claude/skills/ctf-malware && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ctf-malware
GitHub stars
3.4k
Token cost
~2.1k tokens
SKILL.md length
630 words
Files
4
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Provides malware analysis and network traffic techniques for CTF challenges.

  • Analyzing obfuscated scripts
  • SKILL.md covers Prerequisites, Additional Resources, When to Pivot and Quick Start Commands, plus 22 more sections
  • Calls pip, apt and brew
  • Malicious packages

What it does

Ctf Malware is an agent skill from ljagiello/ctf-skills. Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility malfind, process injection detection), anti-analysis techniques (VM/sandbox detection, timing evasion, API hashing, process injection, environment checks), or extracting malware configurations and indicators of compromise.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `c2-and-protocols.md`, `pe-and-dotnet.md` and `scripts-and-obfuscation.md`). Compatibility notes: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.

It sits in Security, covering Capture the flag, Reverse engineering and malware and Digital forensics. It works with .NET and PowerShell. The repository describes itself as: Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more. The licence is MIT.

When your agent uses it

  • Analyzing obfuscated scripts
  • Malicious packages
  • Custom crypto protocols
  • PE/.NET binaries

Example prompts

  • “Use the ctf-malware skill to provide malware analysis and network traffic techniques for CTF challenges”
  • “/ctf-malware”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch

What it can do on your machine

Read from SKILL.md and the folder at commit c332c7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Task
    • WebFetch
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • apt
    • brew
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Ctf Malware loads about 2.1k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 630 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ljagiello/ctf-skills at commit c332c7b, republished under its MIT licence (© ljagiello). 630 words, ~2,098 tokens.

Download SKILL.mdSave it as .claude/skills/ctf-malware/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
ctf-malware
description
Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility malfind, process injection detection), anti-analysis techniques (VM/sandbox detection, timing evasion, API hashing, process injection, environment checks), or extracting malware configurations and indicators of compromise.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch
compatibility
Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation.
license
MIT
metadata.user-invocable
false

CTF Malware & Network Analysis

Quick reference for malware analysis CTF challenges. Each technique has a one-liner here; see supporting files for full details with code.

Prerequisites

Python packages (all platforms):

bash
pip install yara-python pefile capstone oletools unicorn pycryptodome \
  volatility3 dissect.cobaltstrike

Linux (apt):

bash
apt install strace ltrace tshark binwalk binutils

macOS (Homebrew):

bash
brew install wireshark binwalk binutils ghidra

Manual install:

  • dnSpy — GitHub, .NET decompiler (Windows)

Additional Resources

  • scripts-and-obfuscation.md - JavaScript deobfuscation, PowerShell analysis, eval/base64 decoding, junk code detection, hex payloads, Debian package analysis, dynamic analysis techniques (strace/ltrace, network monitoring, memory string extraction, automated sandbox execution), YARA rules for malware detection, shellcode analysis (Unicorn Engine, Capstone), memory forensics for malware (Volatility 3 malfind, process injection detection), anti-analysis techniques (VM detection, timing evasion, API hashing, process injection), trojanized plugin analysis with custom alphabet C2 decoding
  • c2-and-protocols.md - C2 traffic patterns, custom crypto protocols, RC4 WebSocket, DNS-based C2, network indicators, PCAP analysis, AES-CBC, encryption ID, Telegram bot recovery, Poison Ivy RAT Camellia decryption
  • pe-and-dotnet.md - PE analysis (peframe, pe-sieve, pestudio), .NET analysis (dnSpy, AsmResolver), LimeRAT extraction, sandbox evasion, malware config extraction, PyInstaller+PyArmor

When to Pivot

  • If the sample is really just a normal crackme, packed challenge binary, or custom VM with no malware behavior, switch to /ctf-reverse.
  • If the main job is network reconstruction, disk carving, or host artifact recovery, switch to /ctf-forensics.
  • If the challenge turns into public attribution or infrastructure tracing, switch to /ctf-osint.

Quick Start Commands

bash
# Static analysis
file suspicious_file
strings -n 8 suspicious_file | head -50
xxd suspicious_file | head -20

# PE analysis
python3 -c "import pefile; pe=pefile.PE('mal.exe'); print(pe.dump_info())" | head
peframe mal.exe

# Dynamic analysis (sandboxed!)
strace -f -s 200 ./suspicious 2>&1 | head -100
ltrace ./suspicious 2>&1 | head -50

# Network indicators
strings suspicious_file | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
strings suspicious_file | grep -iE 'http|ftp|ws://'

# YARA scan
yara -r rules.yar suspicious_file

Obfuscated Scripts

  • Replace eval/bash with echo to print underlying code; extract base64/hex blobs and analyze with file. See scripts-and-obfuscation.md.

JavaScript & PowerShell Deobfuscation

  • JS: Replace eval with console.log, decode unescape(), atob(), String.fromCharCode().
  • PowerShell: Decode -enc base64, replace IEX with output. See scripts-and-obfuscation.md.

Junk Code Detection

  • NOP sleds, push/pop pairs, dead writes, unconditional jumps to next instruction. Filter to extract real call targets. See scripts-and-obfuscation.md.

PCAP & Network Analysis

bash
tshark -r file.pcap -Y "tcp.stream eq X" -T fields -e tcp.payload

Look for C2 on unusual ports. Extract IPs/domains with strings | grep. See c2-and-protocols.md.

Custom Crypto Protocols

  • Stream ciphers share keystream state for both directions; concatenate ALL payloads chronologically.
  • ChaCha20 keystream extraction: send nullbytes (0 XOR anything = anything). See c2-and-protocols.md.

C2 Traffic Patterns

  • Beaconing, DGA, DNS tunneling, HTTP(S) with custom headers, encoded payloads. See c2-and-protocols.md.

RC4-Encrypted WebSocket C2

  • Remap port with tcprewrite, add RSA key for TLS decryption, find RC4 key in binary. See c2-and-protocols.md.

Identifying Encryption Algorithms

  • AES: 0x637c777b S-box; ChaCha20: expand 32-byte k; TEA/XTEA: 0x9E3779B9; RC4: sequential S-box init. See c2-and-protocols.md.

AES-CBC in Malware

  • Key = MD5/SHA256 of hardcoded string; IV = first 16 bytes of ciphertext. See c2-and-protocols.md.
Show full SKILL.md (247 more words)Show less

PE Analysis

bash
peframe malware.exe      # Quick triage
pe-sieve                 # Runtime analysis
pestudio                 # Static analysis (Windows)

See pe-and-dotnet.md.

.NET Malware Analysis

  • Use dnSpy/ILSpy for decompilation; AsmResolver for programmatic analysis. LimeRAT C2: AES-256-ECB with MD5-derived key. See pe-and-dotnet.md.

Malware Configuration Extraction

  • Check .data section, PE/.NET resources, registry keys, encrypted config files. See pe-and-dotnet.md.

Sandbox Evasion Checks

  • VM detection, debugger detection, timing checks, environment checks, analysis tool detection. See pe-and-dotnet.md.

Anti-Analysis Techniques

VM detection (CPUID, MAC prefix, registry, disk size), timing evasion (sleep/RDTSC sandbox detection), API hashing (ROR13/DJB2/CRC32 + hashdb lookup), process injection (hollowing, APC, CreateRemoteThread), environment checks. See scripts-and-obfuscation.md.

Trojanized Plugin Analysis

Diff malicious plugin against official release to find injected code in try/except blocks. Custom alphabet rotation (C[(C.index(ch) - offset) % len(C)]) decodes C2 domain, XOR decodes endpoint path. See scripts-and-obfuscation.md.

PyInstaller + PyArmor Unpacking

  • pyinstxtractor.py to extract, PyArmor-Unpacker for protected code. See pe-and-dotnet.md.

Telegram Bot Evidence Recovery

  • Use bot token from malware source to call getUpdates and getFile APIs. See c2-and-protocols.md.

Debian Package Analysis

bash
ar -x package.deb && tar -xf control.tar.xz  # Check postinst scripts

See scripts-and-obfuscation.md.

YARA Rules for Malware Detection

Write YARA rules to match byte patterns, strings, and regex against files or memory dumps. Detect XOR loops ({31 ?? 80 ?? ?? 4? 75}), base64 blobs, encoded PowerShell. Use yarac to compile for faster scanning. See scripts-and-obfuscation.md.

Shellcode Analysis

Disassemble with objdump -b binary -m i386:x86-64, emulate with Unicorn Engine (hook syscalls safely), or use Capstone for programmatic disassembly. Look for XOR decoder stubs. See scripts-and-obfuscation.md.

Memory Forensics for Malware

vol windows.malfind detects injected code (PAGE_EXECUTE_READWRITE without mapped file). windows.pstree reveals suspicious parent-child relationships. YARA scan memory with windows.vadyarascan.VadYaraScan. See scripts-and-obfuscation.md.

Network Indicators Quick Reference

bash
strings malware | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
tshark -r capture.pcap -Y "dns.qry.name" -T fields -e dns.qry.name | sort -u

© ljagiello, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in ctf-malware of ljagiello/ctf-skills.

  • SKILL.md
  • c2-and-protocols.md
  • pe-and-dotnet.md
  • scripts-and-obfuscation.md

Open the folder on GitHubat commit c332c7b

Compare with similar skills

Ctf Malware next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ctf Malware compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ctf Malware this skillljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Nes Decompilejonathanpeppers/dotnes780—~1.6kAutomated safety check: PassMIT
Patch Diff AnalyzerHacktronAI/skills115—~2.2kAutomated safety check: PassMIT
Malware Analysishypnguyen1209/offensive-claude388—~2.3kAutomated safety check: PassMIT
Detecting Fileless Malware Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Nes Decompile

    jonathanpeppers/dotnes

    Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes.

    780 GitHub stars~1.6k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Patch Diff Analyzer

    HacktronAI/skills

    Specialized in reverse-engineering compiled binaries (JARs, DLLs).

    115 GitHub stars~2.2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Malware Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

    388 GitHub stars~2.3k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Detecting Fileless Malware Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Dotnet Inspect Decompiler

    richlander/dotnet-inspect

    Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup.

    151 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed

More from ljagiello/ctf-skills

  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check: notes
  • Solve Challenge

    ljagiello/ctf-skills

    Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf- skill.

    3.4k GitHub stars~2.3k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Writeup

    ljagiello/ctf-skills

    Generates a single standardized submission-style CTF writeup for competition handoff and organizer review.

    3.4k GitHub stars~1.2k tokensUpdated 26 days ago
    Auto-check: notes
  • Ctf Forensics

    ljagiello/ctf-skills

    Provides digital forensics and signal analysis techniques for CTF challenges.

    3.4k GitHub stars~9.2k tokensUpdated 26 days ago
    Auto-check: warnings

Works with

Categories

Questions about Ctf Malware

What does Ctf Malware do?

Provides malware analysis and network traffic techniques for CTF challenges. Ctf Malware is an agent skill from ljagiello/ctf-skills. Provides malware analysis and network traffic techniques for CTF challenges.

When should I use Ctf Malware?

Ctf Malware fits situations like: analyzing obfuscated scripts; malicious packages; custom crypto protocols; PE/.NET binaries.

How do I install Ctf Malware in Claude Code?

Run `npx skills add ljagiello/ctf-skills --skill ctf-malware -a claude-code`. Or copy the skill folder (ctf-malware in ljagiello/ctf-skills) into .claude/skills/ctf-malware in your project. Claude Code loads it when a task matches its description.

How do I install Ctf Malware in Codex?

Run `npx skills add ljagiello/ctf-skills --skill ctf-malware -a codex`. Or copy the skill folder (ctf-malware in ljagiello/ctf-skills) into .agents/skills/ctf-malware in your project. Codex loads it when a task matches its description.

Can I use Ctf Malware in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ljagiello/ctf-skills --skill ctf-malware -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ctf-malware, .gemini/skills/ctf-malware, .github/skills/ctf-malware and .opencode/skills/ctf-malware in your project.

What does Ctf Malware need to run?

Going by SKILL.md and its folder, Ctf Malware needs the command-line tools its instructions call (pip, apt, brew and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, WebSearch. Compatibility (from SKILL.md): Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation..

Does Ctf Malware access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Ctf Malware safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ctf Malware use?

Ctf Malware is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ctf Malware use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ctf Malware?

Skills that share tags, products or a category with Ctf Malware: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Nes Decompile (jonathanpeppers/dotnes, 780 stars), Patch Diff Analyzer (HacktronAI/skills, 115 stars) and Malware Analysis (hypnguyen1209/offensive-claude, 388 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ctf Malware?

ljagiello (a GitHub user) maintains it in ljagiello/ctf-skills, which has 3,416 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 13, 2026.

Source: ljagiello/ctf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.