vphone600 Kernel Symbol Analysis
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
Analyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection.
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills malware-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malware-analysis .claude/skills/malware-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .claude/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills malware-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/malware-analysis .agents/skills/malware-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .agents/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills malware-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/malware-analysis .cursor/skills/malware-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .cursor/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/malware-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills malware-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/malware-analysis .gemini/skills/malware-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .gemini/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills malware-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/malware-analysis .github/skills/malware-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .github/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills malware-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/malware-analysis .opencode/skills/malware-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/malware-analysis into .opencode/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malware-analysisAnalyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection.
Malware Analysis is an agent skill from sickn33/agentic-awesome-skills. Analyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anti-analysis-techniques.md`, `references/sandbox-orchestration.md` and `references/yara-sigma-rules.md`).
It sits in Security, covering Reverse engineering and malware. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malware Analysis loads about 2.5k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 47 tokens; SKILL.md has 262 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 262 words, ~2,502 tokens.
.claude/skills/malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.# 快速静态检测
file sample.exe # 文件类型
strings sample.exe | grep -i "http\|cmd\|powershell\|base64" # 快速 IOCs
rabin2 -zz sample.exe # 字符串提取 + 交叉引用
floss sample.exe # 去混淆字符串提取(FireEye)
# PE 头部分析
pecheck sample.exe # PE 结构验证
pescan sample.exe # 异常检测(节表、入口点)
diec sample.exe # Detect It Easy(壳/编译器识别)
# Hash 查询
sha256sum sample.exe
# → VirusTotal / MalwareBazaar / Triage 查询Triage MUST 清单(Issue #65):
□ 文件类型:EXE / DLL / SYS / .NET / 脚本(bat|ps1|vba) / 其他
□ 架构 x86/x64/ARM;查壳(DIE 等)与编译语言线索
□ DLL/SYS:导入表与导出表并列检查(见 Phase 2 硬门)
□ .NET:无传统 IAT → 走 dnSpy/IL/元数据等价锚点(见 Phase 2)
□ 脚本/宏/DLL 专项 P0:见 nonpe-format-cookbook U–AV(E-batch-deobf / E-ps-decode / E-vba-pcode / E-dll-*)□ 无壳 / .NET → 跳到 Phase 2
□ 有壳:尝试脱壳(授权隔离环境)→ 尝试修复 IAT
- x86:ImportREC(或等价);x64:Scylla(或等价)。禁止 64 位死磕 ImportREC
□ 【IAT 修复铁律】优先自动/半自动修复;若工具报错或修复后无法运行:
- 立即终止继续静态 IAT 修复
- MUST 记录 E-iat-repair-fail(命令、工具、现象)
- 转入 Phase 3 动态:API 断点(如 bp CreateFile)/ 硬件断点 / 内存搜索抓取导入
- 这不算跳过导入表:路径已尝试并记 Evidence
□ 【补丁 6】脱壳+修 IAT 后闪退/蓝屏(疑 CRC/大小自校验):
- 放弃继续静态修文件;记 E-self-check-crash 或并入 E-iat-repair-fail
- 转 Phase 3:对 CreateFile / GetFileSize / 哈希相关 API 下断
□ 用户指令可行性(§0.5):加壳时用户抢跑「先别脱壳先看导入表」→ 说明阻塞 + 请确认;强制则记 quality=unreadable/packed,禁止冒充完成有意义 IAT
□ 用户要求重做「IAT 修复 / 导入表检查」:MUST 重做被点名步骤(或经确认的前提协商结果),禁止换无关步骤冒充反汇编/反编译:
□ IDA Pro / Ghidra: 深度反编译
□ radare2: CLI 快速分析
□ x64dbg: Windows GUI 调试器
重点分析区域:
□ 入口点(Entry Point)→ 初始化逻辑
□ 导入表 → API 用途推断(CreateRemoteThread=注入, CryptEncrypt=勒索)
**MUST(硬门)**:执行 rabin2 -i / IDA imports / pecheck 等价命令,将导入表分类摘要写入 Evidence(E-imports)后才能进入 Phase 3(除非已记 E-iat-repair-fail 并走动态旁路,见 Phase 1b)
分类至少覆盖:网络 / 文件 / 加密 / 进程注入 / 注册表 / 其他可疑 API
解析失败或表为空:仍 MUST 记录失败输出,禁止静默跳过
**DLL/SYS**:MUST 并列记录导出表 Evidence(E-exports,`rabin2 -E` 或等价)
**.NET**:无传统 IAT 时 MUST 用 dnSpy/IL/元数据/程序集引用与敏感 API 摘要作为等价锚点,写入 E-imports / E-triage-imports 语义槽
**干净导入表**:仅基础 DLL、几乎无业务 API → MUST 注明动态加载嫌疑(LoadLibrary/GetProcAddress),SHOULD 转入 Phase 3 抓内存 API;若见哈希解析特征 → E-api-hash(补丁 N)
**宽字符串(T)**:ASCII strings 无 IOC 时 MUST 再试 UTF-16(strings -el / IDA unicode)
**签名(F)**:有签名仍 MUST SigCheck;伪造/吊销不降威胁等级
用户要求「重做导入表检查」:MUST 重做本项(阻塞时先走可行性门闩协商),禁止改换其他步骤冒充完成
**高危 API 组合(补丁 8)**:表过长时优先输出恶意组合簇(如 FindWindow+WriteProcessMemory+CreateRemoteThread),过滤纯系统基础调用噪声
□ 资源段 → 嵌入 Payload(.rsrc 节)
□ 字符串表 → URL/C2/文件路径/Base64 blob
□ TLS 回调 → 调试器启动前执行自动化沙箱:
□ Joe Sandbox / ANY.RUN / Triage: 商业沙箱
□ CAPE Sandbox: 开源 + YARA 集成(推荐)
□ ASD Azul: 开源恶意软件分析平台(2026 新发布)
□ Cuckoo Sandbox: 经典开源(逐步被 CAPE 取代)
调试起手式(补丁 7+10 · MUST 顺序,用户态调试器):
□ ① TLS 回调断点 → ② 入口点 EP 断点 → ③ 敏感 API 断点 → ④ ExitProcess/退出路径保底断点
□ ExitProcess 触发时:不急着重启;立即 dump memory,路径写入 Evidence(补丁 10)
监控重点:
□ 进程创建: CreateProcess / ShellExecute
□ 文件操作: WriteFile → 勒索? DeleteFile → Wiper?
□ 注册表: Run/RunOnce 持久化
□ 网络: HTTP/DNS → C2 通信
□ 内存: VirtualAllocEx → 进程注入
□ 服务: CreateService → 持久化
□ IAT 修复失败 / 自校验闪退样本:敏感 API + CreateFile/GetFileSize 断点 / 硬件执行断点 / 内存搜索
无行为应急分支(MUST):
□ 沙箱无行为、秒退或无限休眠 → 检查反调试/反虚拟机(CPUID、计时、环境特征)
□ 尝试硬件断点绕过、补丁检测点、或换物理机/更高保真环境
□ 将「无行为 + 条件」写入 Evidence;禁止无条件写成「样本无害」
时间盒(补丁 9 · SHOULD 默认,可覆盖):
□ 静态深挖约 15 分钟无关键路径 → 强制转入本 Phase 动态
□ 动态单步约 200 条指令无恶意线索 → 强制回静态字符串/交叉引用重锚
反调试/混淆旁路(Issue #65 A–T · 详见 reverse-engineering/anti-analysis.md 菜谱):
□ P0:CPUID / RDTSC / PEB / NtQueryInformationProcess → 记录检测点后 lab 绕过或换环境(E-anti-debug-*)
□ P0:干净 IAT → API 哈希动态解析(bp GetProcAddress,E-api-hash)
□ P0:strings 空 → 串解密例程 + 宽字符串 UTF-16(E-string-decrypt / E-wide-strings)
□ P0:可疑签名 → SigCheck;无效/吊销不降威胁(E-sig-forge)
□ P1:进程名扫描 / VEH / int3·DR / 重叠节 / Overlay / .rsrc / Delay-Load
□ H/S 平坦化与不透明谓词 → ollvm-deobfuscation.md(不在此复制长文)
□ 绕过失败也写 Evidence;禁止反调试退出 = 样本无害
非 PE / 脚本 / DLL 补洞(Issue #65 U–AV · 详见 reverse-engineering/references/nonpe-format-cookbook.md):
□ bat/cmd:SET 拼接还原(U)→ E-batch-deobf;UTF-16 BOM(V);REM/GOTO 淹没(W)
□ PowerShell:多层 Base64/Gzip(X)逐层 Evidence;IEX 拼接/反转(Z) # security-allowlist: SEC005
□ VBA:Stomping/P-Code(AA);Chr/Base64(AB);自修改宏(AC)
□ DLL:TLS+DllMain(AJ);导出异常/无导出(AK/AL);Delay-Load 见 A–T R(AM);侧加载/反射(AO/AP)
□ JS/APK/驱动:路由 js-reverse / apk-reverse / kernel-driver-reverse + cookbook,不在此复制长文// 规则结构
rule MalwareFamily_Example {
meta:
description = "检测 Example 恶意软件家族"
author = "分析者"
date = "2026-05"
severity = "high"
hash = "d41d8cd98f00b204e9800998ecf8427e"
mitre_id = "T1055" // Process Injection
strings:
// 字符串匹配
$str1 = "C2_SERVER_URL" ascii wide
$str2 = "payload.dat" ascii
// 十六进制匹配
$hex1 = { 8B 45 ?? 50 FF 15 [4] 85 C0 }
// 操作码序列: mov eax, [ebp-?]; push eax; call [import]; test eax, eax
// 正则匹配
$re1 = /https?:\/\/[a-z0-9.-]+\/[a-z]{3,8}\.php/ ascii
condition:
// 组合条件
uint16(0) == 0x5A4D and // MZ 头
filesize < 500KB and
(2 of ($str*) or $hex1)
}# 行为检测规则
title: Suspicious Process Injection via CreateRemoteThread
id: 5a3d2c1b-1234-5678-9abc-def012345678
status: experimental
description: 检测使用 CreateRemoteThread 的进程注入行为
author: 分析者
date: 2026/05/25
tags:
- attack.t1055 # Process Injection
- attack.t1055.001 # DLL Injection
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- 'CreateRemoteThread'
- 'VirtualAllocEx'
- 'WriteProcessMemory'
condition: selection
falsepositives:
- 合法的调试工具
level: highIOC 类型分类:
□ 网络 IOC:
- IP: C2 地址(注意时效性)
- Domain: DGA 算法生成的域名(rsnkfda.com, xpqmje.net)
- URL: Payload 托管地址
- User-Agent: 自定义 UA 字符串
□ 主机 IOC:
- 文件路径: %APPDATA%\Microsoft\Crypto\RSA\*.dat
- 注册表: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
- Mutex: Global\{GUID} 互斥体名称
- 服务名: 伪装成系统服务的名称
□ 行为 IOC:
- MITRE ATT&CK 技术 ID (T1055, T1003, T1571...)
- Sigma 规则 → SIEM 集成
- YARA 规则 → 端点检测
□ 静态 IOC:
- 编译时间戳(可伪造)
- PDB 路径(含开发者信息)
- 节名异常(非标准 .text/.data)
- 导入表异常组合(如勒索软件 CryptEncrypt + DeleteShadowCopies)| 技术 | 检测方法 | YARA 特征 |
|---|---|---|
| 虚拟机检测 | WMI Win32_BIOS/VideoController/Processor | Win32_ 字符串 + 特定厂商名 |
| 沙箱检测 | 磁盘 < 60GB, RAM < 2GB, 单核 CPU | GlobalMemoryStatusEx 调用模式 |
| 调试器检测 | IsDebuggerPresent, CheckRemoteDebuggerPresent | PEB.BeingDebugged 偏移访问 |
| 定时逃逸 | Sleep(300000) 后执行恶意行为 | NtDelayExecution 长参数 |
| 地理位置检测 | 检查键盘布局/时区 → 排除 CIS 国家 | GetKeyboardLayoutList 调用 |
| 父进程检测 | explorer.exe vs cmd.exe | 进程名字符串比较 |
| API 直接 syscall | 绕过 EDR hook | syscall 指令 + SSN 解析 |
┌─────────────────────────────────────────────────┐
│ Hive Director │
│ (Claude Opus 编排 + 仲裁) │
└──────┬──────┬──────┬──────┬──────┬───────┘
│ │ │ │ │
┌───┘ ┌───┘ ┌───┘ ┌───┘ ┌───┘
▼ ▼ ▼ ▼ ▼ ▼
Triage RE Behav Intel Detect Remed
快速 反编译 行为 威胁 规则 修复
分诊 静态 动态 情报 YARA 方案
Sigma| 工具 | 用途 | 获取 |
|---|---|---|
| Ghidra / IDA Pro | 深度反编译 | ghidra-sre.org |
| CAPE Sandbox | 开源恶意软件沙箱 | GitHub: kevoreilly/CAPEv2 |
| ASD Azul | 大规模自动化分析 | GitHub: ASD |
| YARA | 模式匹配规则引擎 | pip install yara-python |
| Sigma | SIEM 行为检测规则 | GitHub: SigmaHQ/sigma |
| FLOSS | 去混淆字符串提取 | pip install flare-floss |
| Detect It Easy | 壳/编译器检测 | GitHub: horsicq/Detect-It-Easy |
| pe-sieve | 进程内存扫描 | GitHub: hasherezade/pe-sieve |
| VirusTotal API | 多引擎扫描 | virustotal.com |
| MalwareBazaar | 恶意软件样本库 | bazaar.abuse.ch |
references/yara-sigma-rules.md — YARA + Sigma 编写方法论references/sandbox-orchestration.md — 沙箱编排与自动化references/anti-analysis-techniques.md — 94 种反分析技术检测../reverse-engineering/references/re-agent-workflow.md — IAT 铁律与六阶段门闩(Issue #65)../reverse-engineering/anti-analysis.md — Agent 响应菜谱 A–T(反调试/混淆旁路)../reverse-engineering/references/nonpe-format-cookbook.md — 非 PE/多格式菜谱 U–AV(脚本/宏/JS/驱动/DLL/Android)../reverse-engineering/references/ollvm-deobfuscation.md — 平坦化/不透明谓词(H/S)tool-index 使用了真实工具路径?Adapted from zhaoxuya520/reverse-skill (MIT).
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/malware-analysis of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 1e53ce2
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malware Analysis this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 935 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Website Rebuildboyang-hu/website-rebuild-skill | 1.4k | — | ~6.1k | Automated safety check: Pass | MIT | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT |
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
boyang-hu/website-rebuild-skill
1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Analyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection. Malware Analysis is an agent skill from sickn33/agentic-awesome-skills. Analyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection.
Malware Analysis fits situations like: tasks that involve Reverse engineering and malware.
Run `npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a claude-code`. Or copy the skill folder (skills/malware-analysis in sickn33/agentic-awesome-skills) into .claude/skills/malware-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a codex`. Or copy the skill folder (skills/malware-analysis in sickn33/agentic-awesome-skills) into .agents/skills/malware-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malware-analysis, .gemini/skills/malware-analysis, .github/skills/malware-analysis and .opencode/skills/malware-analysis in your project.
Going by SKILL.md and its folder, Malware Analysis needs the command-line tools its instructions call (pip).
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Malware Analysis is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Malware Analysis: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 935 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.