Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .claude/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add trilwu/secskills --skill analyzing-malware -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .agents/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill analyzing-malware -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .cursor/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add trilwu/secskills --skill analyzing-malware -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .gemini/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add trilwu/secskills --skill analyzing-malware -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .github/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill analyzing-malware -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "analyzing-malware" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-malware into .opencode/skills/analyzing-malware/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-malware", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
analyzing-malware
GitHub stars
156
Token cost
~3.6k tokens
SKILL.md length
1,251 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT
At a glance
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
Handed a suspicious file
SKILL.md covers When to Use, When NOT to Use, Containment: Do This Before… and Static Triage — No Execution, plus 9 more sections
Calls python3 and curl; reaches defuddle.md
Triaging an alert artifact
What it does
Analyzing Malware is an agent skill from trilwu/secskills. Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Use when handed a suspicious file, hash, or sample, when triaging an alert artifact, or when producing detection content from a specimen.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
When your agent uses it
Handed a suspicious file
Triaging an alert artifact
Producing detection content from a specimen
Example prompts
“/analyzing-malware”
Requirements
Python 3
What it can do on your machine
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
python3
curl
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
defuddle.md
Also links to:
attack.mitre.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Analyzing Malware loads about 3.6k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,251 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~81
When it runs· the whole SKILL.md, loaded when a task matches
~3.6k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/analyzing-malware/SKILL.md (or your agent's skills folder).
name
analyzing-malware
description
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Use when handed a suspicious file, hash, or sample, when triaging an alert artifact, or when producing detection content from a specimen.
verified
2026-07-27
Analyzing Malware
The analysis is the easy part. The part that goes wrong is containment: a
sample detonated on a machine that can reach production, or an IOC published
that burns an active investigation. Get the environment right first.
When to Use
Triaging a suspicious file, attachment, script, or dropped binary
Determining a sample's capability, persistence, and command-and-control
Extracting indicators for hunting and blocking
Writing YARA or behavioural detection from a specimen
Supporting an incident with sample-derived intelligence
When NOT to Use
Writing malware, droppers, loaders, or evasion code — out of scope for
this skill regardless of framing
Pure RE of a benign binary — use analyzing-binaries
A raw shellcode blob with no PE/ELF header — use analyzing-shellcode
The sample's network capture — use analyzing-network-traffic
Sweeping a whole web source tree for planted webshells (not one recovered
sample) — use hunting-web-backdoors
Writing a YARA signature for the family — use writing-yara-rules
The wider incident — use responding-to-incidents
Turning findings into deployed rules — use engineering-detections
Pivoting sample IOCs into related infrastructure, actor tracking, or a
finished intel product — use producing-threat-intelligence
Containment: Do This Before Anything Else
Control
Requirement
Host
Disposable VM or dedicated bare-metal, snapshot taken before execution
Network
Isolated segment; simulated services (INetSim/FakeNet-NG) by default
Shares
No host folder sharing, no clipboard sharing, no mounted host drives
Credentials
No real accounts, no domain join, no password manager
Handling
Sample stored in a password-protected archive, extension neutered (.bin, .mal)
Egress
Real internet only with an explicit decision and a plan for attribution leakage
Live C2 contact tells the operator you are looking. On an active incident, do
not resolve the C2 domain, submit the hash publicly, or upload the sample to a
multi-scanner service until the incident lead approves it — public submission
is a disclosure.
Static Triage — No Execution
bash
# Identity, always first
sha256sum sample && file sample && du -h sample
# Fuzzy and import hashes for clustering against known families
ssdeep sample; tlsh sample # Debian tlsh-tools ships /usr/bin/tlsh;
# built from upstream it is tlsh_unittest
python3 -c "import pefile;print(pefile.PE('sample').get_imphash())"
# Structure
pecheck sample # or: rabin2 -I / readelf -h
capa -v sample # capability detection mapped to ATT&CK — start here
floss sample # deobfuscated + stack strings, better than `strings`
# Packing and embedded content
binwalk -E sample # entropy
binwalk -Me sample # extract embedded objects
capa is the highest-value single command in this workflow: it turns a binary
into a list of behaviours mapped to MITRE ATT&CK and MBC, which tells you
whether deeper analysis is warranted at all.
Recover the unpacked payload from memory rather than fighting the packer:
bash
# After the sample unpacks itself, dump and carve
vol -f mem.raw windows.malfind # injected/RWX regions
vol -f mem.raw windows.dumpfiles --pid <pid>
Watch for sleep and evasion gates: many samples idle for minutes, check for
a domain-joined host, count CPU cores, or look for analysis processes. If
nothing happens, patch the check or hook Sleep/NtDelayExecution with Frida
before concluding the sample is inert.
Capability Model
Structure findings against ATT&CK rather than as a narrative:
Initial execution — how it was launched, what it needed
Discovery — host, domain, and security-product enumeration
Collection and exfiltration — what is staged, where, and how it leaves
Command and control — protocol, encoding, jitter, fallback channels, kill date
Impact — encryption, wiping, resource hijacking
For each, record the concrete evidence (address, API call, artifact) that
supports the claim. A capability asserted without evidence is a guess, and
guesses in a malware report drive bad response decisions.
Configuration and C2 Extraction
The config is the most valuable output — it feeds blocking, hunting, and
attribution.
bash
# Known families: use the community extractors first
python3 -m maco.extract sample # MACO / CAPE / RATDecoders ecosystems
# Unknown: find the decode routine, then emulate it over the encrypted blob
Typical config contents: C2 URLs and fallbacks, campaign or botnet ID, RC4/AES
key, mutex, sleep interval and jitter, install path, kill date. Extract all of
them — campaign IDs and mutexes are often better hunting pivots than the C2,
which rotates.
IOC and Detection Output
Rank indicators by how long they survive and how specific they are:
Hash → precise, dies immediately (recompile)
C2 IP/domain → useful now, rotates in days
Mutex / config → survives rotation, family-specific
Behaviour/TTP → survives redevelopment; write these
Write YARA against structure and code, not incidental strings:
yara
rule Family_Loader_ConfigDecode
{
meta:
author = "analyst"
date = "2026-07-26"
description = "Loader config RC4 decode stub"
hash = "<sha256>"
reference = "<internal case id>"
strings:
// The decode loop's constants, not a filename it happens to drop
$decode = { 8A 04 0? 32 0? 88 0? 4? 3B ?? 72 }
$mutex = "Global\\<family-specific>" ascii
condition:
uint16(0) == 0x5A4D and filesize < 2MB and all of them
}
Validate every rule before it ships:
bash
yara -w rule.yar ./samples/family/ # must hit all known-true samples
yara -w rule.yar ./corpus/goodware/ # must produce zero hits — this step is not optional
Hand behavioural detections to engineering-detections for Sigma/EDR
conversion and tuning.
Rationalizations to Reject
"It's just a script, I'll run it on my laptop." Script malware is malware.
"The sandbox said it's clean." Sandboxes are evaded by design. A clean
verdict with a suspicious file is a reason to analyze harder, not to close.
"I'll upload it to VirusTotal to check quickly." Public submission is
disclosure to the adversary and possibly to your customer's competitors.
Decide deliberately.
"The hash is the IOC." The hash blocks exactly this build.
"AV named it Family X, so it is Family X." Vendor names are inconsistent.
Confirm with code or config similarity before you inherit that family's
attribution and playbook.
"No network traffic, so no C2." Check for sleep gates, DGA seeds waiting
on a date, and dead-drop resolvers before concluding.
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
T1071 Application Layer Protocol — see also engineering-detections, analyzing-network-traffic
T1132 Data Encoding — see also transferring-files, analyzing-network-traffic
T1568 Dynamic Resolution — see also hunting-threats, analyzing-network-traffic
T1573 Encrypted Channel — see also engineering-detections, analyzing-network-traffic
Impact (TA0040)
T1486 Data Encrypted for Impact — see also responding-to-incidents
Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
Reading External Sources
Fetch public advisories, specifications, and vendor reports as Markdown:
bash
curl -sL "https://defuddle.md/<url>" # scheme in the path is optional
This strips page boilerplate — roughly 78% fewer tokens on a prose page — and
returns the full text rather than a summary, so you can grep it and trust a
negative result.
Three things it is not for. Fetch JSON and API responses raw, because
readability extraction mangles structured data. Fetch authenticated or
JavaScript-rendered pages directly, because it retrieves them anonymously. And
never route adversary infrastructure (phishing links, C2, malware hosting),
client-owned hosts, or engagement URLs through it — the request leaves
your machine to a third party, and for live adversary infrastructure it also
tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
References
analyzing-binaries — disassembly, unpacking, and anti-analysis detail
responding-to-incidents — scoping and eradication around the sample
engineering-detections — turning capability into deployed rules
MITRE ATT&CK and MBC (Malware Behavior Catalog) for classification
capa, floss, oletools, Volatility 3, YARA as the core toolchain
Analyzing Malware next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun…
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…
Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…
Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis…
Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious…
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
156 GitHub stars~2k tokensUpdated 1 mo ago
Auto-check passed
Questions about Analyzing Malware
What does Analyzing Malware do?
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. Analyzing Malware is an agent skill from trilwu/secskills. Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
When should I use Analyzing Malware?
Analyzing Malware fits situations like: handed a suspicious file; triaging an alert artifact; producing detection content from a specimen.
How do I install Analyzing Malware in Claude Code?
Run `npx skills add trilwu/secskills --skill analyzing-malware -a claude-code`. Or copy the skill folder (secskills-defense/skills/analyzing-malware in trilwu/secskills) into .claude/skills/analyzing-malware in your project. Claude Code loads it when a task matches its description.
How do I install Analyzing Malware in Codex?
Run `npx skills add trilwu/secskills --skill analyzing-malware -a codex`. Or copy the skill folder (secskills-defense/skills/analyzing-malware in trilwu/secskills) into .agents/skills/analyzing-malware in your project. Codex loads it when a task matches its description.
Can I use Analyzing Malware in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-malware -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-malware, .gemini/skills/analyzing-malware, .github/skills/analyzing-malware and .opencode/skills/analyzing-malware in your project.
What does Analyzing Malware need to run?
Going by SKILL.md and its folder, Analyzing Malware needs the command-line tools its instructions call (python3 and curl). Our summary lists: Python 3.
Does Analyzing Malware access the network?
SKILL.md names 2 domains. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Is Analyzing Malware safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Analyzing Malware use?
Analyzing Malware is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Analyzing Malware use?
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Analyzing Malware?
Skills that share tags, products or a category with Analyzing Malware: Analyzing Malware Sandbox Evasion Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Linux Elf Malware (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Android Malware With Apktool (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Packed Malware With Upx Unpacker (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Analyzing Malware?
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.