vphone600 Kernel Symbol Analysis
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
Professional malware analysis workflow for PE executables and suspicious files.
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .claude/skills/malware-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .claude/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-trType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .agents/skills/malware-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .agents/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .cursor/skills/malware-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .cursor/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tsale/awesome-dfir-skills.git --path skills/analysis/malware-analysis-tr--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .gemini/skills/malware-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .gemini/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tsale/awesome-dfir-skills malware-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .github/skills/malware-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .github/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .opencode/skills/malware-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malware-analysis" agent skill from https://github.com/tsale/awesome-dfir-skills/tree/main/skills/analysis/malware-analysis-tr into .opencode/skills/malware-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malware-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malware-analysisProfessional malware analysis workflow for PE executables and suspicious files.
Malware Analysis is an agent skill from tsale/awesome-dfir-skills. Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with requests like "analyze this malware", "analyze this sample", "what does this executable do", "check this file for malware", or any request to examine suspicious files. Performs static analysis, threat intelligence triage, behavioral inference, and produces analyst-grade reports with reasoned conclusions.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `config/config.json`, `references/mitre_techniques.md` and `references/report_template.md`).
It sits in Security, covering Reverse engineering and malware and OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malware Analysis loads about 2.5k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 842 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 842 words, ~2,539 tokens.
.claude/skills/malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.This skill produces analyst-grade threat reports — not data dumps. Every conclusion must be backed by evidence and reasoning.
Run all scripts to gather raw data:
# Static analysis - get hashes, PE info, strings, APIs, entropy
python3 scripts/static_analysis.py /path/to/sample -f json > static.json
# Threat intelligence - check reputation across sources
python3 scripts/triage.py -t file /path/to/sample -f json > triage.json
# IOC extraction - extract network/host indicators
python3 scripts/extract_iocs.py /path/to/sample -f json > iocs.jsonUsing the collected data, perform analyst-grade reasoning:
Ask yourself:
Always explain your reasoning:
"This sample is identified as RedLine Stealer by MalwareBazaar with 45/70 VT detections. The high detection rate and presence in curated malware repositories confirms this is a known threat, not a false positive."
API Analysis - Map APIs to behaviors:
| API Pattern | Likely Behavior | Reasoning |
|---|---|---|
| VirtualAlloc + VirtualProtect + WriteProcessMemory + CreateRemoteThread | Process Injection | This is the classic injection pattern: allocate memory, make it executable, write code, execute in target |
| CredEnumerate, CryptUnprotectData | Credential Theft | These APIs specifically access Windows credential stores and DPAPI-protected data (browser passwords) |
| InternetOpen + URLDownloadToFile | Downloader | Initializes HTTP and downloads files — classic dropper behavior |
| RegSetValueEx + Run key paths in strings | Persistence | Writing to Run keys ensures execution at startup |
| IsDebuggerPresent, GetTickCount, NtQuerySystemInformation | Anti-Analysis | Multiple evasion checks suggest the malware hides its behavior during analysis |
| CryptEncrypt + file enumeration APIs | Possible Ransomware | Encryption capability combined with file discovery — but could also be secure C2 |
Always explain your reasoning:
"The presence of VirtualAlloc, VirtualProtect, and CreateRemoteThread together strongly suggests process injection capability. Individually these APIs have legitimate uses, but this specific combination is the textbook pattern for injecting code into other processes."
Packing Analysis:
| Indicator | Meaning | Confidence |
|---|---|---|
| Entropy > 7.0 | Compressed/encrypted content | High |
| Section entropy > 7.0 (especially .text) | Packed code section | High |
| UPX0, UPX1, .aspack, .packed sections | Known packer signatures | Very High |
| RWX sections | Self-modifying code | Medium |
| Small import table with GetProcAddress/LoadLibrary only | Dynamic API resolution | High |
If packed, state the implication:
"This sample shows multiple packing indicators (entropy 7.4, UPX sections). The static analysis findings represent the unpacker stub, NOT the actual payload. Dynamic analysis is required to reveal true functionality."
Based on the evidence, determine what the malware CAN DO:
| Capability | Required Evidence | Confidence Level |
|---|---|---|
| Process Injection | 2+ injection APIs | High if 3+, Medium if 2 |
| Credential Theft | Any cred access API | High (these are specific) |
| Keylogging | SetWindowsHookEx | Medium (has legit uses) |
| Network C2 | 2+ network APIs + extracted URLs/IPs | High |
| File Download | URLDownloadToFile or similar | High |
| Persistence | Registry/service APIs + relevant strings | Medium |
| Encryption/Ransomware | Crypto APIs + file enumeration | Medium (needs context) |
State confidence and reasoning:
"Credential Theft Capability: HIGH CONFIDENCE — CryptUnprotectData is present, which specifically decrypts DPAPI-protected data including browser passwords. This API has no legitimate use case in most software."
Determine risk level with justification:
| Risk Level | Criteria |
|---|---|
| CRITICAL | Credential theft APIs, process injection, confirmed malware family known for data theft/ransomware |
| HIGH | Multiple malicious capabilities, network C2, persistence mechanisms |
| MEDIUM | Suspicious indicators but no confirmed malicious capability, or packing hiding true behavior |
| LOW | Few indicators, possibly legitimate software with suspicious patterns |
| UNKNOWN | Insufficient evidence, heavily packed, or no TI hits |
Structure your report as follows:
# Threat Analysis Report: [MALWARE_NAME or "Unknown Sample"]
| | |
|---|---|
| **Risk Level** | [CRITICAL/HIGH/MEDIUM/LOW] |
| **Confidence** | [High/Medium/Low] |
| **Analysis Date** | [DATE] |
---
## Executive Summary
[2-3 sentences: What is this? Is it malicious? What can it do? How do we know?]
**Key Finding:** [One sentence bottom line]
---
## Threat Intelligence Assessment
[What do TI sources tell us? Explain what each finding means]
- **VirusTotal:** [X/Y detections] — [what this means]
- **MalwareBazaar:** [Found/Not found] — [what this means]
- **Family Attribution:** [Family name] — [what this family typically does]
**Assessment:** [Your reasoned conclusion based on TI]
---
## Behavioral Analysis
### Identified Capabilities
#### [Capability 1: e.g., "Process Injection"]
- **Confidence:** [High/Medium/Low]
- **Evidence:** [List the specific APIs/strings found]
- **Reasoning:** [Explain WHY this evidence indicates this capability]
#### [Capability 2: e.g., "Credential Theft"]
...
### Packing Assessment
[Is it packed? What does this mean for the analysis?]
### Anti-Analysis Techniques
[What evasion techniques were identified?]
---
## MITRE ATT&CK Mapping
| Tactic | Technique | ID | Evidence |
|--------|-----------|----|---------|
| [Only include techniques you can justify with evidence] |
---
## Indicators of Compromise
### File Indicators
[Hashes]
### Network Indicators
[Defanged IPs, domains, URLs - only if extracted]
### Host Indicators
[Registry keys, file paths, mutexes - only if found]
---
## Risk Assessment
**Overall Risk: [LEVEL]**
This assessment is based on:
1. [Reason 1]
2. [Reason 2]
3. [Reason 3]
**Confidence in Assessment: [High/Medium/Low]**
- [Why this confidence level]
---
## Recommendations
### Immediate Actions
[What should be done RIGHT NOW based on risk level]
### Detection Opportunities
[How to detect this threat]
### Further Analysis Needed
[What questions remain unanswered]| Entropy | Meaning |
|---|---|
| 0-1 | Highly structured (empty, repetitive) |
| 4-5 | Plain text, readable strings |
| 5-6 | Compiled code (normal .text section) |
| 6-7 | Compressed data, some obfuscation |
| 7-8 | Encrypted/compressed (PACKED) |
| Bytes | Type |
|---|---|
| 4D 5A (MZ) | PE executable |
| 50 4B (PK) | ZIP/Office document |
| 7F 45 4C 46 | ELF executable |
| D0 CF 11 E0 | OLE/Legacy Office |
| 25 50 44 46 |
BAD (data dump):
"Found APIs: VirtualAlloc, CreateRemoteThread, RegSetValueEx. Entropy: 7.2. VT: 34/70."
GOOD (analyst reasoning):
"This sample demonstrates process injection capability (HIGH CONFIDENCE) based on the presence of VirtualAlloc and CreateRemoteThread. These APIs, when used together, form the classic code injection pattern where memory is allocated in a target process and a thread is created to execute the injected code. The high entropy (7.2) suggests the payload is packed, meaning the observed APIs may belong to the unpacker stub rather than the final payload. The 34/70 VirusTotal detection rate confirms this is recognized malware, with multiple vendors identifying it as a variant of Agent Tesla — an info-stealer known for credential harvesting. Given the injection capability and association with a credential-stealing family, this sample poses a CRITICAL risk to credential security on any system where it executes."
python3 scripts/static_analysis.py <file> -f [text|json]Extracts: hashes, file type, PE headers, sections, entropy, imports, strings, suspicious indicators
python3 scripts/triage.py <ioc> -f [text|json]
python3 scripts/triage.py -t file <filepath> -f json
python3 scripts/triage.py --status # Check API configQueries: MalwareBazaar, ThreatFox, URLhaus, VirusTotal, AbuseIPDB
python3 scripts/extract_iocs.py <file> -f [text|json|csv]Extracts: IPs, domains, URLs, emails, hashes, registry keys, file paths, crypto wallets, mutexes
© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/analysis/malware-analysis-tr of tsale/awesome-dfir-skills.
Open the folder on GitHubat commit 6e52942
Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malware Analysis this skilltsale/awesome-dfir-skills | 324 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 935 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Osintljagiello/ctf-skills | 3.4k | 2 repos | ~2.3k | Automated safety check: Notes | MIT |
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
ljagiello/ctf-skills
Provides open source intelligence techniques for CTF challenges.
boyang-hu/website-rebuild-skill
1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).
tsale/awesome-dfir-skills
Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.
tsale/awesome-dfir-skills
Analyse Mitre ATT&CK tactics, techniques and sub-techniques.
tsale/awesome-dfir-skills
Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.
tsale/awesome-dfir-skills
Build structured threat actor profiles using the 5W1H framework and the Diamond Model.
Categories
Professional malware analysis workflow for PE executables and suspicious files. Malware Analysis is an agent skill from tsale/awesome-dfir-skills. Professional malware analysis workflow for PE executables and suspicious files.
Malware Analysis fits situations like: file uploads with requests like analyze this malware; analyze this sample; what does this executable do; check this file for malware.
Run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a claude-code`. Or copy the skill folder (skills/analysis/malware-analysis-tr in tsale/awesome-dfir-skills) into .claude/skills/malware-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a codex`. Or copy the skill folder (skills/analysis/malware-analysis-tr in tsale/awesome-dfir-skills) into .agents/skills/malware-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malware-analysis, .gemini/skills/malware-analysis, .github/skills/malware-analysis and .opencode/skills/malware-analysis in your project.
Going by SKILL.md and its folder, Malware Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Malware Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Malware Analysis: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 935 stars) and Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 324 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.
Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.