Agent skill

Malware Analysis

by tsale in tsale/awesome-dfir-skills

Professional malware analysis workflow for PE executables and suspicious files.

Apache-2.0Auto-check passedSecurity

Install Malware Analysis

skills CLI
$ npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tsale/awesome-dfir-skills malware-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tsale/awesome-dfir-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analysis/malware-analysis-tr .claude/skills/malware-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
malware-analysis
GitHub stars
324
Token cost
~2.5k tokens
SKILL.md length
842 words
Files
8 (incl. scripts, references)
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Professional malware analysis workflow for PE executables and suspicious files.

  • Works in 3 steps: Collect Data → Analyze and Reason (THIS IS THE KEY STEP) → Write the Report
  • File uploads with requests like analyze this malware
  • SKILL.md covers Core Principles, Analysis Workflow, Example Analysis Reasoning and Scripts Reference
  • Runs Python scripts from its folder; calls python3

What it does

Malware Analysis is an agent skill from tsale/awesome-dfir-skills. Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with requests like "analyze this malware", "analyze this sample", "what does this executable do", "check this file for malware", or any request to examine suspicious files. Performs static analysis, threat intelligence triage, behavioral inference, and produces analyst-grade reports with reasoned conclusions.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `config/config.json`, `references/mitre_techniques.md` and `references/report_template.md`).

It sits in Security, covering Reverse engineering and malware and OSINT. The repository describes itself as: A curated collection of DFIR skills and workflows for InfoSec practitioners. The licence is Apache-2.0.

When your agent uses it

  • File uploads with requests like analyze this malware
  • Analyze this sample
  • What does this executable do
  • Check this file for malware

Example prompts

  • “analyze this malware”
  • “analyze this sample”
  • “what does this executable do”
  • “/malware-analysis”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Collect Data
  2. Analyze and Reason (THIS IS THE KEY STEP)
  3. Write the Report

What it can do on your machine

Read from SKILL.md and the folder at commit 6e52942. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Malware Analysis loads about 2.5k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 842 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tsale/awesome-dfir-skills at commit 6e52942, republished under its Apache-2.0 licence (© tsale). 842 words, ~2,539 tokens.

Download SKILL.mdSave it as .claude/skills/malware-analysis/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
malware-analysis
description
Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with requests like "analyze this malware", "analyze this sample", "what does this executable do", "check this file for malware", or any request to examine suspicious files. Performs static analysis, threat intelligence triage, behavioral inference, and produces analyst-grade reports with reasoned conclusions.

Malware Analysis Skill

This skill produces analyst-grade threat reports — not data dumps. Every conclusion must be backed by evidence and reasoning.

Core Principles

  1. Evidence-based reasoning: Never state a conclusion without explaining WHY
  2. Connect the dots: Link indicators to behaviors to capabilities to impact
  3. Assess confidence: State how confident you are and why
  4. Actionable output: Reports should enable decisions, not just inform

Analysis Workflow

Step 1: Collect Data

Run all scripts to gather raw data:

bash
# Static analysis - get hashes, PE info, strings, APIs, entropy
python3 scripts/static_analysis.py /path/to/sample -f json > static.json

# Threat intelligence - check reputation across sources
python3 scripts/triage.py -t file /path/to/sample -f json > triage.json

# IOC extraction - extract network/host indicators
python3 scripts/extract_iocs.py /path/to/sample -f json > iocs.json
Step 2: Analyze and Reason (THIS IS THE KEY STEP)

Using the collected data, perform analyst-grade reasoning:

2.1 Threat Intelligence Assessment

Ask yourself:

  • Is this sample known? If found in MalwareBazaar/ThreatFox, it's confirmed malware
  • What's the VT detection rate?
    • 0 detections: New sample, FP, or clean — requires behavioral analysis
    • 1-5 detections: Possibly new variant or targeted — suspicious
    • 5-15 detections: Confirmed malicious by multiple vendors
    • 15+ detections: Well-known malware
  • What family is it attributed to? Research that family's typical behavior
  • When was it first seen? Recent = active campaign

Always explain your reasoning:

"This sample is identified as RedLine Stealer by MalwareBazaar with 45/70 VT detections. The high detection rate and presence in curated malware repositories confirms this is a known threat, not a false positive."

2.2 Behavioral Analysis from Static Indicators

API Analysis - Map APIs to behaviors:

API PatternLikely BehaviorReasoning
VirtualAlloc + VirtualProtect + WriteProcessMemory + CreateRemoteThreadProcess InjectionThis is the classic injection pattern: allocate memory, make it executable, write code, execute in target
CredEnumerate, CryptUnprotectDataCredential TheftThese APIs specifically access Windows credential stores and DPAPI-protected data (browser passwords)
InternetOpen + URLDownloadToFileDownloaderInitializes HTTP and downloads files — classic dropper behavior
RegSetValueEx + Run key paths in stringsPersistenceWriting to Run keys ensures execution at startup
IsDebuggerPresent, GetTickCount, NtQuerySystemInformationAnti-AnalysisMultiple evasion checks suggest the malware hides its behavior during analysis
CryptEncrypt + file enumeration APIsPossible RansomwareEncryption capability combined with file discovery — but could also be secure C2

Always explain your reasoning:

"The presence of VirtualAlloc, VirtualProtect, and CreateRemoteThread together strongly suggests process injection capability. Individually these APIs have legitimate uses, but this specific combination is the textbook pattern for injecting code into other processes."

Packing Analysis:

IndicatorMeaningConfidence
Entropy > 7.0Compressed/encrypted contentHigh
Section entropy > 7.0 (especially .text)Packed code sectionHigh
UPX0, UPX1, .aspack, .packed sectionsKnown packer signaturesVery High
RWX sectionsSelf-modifying codeMedium
Small import table with GetProcAddress/LoadLibrary onlyDynamic API resolutionHigh

If packed, state the implication:

"This sample shows multiple packing indicators (entropy 7.4, UPX sections). The static analysis findings represent the unpacker stub, NOT the actual payload. Dynamic analysis is required to reveal true functionality."

2.3 Capability Assessment

Based on the evidence, determine what the malware CAN DO:

CapabilityRequired EvidenceConfidence Level
Process Injection2+ injection APIsHigh if 3+, Medium if 2
Credential TheftAny cred access APIHigh (these are specific)
KeyloggingSetWindowsHookExMedium (has legit uses)
Network C22+ network APIs + extracted URLs/IPsHigh
File DownloadURLDownloadToFile or similarHigh
PersistenceRegistry/service APIs + relevant stringsMedium
Encryption/RansomwareCrypto APIs + file enumerationMedium (needs context)

State confidence and reasoning:

"Credential Theft Capability: HIGH CONFIDENCE — CryptUnprotectData is present, which specifically decrypts DPAPI-protected data including browser passwords. This API has no legitimate use case in most software."

Show full SKILL.md (307 more words)Show less
2.4 Risk Assessment

Determine risk level with justification:

Risk LevelCriteria
CRITICALCredential theft APIs, process injection, confirmed malware family known for data theft/ransomware
HIGHMultiple malicious capabilities, network C2, persistence mechanisms
MEDIUMSuspicious indicators but no confirmed malicious capability, or packing hiding true behavior
LOWFew indicators, possibly legitimate software with suspicious patterns
UNKNOWNInsufficient evidence, heavily packed, or no TI hits
Step 3: Write the Report

Structure your report as follows:

markdown
# Threat Analysis Report: [MALWARE_NAME or "Unknown Sample"]

| | |
|---|---|
| **Risk Level** | [CRITICAL/HIGH/MEDIUM/LOW] |
| **Confidence** | [High/Medium/Low] |
| **Analysis Date** | [DATE] |

---

## Executive Summary

[2-3 sentences: What is this? Is it malicious? What can it do? How do we know?]

**Key Finding:** [One sentence bottom line]

---

## Threat Intelligence Assessment

[What do TI sources tell us? Explain what each finding means]

- **VirusTotal:** [X/Y detections] — [what this means]
- **MalwareBazaar:** [Found/Not found] — [what this means]  
- **Family Attribution:** [Family name] — [what this family typically does]

**Assessment:** [Your reasoned conclusion based on TI]

---

## Behavioral Analysis

### Identified Capabilities

#### [Capability 1: e.g., "Process Injection"]
- **Confidence:** [High/Medium/Low]
- **Evidence:** [List the specific APIs/strings found]
- **Reasoning:** [Explain WHY this evidence indicates this capability]

#### [Capability 2: e.g., "Credential Theft"]
...

### Packing Assessment

[Is it packed? What does this mean for the analysis?]

### Anti-Analysis Techniques

[What evasion techniques were identified?]

---

## MITRE ATT&CK Mapping

| Tactic | Technique | ID | Evidence |
|--------|-----------|----|---------| 
| [Only include techniques you can justify with evidence] |

---

## Indicators of Compromise

### File Indicators
[Hashes]

### Network Indicators  
[Defanged IPs, domains, URLs - only if extracted]

### Host Indicators
[Registry keys, file paths, mutexes - only if found]

---

## Risk Assessment

**Overall Risk: [LEVEL]**

This assessment is based on:
1. [Reason 1]
2. [Reason 2]
3. [Reason 3]

**Confidence in Assessment: [High/Medium/Low]**
- [Why this confidence level]

---

## Recommendations

### Immediate Actions
[What should be done RIGHT NOW based on risk level]

### Detection Opportunities
[How to detect this threat]

### Further Analysis Needed
[What questions remain unanswered]
Entropy Interpretation
EntropyMeaning
0-1Highly structured (empty, repetitive)
4-5Plain text, readable strings
5-6Compiled code (normal .text section)
6-7Compressed data, some obfuscation
7-8Encrypted/compressed (PACKED)
File Signatures
BytesType
4D 5A (MZ)PE executable
50 4B (PK)ZIP/Office document
7F 45 4C 46ELF executable
D0 CF 11 E0OLE/Legacy Office
25 50 44 46PDF

Example Analysis Reasoning

BAD (data dump):

"Found APIs: VirtualAlloc, CreateRemoteThread, RegSetValueEx. Entropy: 7.2. VT: 34/70."

GOOD (analyst reasoning):

"This sample demonstrates process injection capability (HIGH CONFIDENCE) based on the presence of VirtualAlloc and CreateRemoteThread. These APIs, when used together, form the classic code injection pattern where memory is allocated in a target process and a thread is created to execute the injected code. The high entropy (7.2) suggests the payload is packed, meaning the observed APIs may belong to the unpacker stub rather than the final payload. The 34/70 VirusTotal detection rate confirms this is recognized malware, with multiple vendors identifying it as a variant of Agent Tesla — an info-stealer known for credential harvesting. Given the injection capability and association with a credential-stealing family, this sample poses a CRITICAL risk to credential security on any system where it executes."

Scripts Reference

static_analysis.py
bash
python3 scripts/static_analysis.py <file> -f [text|json]

Extracts: hashes, file type, PE headers, sections, entropy, imports, strings, suspicious indicators

triage.py
bash
python3 scripts/triage.py <ioc> -f [text|json]
python3 scripts/triage.py -t file <filepath> -f json
python3 scripts/triage.py --status  # Check API config

Queries: MalwareBazaar, ThreatFox, URLhaus, VirusTotal, AbuseIPDB

extract_iocs.py
bash
python3 scripts/extract_iocs.py <file> -f [text|json|csv]

Extracts: IPs, domains, URLs, emails, hashes, registry keys, file paths, crypto wallets, mutexes

© tsale, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in skills/analysis/malware-analysis-tr of tsale/awesome-dfir-skills.

  • SKILL.md
  • config/config.json
  • references/mitre_techniques.md
  • references/report_template.md
  • scripts/extract_iocs.py
  • scripts/generate_report.py
  • scripts/static_analysis.py
  • scripts/triage.py

Open the folder on GitHubat commit 6e52942

Compare with similar skills

Malware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Malware Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Malware Analysis this skilltsale/awesome-dfir-skills324—~2.5kAutomated safety check: PassApache-2.0
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill935—~2.4kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k2 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    935 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 2 repos~2.3k tokens
    SecurityAuto-check: notes
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from tsale/awesome-dfir-skills

  • Admiralty System

    tsale/awesome-dfir-skills

    Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis.

    324 GitHub stars~3.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Analysing Attack

    tsale/awesome-dfir-skills

    Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

    324 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Osquery Query Helper

    tsale/awesome-dfir-skills

    Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.

    324 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Threat Actor Profiling

    tsale/awesome-dfir-skills

    Build structured threat actor profiles using the 5W1H framework and the Diamond Model.

    324 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Malware Analysis

What does Malware Analysis do?

Professional malware analysis workflow for PE executables and suspicious files. Malware Analysis is an agent skill from tsale/awesome-dfir-skills. Professional malware analysis workflow for PE executables and suspicious files.

When should I use Malware Analysis?

Malware Analysis fits situations like: file uploads with requests like analyze this malware; analyze this sample; what does this executable do; check this file for malware.

How do I install Malware Analysis in Claude Code?

Run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a claude-code`. Or copy the skill folder (skills/analysis/malware-analysis-tr in tsale/awesome-dfir-skills) into .claude/skills/malware-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Malware Analysis in Codex?

Run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a codex`. Or copy the skill folder (skills/analysis/malware-analysis-tr in tsale/awesome-dfir-skills) into .agents/skills/malware-analysis in your project. Codex loads it when a task matches its description.

Can I use Malware Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsale/awesome-dfir-skills --skill malware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malware-analysis, .gemini/skills/malware-analysis, .github/skills/malware-analysis and .opencode/skills/malware-analysis in your project.

What does Malware Analysis need to run?

Going by SKILL.md and its folder, Malware Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Malware Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Malware Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Malware Analysis use?

Malware Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Malware Analysis use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Malware Analysis?

Skills that share tags, products or a category with Malware Analysis: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 935 stars) and Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Malware Analysis?

tsale (a GitHub user) maintains it in tsale/awesome-dfir-skills, which has 324 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on May 14, 2026.

Source: tsale/awesome-dfir-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.