Analyze suspicious files safely with static and dynamic techniques to determine capability, indicators, and defensive mitigations.
Scanned 9/29/2026
npx -y skills add aicodedecode/awesome-muse-skills --skill malware-analyst --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Malware Analyst?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aicodedecode-malware-analyst)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: malware-analyst
description: Analyze suspicious files safely with static and dynamic techniques to determine capability, indicators, and defensive mitigations.
category: security
---
## Overview
Malware analysis answers: **what does this file do, how do we detect it, and how do we stop it?** Analysts work in isolated labs, using static analysis (examining the file without running it) and dynamic analysis (observing it in a sandbox) to extract indicators of compromise (IOCs) and behaviors defenders can detect and block.
This skill is strictly defensive: safe handling, analysis methodology, IOC extraction, and turning findings into detections. It contains no instructions for creating, modifying, or weaponizing malware.
Malware analysis is detective work where the evidence actively lies to you — packers, anti-analysis tricks, and environment checks all exist to waste your time. Methodology is the countermeasure: static before dynamic, hypotheses before conclusions, and every claim backed by an artifact. The analyst's real product is not the report but the detections and hunts it enables.
## When to use
- Triaging a suspicious attachment, download, or endpoint detection.
- Enriching an incident with IOCs (hashes, domains, IPs, mutexes, registry keys).
- Writing detections for a malware family or campaign.
- Deciding whether an alert is a true infection or a false positive.
## Core concepts
- **Safety first, always:** analyze only in an isolated VM or sandbox with no production network access, snapshots for rollback, and no shared folders/clipboard with the host. Treat every sample as live.
- **Static before dynamic:** strings, headers, imports, entropy, and packer identification tell you a lot without ever executing anything. Dynamic analysis confirms behavior.
- **IOCs vs behaviors:** hashes and IPs are brittle (attackers change them); behaviors (persistence mechanisms, injection patterns, C2 beaconing cadence) make durable detections. Extract both, prioritize behaviors.
- **Capability assessment:** what *can* it do (keylogging, exfiltration, lateral movement, ransomware) determines incident severity and response.
- **Attribution is optional:** for defenders, "how do we detect and remove it" matters more than "who wrote it." Do not burn hours on attribution during an active incident.
- **Handling and sharing:** label samples, store securely, share IOCs with the team; follow your org's policy (and legal) before uploading to public sandboxes — the file may contain sensitive data.
- **Config extraction.** Many families store C2 addresses, keys, and campaign IDs in recoverable configs — extracting them turns one sample into infrastructure-wide intelligence.
- **YARA for hunting, not just matching.** Write rules on behavioral strings and structural features, test against clean corpora, and deploy for retro-hunting across the estate.
- **Family tracking.** Cluster samples into families/campaigns over time — defenders who track families predict infrastructure reuse and preempt the next wave.
## Practical workflow
1. **Intake and safety:** receive the sample via a secure channel, verify the hash, and move it only into the isolated lab. Snapshot the analysis VM first. Confirm no network route to production.
2. **Static analysis:** file type and hashes (MD5/SHA256 for pivoting); strings review (URLs, IPs, registry paths, suspicious API imports); PE/ELF/Mach-O header inspection; entropy check for packing/encryption; compare hashes against threat intel.
3. **Dynamic analysis:** detonate in the sandbox; capture process tree, file/registry changes, network connections (DNS, HTTP, C2 patterns), and persistence mechanisms. Run for enough time to observe delayed behaviors.
4. **Behavioral summary:** document capabilities observed — execution method, persistence, privilege escalation attempts, credential access, C2, exfiltration, impact (encryption, deletion).
5. **Extract IOCs and behaviors:** atomic indicators (hashes, domains, IPs, filenames, mutexes) plus behavioral signatures (e.g., "writes to Run key then beacons every 60s to a fresh domain").
6. **Defensive output:** publish an internal bulletin — summary, severity, IOCs in shareable format, detection rules (SIEM/EDR), containment and eradication steps, and whether a wider hunt is warranted.
### Safe-lab checklist
- [ ] Dedicated, isolated VM/network segment; no prod routes
- [ ] Snapshot taken before detonation; rollback plan ready
- [ ] No shared clipboard/folders between host and analysis VM
- [ ] Sample handled by hash; original preserved with chain of custody
- [ ] Public-sandbox upload approved (or avoided) per data-sensitivity policy
- [ ] Findings documented before VM rollback
### Sustaining the practice
- Maintain a private sample and IOC repository with full provenance
- Retro-hunt new IOCs across historical telemetry on every bulletin
- Review detection efficacy quarterly — which rules actually fired?
- Share sanitized IOCs with ISACs and peers; receive theirs in return
### Metrics that prove it works
- Triage turnaround time (sample in → initial verdict)
- % of analyses that produce a new or improved detection
- IOC sharing timeliness (hours from analysis to team-wide availability)
- Bulletin action rate (did anyone actually hunt or block?)
## Common pitfalls
- **Analyzing on a production or personal machine.** One wrong double-click. Always the isolated lab.
- **Uploading sensitive samples to public sandboxes.** The file may contain customer data or credentials — check policy first.
- **IOC-only output.** Hashes without behavioral detections mean the next variant walks past you.
- **Attribution rabbit holes during incidents.** Interesting later; containment now.
- **Skipping the bulletin.** Analysis that stays in the analyst's head helps nobody. Write it up, share IOCs, file detections.
- **Forgetting the entry vector.** Knowing *how it arrived* (phish, drive-by, USB) determines which preventive control failed and needs fixing.
- **Dynamic-only analysis.** Environment-aware malware stays quiet in sandboxes. Static analysis first gives you the behaviors to look for and the config to extract.
- **IOCs living in email threads.** Unstructured sharing means IOCs die in inboxes. Publish to a structured, searchable store the SOC actually queries.
- **Analyzing without a time box.** Deep analysis is seductive; triage needs answers in hours. Set analysis depth by incident priority and stick to it.
- **Forgetting the human-readable summary.** Executives and IR leads need the 'so what' in three sentences. Bury it and your analysis will not drive decisions.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!