Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Re Env Sandbox

ASecurity

逆向隔离环境流程——搭建可回滚的隔离分析场:虚拟机与快照基线链、网络隔离与受控出网、驱动签名与 Secure Boot 对隐藏驱动的影响、系统时间控制、符号环境、反虚拟机与反沙箱检测排查。当用户准备在真机外分析未知样本、需要快照回滚、要断网或改日期做破坏性实验、需要加载内核级隐藏驱动,或 re-flow-orchestrator 进入 SANDBOX 阶段时使用。触发词:隔离环境、虚拟机、快照、回滚、断网、改系统时间、驱动签名、Secure Boot、反虚拟机、符号服务器。

34 stars
0 votes
0 copies
0 views
Added 9/24/2026
ai-agentsshellbashapi

Works with

api

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add alicewe1/alice_skill --skill re-env-sandbox --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Re Env Sandbox?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Re Env Sandbox
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-re-env-sandbox/badge)](https://www.skillsdirectory.com/skills/alicewe1-re-env-sandbox)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: re-env-sandbox
description: 逆向隔离环境流程——搭建可回滚的隔离分析场:虚拟机与快照基线链、网络隔离与受控出网、驱动签名与 Secure Boot 对隐藏驱动的影响、系统时间控制、符号环境、反虚拟机与反沙箱检测排查。当用户准备在真机外分析未知样本、需要快照回滚、要断网或改日期做破坏性实验、需要加载内核级隐藏驱动,或 re-flow-orchestrator 进入 SANDBOX 阶段时使用。触发词:隔离环境、虚拟机、快照、回滚、断网、改系统时间、驱动签名、Secure Boot、反虚拟机、符号服务器。
agent_created: true
x-alice-class: reverse
---# 隔离环境流程(re-env-sandbox)

## 单一职责

只做一件事:**提供一个可随时回滚、不外泄、行为尽量贴近真机的干净实验场**。
不做工具安装(re-tool-*)、不做具体分析(re-flow-*)。

## 触发条件

- 首次分析未知样本之前
- 需要破坏性实验:改系统日期、断网、清注册表、跑可疑样本
- 需要内核级隐藏驱动(TitanHide / HyperHide / ScyllaHide 内核模式)
- orchestrator 进入 SANDBOX 阶段

## 输入与输出

- **输入**:宿主机系统与虚拟化支持情况;目标程序位数;是否需要内核驱动
- **输出**:可用的隔离环境 + 任务目录 `env.md`(OS 版本、快照名与时间点、网络策略、时间策略、符号路径、已验证可加载的驱动版本、回滚方法)

## 为什么必须先做

**没有快照 = 没有撤销**:一次蓝屏、样本跑飞、误删就要重装系统,之前所有进度归零。
**反虚拟机检测会让行为失真**:样本在 VM 里可能直接拒绝运行或走"错误分支",你抓到的请求、看到的"校验失败"可能全是假象,据此做的判断全部作废。

## 执行步骤

1. **选载体**:优先二型虚拟机(VMware Workstation / VirtualBox),快照机制成熟、回滚快、可多分支。需要更强对抗再考虑内核隐藏方案(风险高、易蓝屏)。**不要拿日常用机直接上**。
2. **建基线快照链**(命名带序号与时间点,每次重大操作前打一个):
   - `00-clean`:系统装好、关自动更新、工具链未装、**未运行样本**
   - `01-tools`:工具链完整(re-tool-manifest 自检通过)
   - `02-<动作>`:每个破坏性实验前各打一个
   - 回滚前先确认当前所在快照分支,避免误删后续快照
3. **网络策略**:默认 host-only 或无网络;需要抓包时才改为 NAT + 受控代理(Fiddler / mitmproxy)。**默认不出公网**:样本可能外传本机数据、回连 C2,在线激活多次失败还可能触发机器封禁。
4. **共享与剪贴板**:默认关闭(既防外泄也防样本逃逸)。确需传文件用一次性只读共享或 ISO。
5. **时间控制**:关闭 VM tools 的时间同步(否则改的日期会被偷偷同步回去),改日期前先断网。用于验证试用期与时间锁。
6. **驱动签名与 Secure Boot**(仅在上内核级隐藏驱动时需要):
   - 关闭 Secure Boot(BIOS)或开启测试签名 `bcdedit /set testsigning on` → 重启
   - 测试签名状态本身会被部分程序识别为"调试环境",且 Win10/Win11 不同版本内核结构偏移不同 → **换 OS 版本必须重新验证驱动能否加载,不要复用旧驱动**
   - 优先级:先用 ScyllaHide 用户模式;不够再上内核
7. **符号环境**:设置 `_NT_SYMBOL_PATH`,让系统 API 名可见。否则 API 断点只能靠硬地址,换机即失效、追踪效率降一个量级。
8. **反虚拟机 / 反沙箱检测排查**:跑样本前先确认是否存在检测(设备名、MAC 前缀、CPUID hypervisor 位、进程数、磁盘名、BIOS 串、鼠标移动)。有检测 → 用 VM 配置伪装或改用真机隔离分区,否则后续结论不可信。
9. **记录**:写入 `env.md`,含快照名、网络策略、时间策略、符号路径、已验证可加载的驱动版本。

## 环境差异速查(最容易踩的)

| 差异 | 表现 | 处置 |
|---|---|---|
| Win10 vs Win11 / 22H2 vs 23H2 | 内核结构偏移不同 → 隐藏驱动蓝屏 | 换版本先验证驱动可加载 |
| Secure Boot 开启 | 未签名驱动拒绝加载 | 关 Secure Boot,或开测试签名(会被检测) |
| 32 位 vs 64 位 | 驱动与调试器位数必须匹配 | 64 位系统配 64 位驱动 + 64 位 x64dbg |
| VM tools 时间同步 | 改的日期被自动改回 | 关时间同步 + 断网后再改 |
| 直连公网 | 样本外传 / 激活封禁 | 默认 host-only,抓包时才开受控代理 |
| 无快照 | 一次蓝屏即重装 | 每个破坏性实验前打快照 |
| 本机 bash coreutils 损坏 | `ls`/`head`/`dirname` 报 command not found | 所有目录操作走 PowerShell |

## 边界与上下游

- **前置**:re-tool-manifest 自检通过后才打 `01-tools` 快照(保证快照里工具齐全、可复用)
- **后继**:所有 re-flow-* 阶段都在本环境内执行;每个破坏性动作前先回滚到最近快照
- **不重复**:样本本身的行为侦察属 re-flow-recon;本 skill 只提供场地、隔离策略与回滚手段

## 参考资源

- `references/env-recipes.md` —— 快照、网络、时间、驱动签名、符号环境的具体命令与检查清单

Attribution

alicewe1alicewe1
View sourceSee grades on GitHubMore from alicewe1 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →