Observe suspicious content in a disposable environment. Use when execution, process ancestry, file changes, persistence, network behavior, payloads, or user interaction need measurement after static analysis with isolation and teardown.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill perform-dynamic-malware-analysis --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Perform Dynamic Malware Analysis?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-perform-dynamic-malware-analysis)More formats (shields.io, HTML) on the badges page.
---
name: perform-dynamic-malware-analysis
description: Observe suspicious content in a disposable environment. Use when execution, process ancestry, file changes, persistence, network behavior, payloads, or user interaction need measurement after static analysis with isolation and teardown.
---
# Perform Dynamic Malware Analysis
## Overview
Execute only inside an environment chosen by `select-analysis-isolation` and preflighted by `prepare-isolated-analysis-lab`, with an observation plan that can distinguish artifact behavior from baseline noise. Preserve the exact sample, prepared-lab record, and environment identity.
Read [references/dynamic-observation-plan.md](references/dynamic-observation-plan.md) for baseline, stimulus, telemetry, and teardown fields.
## Workflow
1. Define the unresolved question and minimum stimulus.
2. Verify isolation.
- Require the prepared-lab record and verify its guest/platform build, baseline/reset state, accounts, shares, clipboard, devices, credentials, network mode, monitoring, stop controls, export path, and teardown plan are still current.
- Record virtualization artifacts or anti-VM behavior that may affect the conclusion.
3. Capture a baseline.
- Record processes, files/registrations, persistence surfaces, network state, services, and relevant logs before execution.
4. Execute one controlled step.
- Record command/UI action, time, user/privilege, environment variables, arguments, and interactions.
- Do not improvise additional payloads, credentials, or targets.
5. Observe behavior.
- Correlate process tree, file/registry or platform state, persistence, permissions, child artifacts, network/DNS, logs, prompts, crashes, and timing.
- Hash and preserve dropped/modified artifacts as new evidence.
6. Repeat only to answer a named question.
- Change one variable at a time and revert to the baseline snapshot.
7. Export and tear down.
- Export only intended evidence, scan it before host use, destroy/revert the environment, and revoke temporary access.
## Output
Return the prepared-lab identity, environment/baseline identity, stimulus, observed timeline, artifacts and indicators, absent expected behavior, virtualization/evasion/coverage limits, conclusion, and teardown verification.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!