Analyze a suspicious artifact without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or payloads when metadata, signatures, imports, strings, resources, and obfuscation need inspection.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill perform-static-malware-analysis --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Perform Static Malware Analysis?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-perform-static-malware-analysis-socket)More formats (shields.io, HTML) on the badges page.
---
name: perform-static-malware-analysis
description: Analyze a suspicious artifact without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or payloads when metadata, signatures, imports, strings, resources, and obfuscation need inspection.
---
# Perform Static Malware Analysis
## Overview
Build a capability hypothesis from preserved bytes and structure. Keep every source-level or behavioral claim bounded by what static evidence can actually prove.
Read [references/static-analysis-layers.md](references/static-analysis-layers.md) for layered checks and escalation criteria.
## Workflow
1. Establish artifact identity and working copy.
2. Inspect outer structure.
- Identify formats, architectures, bundles, packages, sections, members, overlays, embedded resources, signatures, timestamps, and declared permissions.
3. Extract low-risk indicators.
- Collect imports/exports, linked libraries, symbols, strings, URLs/domains, paths, commands, mutex/service names, configuration, certificates, and persistence references.
4. Inspect code and content shape.
- Identify interpreters, entry points, packers/obfuscation, encrypted blobs, staged payloads, anti-analysis checks, and unusual executable mappings.
- Use YARA-X or other local rules as evidence with rule/version recorded.
5. Form capability hypotheses.
- Map evidence to possible execution, persistence, discovery, credential, collection, command-and-control, exfiltration, or defense-evasion behavior.
- Separate present code from reachable behavior and capability from observed execution.
6. Escalate deliberately.
- Use `reverse-engineering-skills` for control flow, decompilation, protocol/config recovery, or exact binary comparisons.
- Use dynamic analysis only after isolation selection and a clear observation plan.
## Output
Return identity, structure, indicators, likely capabilities, contradictory evidence, obfuscation/coverage limits, confidence, and the smallest next analysis step.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!