Use when extracts indicators of compromise (IOCs) from malware samples
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill extracting-iocs-from-malware-samples --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Extracting Iocs From Malware Samples?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-extracting-iocs-from-malware-samples)More formats (shields.io, HTML) on the badges page.
---
name: extracting-iocs-from-malware-samples
description: Use when extracts indicators of compromise (IOCs) from malware samples
including file hashes, network indicators (IPs, domains, URLs), host artifacts (file
paths, registry keys, mutexes), and behavioral patterns for threat intelligence
sharing and detection rule creation. Activates for requests involving IOC extraction,
threat indicator harvesting, malware indicator collection, or building detection
content from samples. . Use when working with extracting iocs from malware samples.
domain: cybersecurity
tags:
- malware
- IOC-extraction
- threat-intelligence
- indicators
- detection
subdomain: malware-analysis
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- DE.AE-02
- RS.AN-03
- ID.RA-01
- DE.CM-01
category: cybersecurity
---
# Extracting Iocs From Malware Samples
## Overview
Cybersecurity skill for extracting iocs from malware samples. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "extracting iocs from malware samples"
- "Extracts indicators of compromise (IOCs) from malware samples including file has"
- A malware analysis (static or dynamic) is complete and actionable indicators need to be extracted for defense teams
- Building blocklists for firewalls, proxies, and DNS sinkholes from analyzed samples
- Creating YARA rules, Snort/Suricata signatures, or SIEM detection content from malware artifacts
- Contributing to threat intelligence sharing platforms (MISP, OTX, ThreatConnect)
- Tracking malware campaigns by correlating IOCs across multiple samples
**Do not use** for IOCs from unverified sources without validation; false positives in blocklists can disrupt legitimate business operations.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Python 3.8+ with `iocextract`, `pefile`, `yara-python` libraries installed
- Completed malware analysis report (static analysis, dynamic analysis, or reverse engineering)
- Access to PCAP files, memory dumps, or sandbox reports from the analysis
- MISP instance or STIX/TAXII server for structured IOC sharing
- VirusTotal API key for IOC enrichment and validation
- CyberChef for decoding obfuscated indicators
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Define Objectives** — Clarify the goals and scope for iocs from malware samples.
2. **Gather Resources** — Collect tools, data, and access needed for iocs from malware samples.
3. **Execute Process** — Carry out iocs from malware samples operations methodically.
4. **Verify Quality** — Check results against acceptance criteria.
5. **Document Outcomes** — Record findings, decisions, and next steps.
## Tools
- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing
## Process
1. **Reconnaissance** — Gather target information, identify attack surface, enumerate services
1. **Analysis/Exploitation** — Execute the technique, analyze results, document findings
1. **Reporting** — Document IOCs, write findings, provide remediation recommendations
## Verification
- [ ] All iocs from malware samples procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!