hypnguyen1209/malware-analysis
Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill malware-analysis
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Hash/imphash/Rich/ssdeep/TLSH triage + PE anomalies | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py |
| Per-section entropy + packer/RWX/EP heuristics | T1027.002 | CWE-1066 | references/static-triage-capa.md | scripts/triage.py |
| Obfuscated string recovery (FLOSS) | T1140, T1027.013 | CWE-656 | references/static-triage-capa.md | scripts/triage.py |
| Capability detection → ATT&CK (capa, static+dynamic) | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py |
| Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling) | T1140, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/auto_unpack.py |
| DBI unpacking via API hooks (Frida) | T1055, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js |
| .NET deobfuscation/unpacking (de4dot/dnSpyEx) | T1027, T1140 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js |
| Sandbox detonation + behavioral capture | T1497 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |
| Memory injection/hollowing/ghosting analysis (Vol3) | T1055, T1055.012 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |
| AMSI/ETW in-memory patch + patchless detection | T1562.001 | CWE-693 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |
| Fileless WMI/registry/PowerShell persistence | T1546.003, T1547.001, T1059.001 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |
| Cobalt Strike / AdaptixC2 config extraction | T1071.001, T1573 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py |
| Config framework at scale (MACO/CAPE) | T1071.001 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py |
| Generic unknown-C2 protocol RE + decoder | T1573, T1071.004 | CWE-311 | references/config-c2-extraction.md | scripts/cs_config_extract.py |
| Beacon cadence/jitter detection (PCAP/Zeek) | T1071.001, T1029 | CWE-778 | references/network-c2-detection.md | scripts/beacon_profiler.py |
| JA4+ TLS/HTTP/cert fingerprinting (Sliver/Havoc JA4X) | T1071.001, T1573 | CWE-295 | references/network-c2-detection.md | scripts/beacon_profiler.py |
| Tunneled/DoH C2 surfacing (cloudflared/chisel) | T1572, T1568.002, T1071.004 | CWE-441 | references/network-c2-detection.md | scripts/beacon_profiler.py |
| YARA-X family rule authoring + FP validation | T1027 | CWE-506 | references/yara-detection-engineering.md | scripts/yara_gen.py |
# 1. Static triage: hashes + PE anomalies + capability combos + FLOSS/capa/YARA-X
python3 scripts/triage.py sample.exe --floss --capa --yara rules/family.yar --json out/triage.json
capa -j sample.exe > out/capa.json # capabilities -> ATT&CK
# 2. Unpack (try emulation first; DBI fallback in isolated VM)
python3 scripts/auto_unpack.py sample.exe -o out/dumps/ # static emulation, no detonation
frida -f C:\sample.exe -l scripts/frida_unpack.js --no-pause # DBI, isolated VM only
de4dot sample.exe -o cleaned.exe # .NET layer
# 3. Dynamic + memory (capture mem BEFORE remediation)
python3 scripts/mem_triage.py -f mem.raw --vol vol --patch-hunt --json out/mem.json
# 4. Config + C2 extraction
python3 scripts/cs_config_extract.py beacon.bin --json # Cobalt Strike
python3 1768.py -S beacon.bin # full CS incl. runtime/heap config
configextractor sample.bin # MACO/MWCP/CAPE at scale
# 5. Network C2 detection
python3 scripts/beacon_profiler.py capture.pcap --min-beacons 6 # cadence/jitter
zeek -r capture.pcap LOCAL ja4 && zeek-cut ja4 ja4s ja4x < ja4.log # JA4+ pivots
# 6. Detection engineering
python3 scripts/yara_gen.py --family samples/fam/ --name Fam --goodware /usr/bin --out rules/fam.yar
yara-x fmt rules/fam.yar && yara-x scan rules/fam.yar /corpus/
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|---------------|------------------------|------------|
| Static triage | None (offline) | n/a — feeds YARA/imphash hunting | Read-only, no execution; isolate sample dir |
| Emulation unpack | None (no detonation) | n/a | Preferred first pass; safe, no network |
| DBI/manual unpack | Sysmon 8/10 (CallTrace UNKNOWN), RWX commit | EDR memory scan; RWX-then-exec Sigma | DETONATES — isolated VM, snapshot, FakeNet; loaders self-delete, dump first |
| Injection/hollowing | malfind/hollowprocesses; EID 8/10 | Vol3 hollow/ghosting/pebmasquerade; CreateRemoteThread | Capture memory pre-remediation |
| AMSI/ETW patch | amsi.dll load + patched prologue; B8 00..C3 stub | Sigma T1562.001; debug-reg+VEH for patchless | Patchless evades byte scans — watch Dr0-Dr7 |
| Fileless persistence | WMI consumers; PS 4104; Run-key blobs | Vol3 registry/wmi; Sysmon 13/22 | Lives in WMI/registry/memory — no disk file |
| Config extraction | C2 host/UA/pipe/watermark | YARA config table; Suricata on C2 URI/SNI | Offline; handle watermark/keys per ROE |
| Beacon detection | Periodic outbound deltas | beacon_profiler CV score; Suricata threshold | Passive on captured traffic |
| JA4+ fingerprint | JA4/JA4S/JA4X/JA4H tuples | Zeek ja4 watchlist (Sliver/Havoc JA4X) | JA4X needs TLS1.3 cert visibility at proxy |
| YARA-X authoring | None | The rules themselves | Validate 0-FP on goodware before deploy |
Take hypnguyen1209/malware-analysis from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.