mcpbeat

Malware Analysis

hypnguyen1209/malware-analysis

Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing)

24k tokens
context cost
the whole folder, loaded on every use
14
files
ships runnable scripts
0
copies elsewhere
how many repositories repackaged it
334
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill malware-analysis

What comes with it

87 619 bytes besides the instruction
references/config-c2-extraction.md
references/dynamic-fileless-memory.md
references/network-c2-detection.md
references/static-triage-capa.md
references/unpacking-deobfuscation.md
references/yara-detection-engineering.md
scripts/auto_unpack.py
scripts/beacon_profiler.py
scripts/cs_config_extract.py
scripts/frida_unpack.js
scripts/mem_triage.py
scripts/triage.py
scripts/yara_gen.py

The instruction itself

6 sections, as written by the author

Malware Analysis

When to Activate

  • Triaging an unknown binary/script: identity, packing verdict, capability map, IOCs, go/no-go for detonation.
  • Recovering the real payload from a packed/crypted/obfuscated loader (commodity loaders, RAT chains, .NET).
  • Detonating safely and recovering fileless / in-memory artifacts (injection, AMSI/ETW patching, WMI persistence).
  • Extracting malware configuration (C2, keys, sleep/jitter, campaign IDs) for threat intel and detection.
  • Detecting/characterizing C2 on the wire (beacon cadence, JA4+ fingerprints, tunneled/DoH channels).
  • Writing durable, low-FP YARA-X detection from analysis findings; incident-response scoping.

Technique Map

| Technique | ATT&CK | CWE | Reference | Script |

|-----------|--------|-----|-----------|--------|

| Hash/imphash/Rich/ssdeep/TLSH triage + PE anomalies | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py |

| Per-section entropy + packer/RWX/EP heuristics | T1027.002 | CWE-1066 | references/static-triage-capa.md | scripts/triage.py |

| Obfuscated string recovery (FLOSS) | T1140, T1027.013 | CWE-656 | references/static-triage-capa.md | scripts/triage.py |

| Capability detection → ATT&CK (capa, static+dynamic) | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py |

| Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling) | T1140, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/auto_unpack.py |

| DBI unpacking via API hooks (Frida) | T1055, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js |

| .NET deobfuscation/unpacking (de4dot/dnSpyEx) | T1027, T1140 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js |

| Sandbox detonation + behavioral capture | T1497 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |

| Memory injection/hollowing/ghosting analysis (Vol3) | T1055, T1055.012 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |

| AMSI/ETW in-memory patch + patchless detection | T1562.001 | CWE-693 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |

| Fileless WMI/registry/PowerShell persistence | T1546.003, T1547.001, T1059.001 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py |

| Cobalt Strike / AdaptixC2 config extraction | T1071.001, T1573 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py |

| Config framework at scale (MACO/CAPE) | T1071.001 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py |

| Generic unknown-C2 protocol RE + decoder | T1573, T1071.004 | CWE-311 | references/config-c2-extraction.md | scripts/cs_config_extract.py |

| Beacon cadence/jitter detection (PCAP/Zeek) | T1071.001, T1029 | CWE-778 | references/network-c2-detection.md | scripts/beacon_profiler.py |

| JA4+ TLS/HTTP/cert fingerprinting (Sliver/Havoc JA4X) | T1071.001, T1573 | CWE-295 | references/network-c2-detection.md | scripts/beacon_profiler.py |

| Tunneled/DoH C2 surfacing (cloudflared/chisel) | T1572, T1568.002, T1071.004 | CWE-441 | references/network-c2-detection.md | scripts/beacon_profiler.py |

| YARA-X family rule authoring + FP validation | T1027 | CWE-506 | references/yara-detection-engineering.md | scripts/yara_gen.py |

Quick Start

# 1. Static triage: hashes + PE anomalies + capability combos + FLOSS/capa/YARA-X
python3 scripts/triage.py sample.exe --floss --capa --yara rules/family.yar --json out/triage.json
capa -j sample.exe > out/capa.json                       # capabilities -> ATT&CK

# 2. Unpack (try emulation first; DBI fallback in isolated VM)
python3 scripts/auto_unpack.py sample.exe -o out/dumps/  # static emulation, no detonation
frida -f C:\sample.exe -l scripts/frida_unpack.js --no-pause   # DBI, isolated VM only
de4dot sample.exe -o cleaned.exe                         # .NET layer

# 3. Dynamic + memory (capture mem BEFORE remediation)
python3 scripts/mem_triage.py -f mem.raw --vol vol --patch-hunt --json out/mem.json

# 4. Config + C2 extraction
python3 scripts/cs_config_extract.py beacon.bin --json    # Cobalt Strike
python3 1768.py -S beacon.bin                             # full CS incl. runtime/heap config
configextractor sample.bin                               # MACO/MWCP/CAPE at scale

# 5. Network C2 detection
python3 scripts/beacon_profiler.py capture.pcap --min-beacons 6     # cadence/jitter
zeek -r capture.pcap LOCAL ja4 && zeek-cut ja4 ja4s ja4x < ja4.log  # JA4+ pivots

# 6. Detection engineering
python3 scripts/yara_gen.py --family samples/fam/ --name Fam --goodware /usr/bin --out rules/fam.yar
yara-x fmt rules/fam.yar && yara-x scan rules/fam.yar /corpus/

OPSEC & Detection (summary)

| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note |

|-----------|---------------|------------------------|------------|

| Static triage | None (offline) | n/a — feeds YARA/imphash hunting | Read-only, no execution; isolate sample dir |

| Emulation unpack | None (no detonation) | n/a | Preferred first pass; safe, no network |

| DBI/manual unpack | Sysmon 8/10 (CallTrace UNKNOWN), RWX commit | EDR memory scan; RWX-then-exec Sigma | DETONATES — isolated VM, snapshot, FakeNet; loaders self-delete, dump first |

| Injection/hollowing | malfind/hollowprocesses; EID 8/10 | Vol3 hollow/ghosting/pebmasquerade; CreateRemoteThread | Capture memory pre-remediation |

| AMSI/ETW patch | amsi.dll load + patched prologue; B8 00..C3 stub | Sigma T1562.001; debug-reg+VEH for patchless | Patchless evades byte scans — watch Dr0-Dr7 |

| Fileless persistence | WMI consumers; PS 4104; Run-key blobs | Vol3 registry/wmi; Sysmon 13/22 | Lives in WMI/registry/memory — no disk file |

| Config extraction | C2 host/UA/pipe/watermark | YARA config table; Suricata on C2 URI/SNI | Offline; handle watermark/keys per ROE |

| Beacon detection | Periodic outbound deltas | beacon_profiler CV score; Suricata threshold | Passive on captured traffic |

| JA4+ fingerprint | JA4/JA4S/JA4X/JA4H tuples | Zeek ja4 watchlist (Sliver/Havoc JA4X) | JA4X needs TLS1.3 cert visibility at proxy |

| YARA-X authoring | None | The rules themselves | Validate 0-FP on goodware before deploy |

Deep Dives

  • references/static-triage-capa.md — Identity/code hashes, Rich header, entropy/packer heuristics, FLOSS, capa (PE/ELF/.NET/shellcode + dynamic capa over CAPE, Android rules, capa Explorer Web), FLARE-VM 2025.
  • references/unpacking-deobfuscation.md — Self-modifying-stub oracle, emulation (auto_unpack/unipacker/Speakeasy/Qiling), Frida DBI hooks, x64dbg→OEP→Scylla, .NET (de4dot/dnSpyEx), Latrodectus 1.4 AES strings, AsyncRAT fileless loaders, garble/pyc.
  • references/dynamic-fileless-memory.md — Sandbox build, Volatility 3 injection playbook + 2025 contest plugins (PEScan/Fileless Hunter), AMSI/ETW patch IOCs + patchless VEH bypass, WMI/registry/PS fileless persistence.
  • references/config-c2-extraction.md — Cobalt Strike (1768.py runtime config, CobaltStrikeParser XOR 0x69/0x2e), AdaptixC2 (Unit 42, 2025), MACO/configextractor-py/CAPEv2 at scale, generic unknown-C2 decoder methodology.
  • references/network-c2-detection.md — Beacon cadence/CV scoring, JA4+ suite (JA4X for randomized-cert Sliver/Havoc, Zeek/TheHive 2025-26), tunneled/DoH C2 (cloudflared/TryCloudflare/chisel), Suricata/Sigma + ransomware 2025 tradecraft.
  • references/yara-detection-engineering.md — YARA-X 1.0 (Rust, 99% compat, fmt/WASM, perf caveats), code/byte > string rules, pe/math modules, threshold logic, goodware FP validation, memory+disk scanning, capa pairing.

How to use it

Copy the folder

Take hypnguyen1209/malware-analysis from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.