本文へ移動
cccskills
無料GitHub で公開

malware-reverse-engineering

Malware reverse engineering and suspicious artifact analysis skill for defensive triage, static analysis, dynamic analysis planning, unpacking strategy, indicators of compromise, behavior summaries, YARA/Sigma ideas, and remediation guidance. Use for suspicious binaries, scripts, documents, logs, memory artifacts, sandbox reports, and malware family analysis in isolated environments.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md1.7 KB
  • agents/openai.yaml232 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Malware Reverse Engineering

Safety Boundary

  • Treat samples as hostile. Use isolated labs, snapshots, no shared clipboard, no mounted personal directories, and controlled networking.
  • Do not provide malware improvement, persistence, stealth, evasion, credential theft, or deployment guidance.
  • Focus on behavior, indicators, detection, containment, and eradication.

Workflow

  1. Record sample metadata: filename, hashes, size, type, source, timestamp, and handling notes.
  2. Perform static triage: strings, imports, sections, packer hints, scripts/macros, config blobs, and suspicious capabilities.
  3. Plan dynamic analysis with containment: VM snapshot, fake services, monitored filesystem/registry/process/network activity.
  4. Summarize behavior by capability: execution, persistence, privilege, defense evasion, discovery, C2, collection, exfiltration.
  5. Produce IOCs, detection logic ideas, remediation steps, and confidence levels.

Output Format

  • Summary: what the artifact appears to do.
  • Evidence: strings, APIs, paths, domains, mutexes, commands, or observed events.
  • IOCs: hashes, filenames, registry keys, network indicators, and caveats.
  • Detections: YARA/Sigma/EDR hunting ideas where appropriate.
  • Response: containment, eradication, recovery, and monitoring.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

AI and LLM red-teaming skill for evaluating prompt injection, jailbreak, data exfiltration, tool abuse, agent hijack, RAG poisoning, model denial of service, and unsafe tool-use chains in Gemini, Claude, GPT, and open-weight models. Use to build evaluation harnesses, attack corpora, defensive guardrails, and red-team reports for AI systems you own or are authorized to test.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

API security automation skill for REST, GraphQL, gRPC, and WebSocket APIs. Covers OpenAPI/AsyncAPI ingestion, authenticated fuzzing, OWASP API Top 10 (BOLA, BFLA, mass assignment, SSRF), schema diffing, GraphQL introspection abuse, JWT and OAuth misuse, rate-limit and replay testing. Use to automate API assessments with safe, scoped, evidence-backed findings.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assembly programming and low-level debugging skill for reading, writing, explaining, optimizing, and reviewing assembly across x86, x86-64, ARM, AArch64, RISC-V, calling conventions, ABI boundaries, inline assembly, disassembly, stack frames, registers, and binary-level behavior. Use for .s/.asm files, compiler output, reverse-engineering snippets, low-level performance, and crash analysis.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Bug bounty workflow skill for program scope mapping, recon-to-report automation, deduplication against prior submissions, and high-signal reporting on HackerOne, Bugcrowd, Intigriti, YesWeHack, and self-hosted programs. Use to organize bounty work end to end while staying inside program rules.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assistant-behavior design skill for approximating a Claude-like analytical, careful, conversational style without claiming to be Claude or Anthropic. Use when the user asks to duplicate, emulate, adapt, or recreate a Claude-style "mythos" or persona for prompts, agent specs, writing style, reasoning discipline, safety posture, or UX behavior.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Cloud security posture skill for AWS, Azure, GCP, and multi-cloud. Covers IAM least-privilege, key and secret hygiene, network exposure, data protection, logging coverage, IaC scanning (Terraform, CloudFormation, Bicep, Pulumi), CSPM remediation, and landing-zone hardening. Use for misconfig discovery, IaC review, and automated drift-and-fix workflows on cloud accounts you own.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Garyson26 のスキルをすべて見る

このスキルの問題を報告する