Skill v1.0.1
currentAutomated scan94/100+15 new
version: "1.0.1" name: malware-analysis description: Use when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction (Cobalt Strike/CAPE), C2 traffic detection (JA4+, beaconing) metadata: type: defensive phase: analysis tools: capa, FLOSS, YARA-X, pefile, x64dbg, dnSpyEx, de4dot, Frida, Qiling, Speakeasy, unipacker, Volatility3, FakeNet-NG, INetSim, 1768.py, CobaltStrikeParser, MACO, CAPEv2, Zeek, ja4, Suricata mitre: TA0042 kill_chain: phase: [weaponize] step: [2] attck_tactics: [TA0042, TA0005, TA0011] attck_techniques: [T1027, T1027.002, T1027.013, T1140, T1055, T1055.012, T1620, T1562.001, T1497, T1547.001, T1546.003, T1059.001, T1071.001, T1071.004, T1573, T1572, T1568.002, T1480] depends_on: [reverse-engineering] feeds_into: [threat-hunting, incident-response, edr-evasion, network-attack] inputs: [malware_sample, memory_image, pcap_capture, sandbox_report] outputs: [yara_rules, ioc_list, behavioral_report, malware_config, capability_map, c2_indicators] references:
- references/static-triage-capa.md
- references/unpacking-deobfuscation.md
- references/dynamic-fileless-memory.md
- references/config-c2-extraction.md
- references/network-c2-detection.md
- references/yara-detection-engineering.md
scripts:
- scripts/triage.py
- scripts/auto_unpack.py
- scripts/frida_unpack.js
- scripts/cs_config_extract.py
- scripts/mem_triage.py
- scripts/beacon_profiler.py
- scripts/yara_gen.py
Malware Analysis
When to Activate
- Triaging an unknown binary/script: identity, packing verdict, capability map, IOCs, go/no-go for detonation.
- Recovering the real payload from a packed/crypted/obfuscated loader (commodity loaders, RAT chains, .NET).
- Detonating safely and recovering fileless / in-memory artifacts (injection, AMSI/ETW patching, WMI persistence).
- Extracting malware configuration (C2, keys, sleep/jitter, campaign IDs) for threat intel and detection.
- Detecting/characterizing C2 on the wire (beacon cadence, JA4+ fingerprints, tunneled/DoH channels).
- Writing durable, low-FP YARA-X detection from analysis findings; incident-response scoping.
Technique Map
| Technique | ATT&CK | CWE | Reference | Script | |
|---|---|---|---|---|---|
| Hash/imphash/Rich/ssdeep/TLSH triage + PE anomalies | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | |
| Per-section entropy + packer/RWX/EP heuristics | T1027.002 | CWE-1066 | references/static-triage-capa.md | scripts/triage.py | |
| Obfuscated string recovery (FLOSS) | T1140, T1027.013 | CWE-656 | references/static-triage-capa.md | scripts/triage.py | |
| Capability detection → ATT&CK (capa, static+dynamic) | T1027 | CWE-506 | references/static-triage-capa.md | scripts/triage.py | |
| Emulation unpacking (Unicorn/unipacker/Speakeasy/Qiling) | T1140, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/auto_unpack.py | |
| DBI unpacking via API hooks (Frida) | T1055, T1620 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js | |
| .NET deobfuscation/unpacking (de4dot/dnSpyEx) | T1027, T1140 | CWE-656 | references/unpacking-deobfuscation.md | scripts/frida_unpack.js | |
| Sandbox detonation + behavioral capture | T1497 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | |
| Memory injection/hollowing/ghosting analysis (Vol3) | T1055, T1055.012 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | |
| AMSI/ETW in-memory patch + patchless detection | T1562.001 | CWE-693 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | |
| Fileless WMI/registry/PowerShell persistence | T1546.003, T1547.001, T1059.001 | CWE-506 | references/dynamic-fileless-memory.md | scripts/mem_triage.py | |
| Cobalt Strike / AdaptixC2 config extraction | T1071.001, T1573 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py | |
| Config framework at scale (MACO/CAPE) | T1071.001 | CWE-798 | references/config-c2-extraction.md | scripts/cs_config_extract.py | |
| Generic unknown-C2 protocol RE + decoder | T1573, T1071.004 | CWE-311 | references/config-c2-extraction.md | scripts/cs_config_extract.py | |
| Beacon cadence/jitter detection (PCAP/Zeek) | T1071.001, T1029 | CWE-778 | references/network-c2-detection.md | scripts/beacon_profiler.py | |
| JA4+ TLS/HTTP/cert fingerprinting (Sliver/Havoc JA4X) | T1071.001, T1573 | CWE-295 | references/network-c2-detection.md | scripts/beacon_profiler.py | |
| Tunneled/DoH C2 surfacing (cloudflared/chisel) | T1572, T1568.002, T1071.004 | CWE-441 | references/network-c2-detection.md | scripts/beacon_profiler.py | |
| YARA-X family rule authoring + FP validation | T1027 | CWE-506 | references/yara-detection-engineering.md | scripts/yara_gen.py |
Quick Start
# 1. Static triage: hashes + PE anomalies + capability combos + FLOSS/capa/YARA-Xpython3 scripts/triage.py sample.exe --floss --capa --yara rules/family.yar --json out/triage.jsoncapa -j sample.exe > out/capa.json # capabilities -> ATT&CK# 2. Unpack (try emulation first; DBI fallback in isolated VM)python3 scripts/auto_unpack.py sample.exe -o out/dumps/ # static emulation, no detonationfrida -f C:\sample.exe -l scripts/frida_unpack.js --no-pause # DBI, isolated VM onlyde4dot sample.exe -o cleaned.exe # .NET layer# 3. Dynamic + memory (capture mem BEFORE remediation)python3 scripts/mem_triage.py -f mem.raw --vol vol --patch-hunt --json out/mem.json# 4. Config + C2 extractionpython3 scripts/cs_config_extract.py beacon.bin --json # Cobalt Strikepython3 1768.py -S beacon.bin # full CS incl. runtime/heap configconfigextractor sample.bin # MACO/MWCP/CAPE at scale# 5. Network C2 detectionpython3 scripts/beacon_profiler.py capture.pcap --min-beacons 6 # cadence/jitterzeek -r capture.pcap LOCAL ja4 && zeek-cut ja4 ja4s ja4x < ja4.log # JA4+ pivots# 6. Detection engineeringpython3 scripts/yara_gen.py --family samples/fam/ --name Fam --goodware /usr/bin --out rules/fam.yaryara-x fmt rules/fam.yar && yara-x scan rules/fam.yar /corpus/
OPSEC & Detection (summary)
| Technique | Telemetry/IOC | Detection (Sigma/EDR) | OPSEC note | |
|---|---|---|---|---|
| Static triage | None (offline) | n/a — feeds YARA/imphash hunting | Read-only, no execution; isolate sample dir | |
| Emulation unpack | None (no detonation) | n/a | Preferred first pass; safe, no network | |
| DBI/manual unpack | Sysmon 8/10 (CallTrace UNKNOWN), RWX commit | EDR memory scan; RWX-then-exec Sigma | DETONATES — isolated VM, snapshot, FakeNet; loaders self-delete, dump first | |
| Injection/hollowing | malfind/hollowprocesses; EID 8/10 | Vol3 hollow/ghosting/pebmasquerade; CreateRemoteThread | Capture memory pre-remediation | |
| AMSI/ETW patch | amsi.dll load + patched prologue; B8 00..C3 stub | Sigma T1562.001; debug-reg+VEH for patchless | Patchless evades byte scans — watch Dr0-Dr7 | |
| Fileless persistence | WMI consumers; PS 4104; Run-key blobs | Vol3 registry/wmi; Sysmon 13/22 | Lives in WMI/registry/memory — no disk file | |
| Config extraction | C2 host/UA/pipe/watermark | YARA config table; Suricata on C2 URI/SNI | Offline; handle watermark/keys per ROE | |
| Beacon detection | Periodic outbound deltas | beacon_profiler CV score; Suricata threshold | Passive on captured traffic | |
| JA4+ fingerprint | JA4/JA4S/JA4X/JA4H tuples | Zeek ja4 watchlist (Sliver/Havoc JA4X) | JA4X needs TLS1.3 cert visibility at proxy | |
| YARA-X authoring | None | The rules themselves | Validate 0-FP on goodware before deploy |
Deep Dives
- references/static-triage-capa.md — Identity/code hashes, Rich header, entropy/packer heuristics, FLOSS, capa (PE/ELF/.NET/shellcode + dynamic capa over CAPE, Android rules, capa Explorer Web), FLARE-VM 2025.
- references/unpacking-deobfuscation.md — Self-modifying-stub oracle, emulation (auto_unpack/unipacker/Speakeasy/Qiling), Frida DBI hooks, x64dbg→OEP→Scylla, .NET (de4dot/dnSpyEx), Latrodectus 1.4 AES strings, AsyncRAT fileless loaders, garble/pyc.
- references/dynamic-fileless-memory.md — Sandbox build, Volatility 3 injection playbook + 2025 contest plugins (PEScan/Fileless Hunter), AMSI/ETW patch IOCs + patchless VEH bypass, WMI/registry/PS fileless persistence.
- references/config-c2-extraction.md — Cobalt Strike (1768.py runtime config, CobaltStrikeParser XOR 0x69/0x2e), AdaptixC2 (Unit 42, 2025), MACO/configextractor-py/CAPEv2 at scale, generic unknown-C2 decoder methodology.
- references/network-c2-detection.md — Beacon cadence/CV scoring, JA4+ suite (JA4X for randomized-cert Sliver/Havoc, Zeek/TheHive 2025-26), tunneled/DoH C2 (cloudflared/TryCloudflare/chisel), Suricata/Sigma + ransomware 2025 tradecraft.
- references/yara-detection-engineering.md — YARA-X 1.0 (Rust, 99% compat, fmt/WASM, perf caveats), code/byte > string rules, pe/math modules, threshold logic, goodware FP validation, memory+disk scanning, capa pairing.