analyzing-malware-sandbox-evasion-techniques
Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
معلومات المصدر
- المستودع
- mukul975/Anthropic-Cybersecurity-Skills
- آخر نشاط في المصدر
- ٢ أغسطس ٢٠٢٦ في ١٦:٣٢
- لغة SKILL.md المكتشفة
- الإنجليزية
- النجوم
- ٣٣٬١٢٩
- التفرعات
- ٤٬٠١٦
خيارات التثبيت
يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.
مراجعة ملفات المصدر
اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.
عرض SKILL.md
- name
- analyzing-malware-sandbox-evasion-techniques
- description
- Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
- domain
- cybersecurity
- subdomain
- malware-analysis
- tags
- ["sandbox-evasion","malware-analysis","cuckoo","anyrun","mitre-attack","virtualization-detection","behavioral-analysis"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Platform Hardening","Restore Object","Process Analysis","System Call Filtering","Restore Software"]
- nist_csf
- ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"]
- mitre_attack
- ["T1497.001","T1497.003","T1480","T1027.002"]