| name | analyzing-malware-behavior-with-cuckoo-sandbox |
| description | Use when executing malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution. |
| domain | cybersecurity |
| tags | ["malware","dynamic-analysis","sandbox","Cuckoo","behavioral-analysis"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Analyzing Malware Behavior With Cuckoo Sandbox
Overview
Cybersecurity skill for analyzing malware behavior with cuckoo sandbox. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing malware behavior with cuckoo sandbox"
-
"Executes malware samples in Cuckoo Sandbox to observe runtime behavior including"
-
A suspicious sample passed static analysis triage and requires behavioral observation in a controlled environment
-
You need to capture network traffic, file drops, registry modifications, and API calls from a malware execution
-
Determining the full infection chain including second-stage payload downloads and persistence mechanisms
-
Generating behavioral signatures and YARA rules based on observed runtime activity
-
Automated analysis of bulk malware samples requiring consistent reporting
Do not use when the sample is a known ransomware variant that may spread via network shares in a misconfigured sandbox; verify network isolation first.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Cuckoo Sandbox 3.x installed on a dedicated analysis server (Ubuntu 22.04 recommended)
- Guest VMs configured with Windows 10/11 snapshots (Cuckoo agent installed, snapshots taken at clean state)
- VirtualBox, KVM, or VMware configured as the Cuckoo virtualization backend
- Isolated network with InetSim or FakeNet-NG for simulating internet services
- Suricata or Snort integrated for network-level signature matching during analysis
- Sufficient disk space for PCAP captures and memory dumps (minimum 500 GB recommended)
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}