| name | extracting-iocs-from-malware-samples |
| description | Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples. . Use when working with extracting iocs from malware samples. |
| domain | cybersecurity |
| tags | ["malware","IOC-extraction","threat-intelligence","indicators","detection"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Extracting Iocs From Malware Samples
Overview
Cybersecurity skill for extracting iocs from malware samples. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"extracting iocs from malware samples"
-
"Extracts indicators of compromise (IOCs) from malware samples including file has"
-
A malware analysis (static or dynamic) is complete and actionable indicators need to be extracted for defense teams
-
Building blocklists for firewalls, proxies, and DNS sinkholes from analyzed samples
-
Creating YARA rules, Snort/Suricata signatures, or SIEM detection content from malware artifacts
-
Contributing to threat intelligence sharing platforms (MISP, OTX, ThreatConnect)
-
Tracking malware campaigns by correlating IOCs across multiple samples
Do not use for IOCs from unverified sources without validation; false positives in blocklists can disrupt legitimate business operations.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Python 3.8+ with
iocextract, pefile, yara-python libraries installed
- Completed malware analysis report (static analysis, dynamic analysis, or reverse engineering)
- Access to PCAP files, memory dumps, or sandbox reports from the analysis
- MISP instance or STIX/TAXII server for structured IOC sharing
- VirusTotal API key for IOC enrichment and validation
- CyberChef for decoding obfuscated indicators
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}