analyzing-malware-sandbox-evasion-techniques
Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
Informations de source
- Dépôt
- mukul975/Anthropic-Cybersecurity-Skills
- Dernière activité de la source
- 2 août 2026 à 16:32
- Langue détectée de SKILL.md
- anglais
- Étoiles
- 33 129
- Forks
- 4 016
Options d'installation
Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.
Vérifiez les fichiers source
Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.
Affichage de SKILL.md
- name
- analyzing-malware-sandbox-evasion-techniques
- description
- Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
- domain
- cybersecurity
- subdomain
- malware-analysis
- tags
- ["sandbox-evasion","malware-analysis","cuckoo","anyrun","mitre-attack","virtualization-detection","behavioral-analysis"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Platform Hardening","Restore Object","Process Analysis","System Call Filtering","Restore Software"]
- nist_csf
- ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"]
- mitre_attack
- ["T1497.001","T1497.003","T1480","T1027.002"]