analyzing-malware-sandbox-evasion-techniques
Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
ソース情報
- リポジトリ
- mukul975/Anthropic-Cybersecurity-Skills
- ソースの最終更新活動
- 2026年8月2日 16:32
- 検出された SKILL.md の言語
- 英語
- スター
- 33,129
- フォーク
- 4,016
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
SKILL.md を表示中
- name
- analyzing-malware-sandbox-evasion-techniques
- description
- Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques.
- domain
- cybersecurity
- subdomain
- malware-analysis
- tags
- ["sandbox-evasion","malware-analysis","cuckoo","anyrun","mitre-attack","virtualization-detection","behavioral-analysis"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- d3fend_techniques
- ["Platform Hardening","Restore Object","Process Analysis","System Call Filtering","Restore Software"]
- nist_csf
- ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"]
- mitre_attack
- ["T1497.001","T1497.003","T1480","T1027.002"]