Skip to main content
在 Manus 中运行任何 Skill
一键导入

malware-analysis

星标2
分支0
更新时间2026年4月22日 03:07

Analyze suspicious files, executables, and samples for malicious behavior using the Practical Malware Analysis methodology (Sikorski & Honig), orchestrated through the REMnux MCP server. Use whenever the user asks to triage, reverse-engineer, analyze, investigate, unpack, or figure out what a binary does — PE (.exe/.dll/.sys), ELF, Mach-O, script, Office doc, PDF, archive, or raw shellcode. Covers the full four-layer methodology — basic static (hashes, strings, PE/ELF headers, imports, packing), basic dynamic (sandbox/Procmon/FakeNet), advanced static (Ghidra/IDA disassembly), and advanced dynamic (x64dbg debugging, unpacking, anti-analysis bypass). Produces IOC extraction, MITRE ATT&CK TTP mapping, host- and network-based detections, and analyst reports with STIX 2.1 output for OpenCTI ingestion. Trigger even for low-signal phrasings like 'what is this file', 'is this malicious', 'I got this dropper', or 'pulled this off a workstation'.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly