Fast malware triage workflow — static (PE/Mach-O/ELF format, strings, imports, signatures, entropy/packed indicators), dynamic (sandbox with INetSim, Wireshark, Process Monitor, Procmon, time-shift), unpack (Scylla/PE-sieve), then full RE with Ghidra/IDA. Designed for ≤15 min initial verdict.
60
70%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/standard/reverser/malware-triage/SKILL.mdYou have a suspicious binary. Goal: in 15 minutes, decide CLEAN / SUSPICIOUS / MALICIOUS / NEEDS-DEEPER.
# 1. File format
file sample.bin
exiftool sample.bin # author / compile timestamp / version
# 2. Hash + reputation
sha256sum sample.bin
# Submit to: VirusTotal, MalwareBazaar, IntelX, Joe Sandbox, ANY.RUN
# Often the verdict already exists — saves you 14 minutes.
# 3. Strings — fast triage signal
strings -n 8 sample.bin | sort -u | head -100
strings -e l -n 8 sample.bin | sort -u | head -50 # wide (UTF-16) strings on Windows
# Suspicious strings to grep for:
strings sample.bin | grep -iE 'http|https|wmic|powershell|cmd.exe|temp|appdata|amsi|defender|reflectiveloader'
# 4. Format-specific: PE
peresearcher sample.exe # OR python pefile
python3 -c '
import pefile
p = pefile.PE("sample.exe")
print("Compile time:", p.FILE_HEADER.TimeDateStamp)
print("Sections:", [(s.Name.decode().rstrip("\x00"), s.SizeOfRawData, s.get_entropy()) for s in p.sections])
print("Imports:", [(e.dll.decode(), [i.name.decode() if i.name else hex(i.ordinal) for i in e.imports]) for e in p.DIRECTORY_ENTRY_IMPORT])
'
# 5. Entropy → packed?
python3 -c '
import math
data = open("sample.bin","rb").read()
counts = [data.count(bytes([b])) for b in range(256)]
total = len(data)
ent = -sum((c/total)*math.log2(c/total) for c in counts if c)
print(f"Entropy: {ent:.3f} / 8 — {'packed' if ent > 7.5 else 'normal'}")
'
# 6. YARA against canonical rulesets
yara -r /opt/yara-rules/ sample.bin
yara -r /opt/Neo23x0-signature-base/ sample.bin# Pre-flight (do this once, save snapshot)
# - Disconnected network OR use INetSim/FakeNet-NG to fake services
# - Procmon recording (Process / File / Network / Registry filters)
# - Wireshark capturing on the snapshot's network adapter
# - Fakedns / inetsim listening for DNS / HTTP / SMTP / FTP
# Detonate
cp sample.bin C:\tmp\sample.exe
# Right-click → Run as admin OR sample.exe in cmd
# Observe for 60-180 seconds, then take snapshot
# Then revert VM for next run| Signal | Verdict |
|---|---|
Writes to \AppData\Local\Temp then executes | Likely dropper |
| Creates Run/RunOnce registry key | Persistence |
| Schedules a task | Persistence |
| Modifies firewall via netsh | Defense evasion |
| Spawns powershell + LongStringEncoded | Stage 2 |
| Network: HTTPS to a no-SNI IP | C2 callback |
| DNS to a DGA-looking domain | C2 callback |
| Reads process memory of lsass.exe / winlogon.exe | Credential theft |
| Writes to userinit / shells / image-file-exec-options | Persistence |
Touches \Microsoft\Cryptography\Defaults\Provider | Cert injection |
# In dynamic VM, after detonation, dump memory:
# Scylla (UI) → attach to process, dump PE image
# OR PE-sieve (command-line):
pe-sieve.exe /pid 1234 /dir dumped
# OR DnSpy + DotNetReactorUnpacker for .NET
# OR de4dot for obfuscated .NET
# Then static-re the unpacked binary (Phase 1 strings/imports against the dump)| Verdict | Indicators | Next step |
|---|---|---|
| CLEAN | Known-good hash, signed, expected strings/imports, no suspicious behavior | Mark + move on |
| SUSPICIOUS | Unsigned, low rep, mildly unusual imports/strings, no clear malicious behavior | Sandbox 30 min longer, YARA against custom rules |
| MALICIOUS | C2 callback, drops files, persistence, credential theft, packed + evades VMs | IOC extraction, then deep RE (load reverser/ghidra/SKILL.md) |
| NEEDS-DEEPER | High entropy, anti-analysis, custom-packed, no obvious signal | Unpack first (Phase 3), then re-triage |
If MALICIOUS:
| Stage | Tool | Use |
|---|---|---|
| Static (PE) | pefile, capa, exiftool, Detect It Easy (DIE) | Format + capability scan |
| Static (ELF) | readelf, objdump, radare2 | Format + symbols |
| Static (Mach-O) | jtool2, otool, MachOView | Format + symbols |
| Dynamic | Cuckoo, CAPE, ANY.RUN, Joe Sandbox, Hatching Triage | Automated sandbox |
| Network | Wireshark, mitmproxy, FakeNet-NG, INetSim | Traffic capture + fake services |
| Memory | Volatility 3, PE-sieve, Scylla | Memory forensics + unpacking |
| Disassembly | Ghidra, IDA, Binary Ninja | Full RE — see reverser/ghidra/SKILL.md |
| YARA | yara, capa rules | Signature matching |
e34afba
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.