Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Malware Analysis › Page 3

Malware Analysis (Page 3 of 3)

175 Claude Code skills in the Malware Analysis sub-category of Security.

175 skills · updated 2026-07-27 · showing 121–175 of 175 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Windows persistence mechanism scanner. Scans all autorun vectors: Registry Run/RunOnce keys (T1547.001), Startup folders (T1547.004), Scheduled Tasks (T1053.005), and WMI Event…
Banking-App-Malware (Anubis, Cerberus, BRATA): Trojaner uebernimmt App und pushTAN, Overlay-Attacke. Forensische Hinweise: ungewoehnliche App-Berechtigungen, beobachtete SMS.
Scan a project or machine for the PolinRider DPRK/Lazarus supply-chain malware (March–April 2026 npm + VS Code campaign).
Proje kapanışında lessons learned oturumu, sprint sonu retrospektifi veya incident sonrası postmortem kolaylaştırır.
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
Rakiplerin içeriklerini (Instagram, TikTok) ve reklam stratejilerini (Meta Ads vb.) analiz ederek içerik boşluklarını (content gap) bulmaya yarayan araştırma motoru.
Prüft Ransomware-Entscheidungen und Grenzen von Zahlungen im Nis2 Cybersecurity Compliance.
Meta-Skill für die komplette Roblox-Spieleentwicklung mit Rojo — der Einstiegspunkt, der die drei Spezialskills `/rojo` (Filesystem→Studio-Sync, Projekt-Setup), `/rbx-stu — from…
Bedienung von Roblox Studio für die Spieleentwicklung — der visuelle Editor, in dem die 3D-Szene gebaut, getestet und veröffentlicht wird.
Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment
Detailed reverse-engineering pack for binaries, loaders, anti-analysis, deobfuscation, and exploitability clues.
Statically scan a public GitHub repo for supply-chain malware BEFORE an agent installs or runs it (a dependency, a Claude/MCP skill, an MCP server).
Report suspicious or malicious URLs discovered during web exploration. Trigger proactively when: encountering phishing, malware, scam sites, suspicious redirects, or data…
Analyze and guide security incident response, investigation, and remediation processes. Use when you need to handle security breaches, classify incidents, develop response…
Pipeline automatica di reverse engineering per APK Android (Flutter e nativi). Fa preflight dei tool, scarica l'app dal device con adb, rileva se è Flutter o nativa, lancia il…
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify
Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated
Führt die Risikobewertung eines Datenschutzvorfalls anhand der EDSA-Leitlinie 9/2022 zu Beispielen für die Meldung von Datenschutzverletzungen durch.
Interprets rl-protect JSON reports (rl-protect.report.json). Use when the user asks about vulnerabilities, malware, indicators, policy violations, overrides, governance,…
Meta-Skill für die komplette Roblox-Spieleentwicklung mit Rojo — der Einstiegspunkt, der die drei Spezialskills `/rojo` (Filesystem→Studio-Sync, Projekt-Setup), `/roblox- — from…
Bedienung von Roblox Studio für die Spieleentwicklung — der visuelle Editor, in dem die 3D-Szene gebaut, getestet und veröffentlicht wird.
Apply Florian Roth's detection engineering methodology with YARA and Sigma rules. Emphasizes portable detection logic, community sharing, and signature quality.
Give agents a routing pack for authorized APK, binary, mobile, API, malware, CTF, and penetration-test analysis with tool checks and case structure.
Sade hukuk dili: karmaşık dilekçe, karar ve sözleşmeleri müvekkilin anlayacağı yalın Türkçeye çevirme; hukuki doğruluğu koruyarak özetleme, terim açıklama ve bilgilendirme metni…
Retrieve active cyber-threat intelligence — malware IOCs, C2 infrastructure, and CISA known-exploited vulnerabilities — filterable by type, source, and severity.
Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning.
Use SafeDep Vet as a pre-adoption gate when an agent, maintainer, or CI pipeline is about to add a new dependency or import a skill repository and needs malware and policy signals…
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage…
Document security research, CTF solutions, and malware analysis. Includes REPORT.md and STATUS.md templates.
Launch a Windows background process (.bat, node, python, .exe) with no visible console window — no black console flash on login or restart.
Security-audit Agent Skills and plugins — vet a new skill before installing it, scan everything already installed on this machine, or harden your own skill before publishing.
Extracts implementation-agnostic feature specs from working prototypes with SDLC guardrails. Use when handing off a prototype to an engineering team, reverse-engineering prototype…
Liefert eine schnelle Übersicht über häufige Spezialfälle eines Datenschutzvorfalls und verweist auf vertiefte Skills.
Behavioural-first software supply chain defense - catches poisoned npm/PyPI packages in the publish-to-advisory window that CVE tools miss.
Analysis of how suppressing volatility creates fragile systems vulnerable to black swan events
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,
Maintain THOR installs using thor-util: update signatures, upgrade versions, download offline packs, generate reports, manage YARA-Forge.
Triage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts,…
Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it.
Submit URLs for automated malware and phishing analysis, then retrieve safety verdicts and screenshots via urlscan.io
Cyberversicherung bei Ransomware: Deckung, Lösegeld, Forensik, DSGVO-Meldung, DORA/NIS2 und Sanktionsrecht: Cyberversicherung bei Ransomware: Deckung, Lösegeld, Forensik,…
Detection Engineering agent. Designs Sigma/YARA rules, maps detection coverage, designs threat hunting hypotheses, executes Purple Team Blue side, and integrates Detection-as-Code…
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules.
Use this skill when selecting or applying Arabic NLP, tokenization, stemming, diacritization, morphological analysis, stopword, OCR, speech, or language-model tools including…
Use this skill when the user says 'backup', 'disaster recovery', 'DR', 'RPO', 'RTO', 'backup strategy', '3-2-1 rule', 'business continuity', 'disaster recovery plan', 'failover',…
Foundational cybersecurity literacy covering threat landscape (malware, phishing, social engineering, network attacks), defensive practices (encryption, authentication, access…
This skill should be used when the user asks to 'buy BTC', 'sell ETH', 'place a limit order', 'place a market order', 'cancel my order', 'amend my order', 'long BTC perp', 'short…
Use this skill when working with Checkpoint Harmony Email security policies - DLP policies, anti-phishing rules, anti-malware settings, quarantine policies, allow/block lists, and…
Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavior, credential leaks,…
Use this skill when working with Abnormal Security threat detection and analysis - BEC, phishing, malware, socially-engineered attacks, spam, graymail, and credential theft.
CTF 综合解题编排器。当面对未知类型的 CTF 挑战、需要自动分析挑战类型并选择正确解题路径时使用。自动调度对应的专项 skill(pwn/crypto/web/reverse/forensics/osint/malware/misc),适合给定挑战文件或服务端点但不确定属于哪个类别的场景
Test skill containing EICAR test file for malware detection
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Threat Hunting (588) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Forensics (200) · Compliance (191) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)