---
name: perform-static-malware-analysis
description: Analyze a suspicious artifact for capabilities without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or embedded payloads when metadata, signatures, imports, strings, resources, configuration, rules, obfuscation, and likely behavior must be inspected and deep binary work may hand off to reverse-engineering-skills.
---

# Perform Static Malware Analysis

## Overview

Build a capability hypothesis from preserved bytes and structure. Keep every source-level or behavioral claim bounded by what static evidence can actually prove.

Read [references/static-analysis-layers.md](references/static-analysis-layers.md) for layered checks and escalation criteria.

## Workflow

1. Establish artifact identity and working copy.
2. Inspect outer structure.
   - Identify formats, architectures, bundles, packages, sections, members, overlays, embedded resources, signatures, timestamps, and declared permissions.
3. Extract low-risk indicators.
   - Collect imports/exports, linked libraries, symbols, strings, URLs/domains, paths, commands, mutex/service names, configuration, certificates, and persistence references.
4. Inspect code and content shape.
   - Identify interpreters, entry points, packers/obfuscation, encrypted blobs, staged payloads, anti-analysis checks, and unusual executable mappings.
   - Use YARA-X or other local rules as evidence with rule/version recorded.
5. Form capability hypotheses.
   - Map evidence to possible execution, persistence, discovery, credential, collection, command-and-control, exfiltration, or defense-evasion behavior.
   - Separate present code from reachable behavior and capability from observed execution.
6. Escalate deliberately.
   - Use `reverse-engineering-skills` for control flow, decompilation, protocol/config recovery, or exact binary comparisons.
   - Use dynamic analysis only after isolation selection and a clear observation plan.

## Output

Return identity, structure, indicators, likely capabilities, contradictory evidence, obfuscation/coverage limits, confidence, and the smallest next analysis step.
