# Perform Static Malware Analysis

> Analyze a suspicious artifact without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or payloads when metadata, signatures, imports, strings, resources, and obfuscation need inspection.

- Skill: `gaelic-ghost/perform-static-malware-analysis` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add gaelic-ghost/perform-static-malware-analysis`
- Raw SKILL.md: https://api.skillmd.com/api/skills/gaelic-ghost/perform-static-malware-analysis/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: gaelic-ghost (https://skillmd.com/u/gaelic-ghost)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/gaelic-ghost/perform-static-malware-analysis

---


# Perform Static Malware Analysis

## Overview

Build a capability hypothesis from preserved bytes and structure. Keep every source-level or behavioral claim bounded by what static evidence can actually prove.

Read [references/static-analysis-layers.md](references/static-analysis-layers.md) for layered checks and escalation criteria.

## Workflow

1. Establish artifact identity and working copy.
2. Inspect outer structure.
   - Identify formats, architectures, bundles, packages, sections, members, overlays, embedded resources, signatures, timestamps, and declared permissions.
3. Extract low-risk indicators.
   - Collect imports/exports, linked libraries, symbols, strings, URLs/domains, paths, commands, mutex/service names, configuration, certificates, and persistence references.
4. Inspect code and content shape.
   - Identify interpreters, entry points, packers/obfuscation, encrypted blobs, staged payloads, anti-analysis checks, and unusual executable mappings.
   - Use YARA-X or other local rules as evidence with rule/version recorded.
5. Form capability hypotheses.
   - Map evidence to possible execution, persistence, discovery, credential, collection, command-and-control, exfiltration, or defense-evasion behavior.
   - Separate present code from reachable behavior and capability from observed execution.
6. Escalate deliberately.
   - Use `reverse-engineering-skills` for control flow, decompilation, protocol/config recovery, or exact binary comparisons.
   - Use dynamic analysis only after isolation selection and a clear observation plan.

## Output

Return identity, structure, indicators, likely capabilities, contradictory evidence, obfuscation/coverage limits, confidence, and the smallest next analysis step.

