Malware Dynamic Analysis

Behavioral analysis of a sample executed in an isolated VM. Use after triage when runtime behavior, C2 traffic, dropped files, persistence, or injection must be observed. Claude produces a tailored VM runbook from triage predictions, then parses the exported text evidence (Procmon CSV, Sysmon JSON/CSV, tshark output, autoruns, strings) on the host to reconstruct behavior and extract IOCs. The analyst runs the VM; Claude never executes the sample.

gl0bal01 Updated

File contents

gl0bal01/malware-analysis-claude-skills/tree/main/malware-dynamic-analysis commit fcc43668eb

Frequently asked questions

npx skillmds@latest add gl0bal01/malware-dynamic-analysis