1---2name: malware-reverse-engineering3description: Malware reverse engineering and suspicious artifact analysis skill for defensive triage, static analysis, dynamic analysis planning, unpacking strategy, indicators of compromise, behavior summaries, YARA/Sigma ideas, and remediation guidance. Use for suspicious binaries, scripts, documents, logs, memory artifacts, sandbox reports, and malware family analysis in isolated environments.4---56# Malware Reverse Engineering78## Safety Boundary910- Treat samples as hostile. Use isolated labs, snapshots, no shared clipboard, no mounted personal directories, and controlled networking.11- Do not provide malware improvement, persistence, stealth, evasion, credential theft, or deployment guidance.12- Focus on behavior, indicators, detection, containment, and eradication.1314## Workflow15161. Record sample metadata: filename, hashes, size, type, source, timestamp, and handling notes.172. Perform static triage: strings, imports, sections, packer hints, scripts/macros, config blobs, and suspicious capabilities.183. Plan dynamic analysis with containment: VM snapshot, fake services, monitored filesystem/registry/process/network activity.194. Summarize behavior by capability: execution, persistence, privilege, defense evasion, discovery, C2, collection, exfiltration.205. Produce IOCs, detection logic ideas, remediation steps, and confidence levels.2122## Output Format2324- `Summary`: what the artifact appears to do.25- `Evidence`: strings, APIs, paths, domains, mutexes, commands, or observed events.26- `IOCs`: hashes, filenames, registry keys, network indicators, and caveats.27- `Detections`: YARA/Sigma/EDR hunting ideas where appropriate.28- `Response`: containment, eradication, recovery, and monitoring.29