analyzing-malware-behavior-with-cuckoo-sandbox

mukul975/analyzing-malware-behavior-with-cuckoo-sandbox · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.6 KB
  • 📁scripts
  • ⚙️agent.py 9.1 KB
  • 📄LICENSE 11.0 KB

Related

  1. performing-automated-malware-analysis-with-cape · mukul975 bundle
    Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction, configuration parsing, and anti-evasion capabilities.
    24.6k
    repo stars
  2. analyzing-malware-sandbox-evasion-techniques · mukul975 bundle
    Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports.
    24.6k
    repo stars
  3. building-automated-malware-submission-pipeline · mukul975 bundle
    Automates the collection of suspicious files from endpoints and email gateways, submission to sandbox and multi-engine scanners, and generation of verdicts with IOCs for SIEM integration.
    24.6k
    repo stars
  4. performing-memory-forensics-with-volatility3-plugins · mukul975 bundle
    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
    24.6k
    repo stars
  5. performing-malware-ioc-extraction · mukul975 bundle
    Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
    24.6k
    repo stars
  6. performing-malware-triage-with-yara · mukul975 bundle
    Rapidly classify malware samples against known family signatures using YARA rules, covering rule writing, scanning, and integration with analysis pipelines.
    24.6k
    repo stars

Frequently asked questions

How do I install the analyzing-malware-behavior-with-cuckoo-sandbox skill?

Run npx skillmds add mukul975/analyzing-malware-behavior-with-cuckoo-sandbox in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the analyzing-malware-behavior-with-cuckoo-sandbox skill do?

Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. It is listed under Security, Data & Analytics, Integrations & APIs, Data Analysis, Vulnerability Scanning on SkillMD.

Is analyzing-malware-behavior-with-cuckoo-sandbox safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with analyzing-malware-behavior-with-cuckoo-sandbox?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is analyzing-malware-behavior-with-cuckoo-sandbox free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published analyzing-malware-behavior-with-cuckoo-sandbox?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.