extracting-iocs-from-malware-samples

mukul975/extracting-iocs-from-malware-samples · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Extracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators, host artifacts, and behavioral patterns for threat intelligence sharing and detection rule creation.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.6 KB
  • 📁scripts
  • ⚙️agent.py 10.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. performing-malware-ioc-extraction · mukul975 bundle
    Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
    24.6k
    repo stars
  2. building-automated-malware-submission-pipeline · mukul975 bundle
    Automates the collection of suspicious files from endpoints and email gateways, submission to sandbox and multi-engine scanners, and generation of verdicts with IOCs for SIEM integration.
    24.6k
    repo stars
  3. collecting-indicators-of-compromise · mukul975 bundle
    Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.
    24.6k
    repo stars
  4. analyzing-command-and-control-communication · mukul975 bundle
    Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure for detection development and threat intelligence.
    24.6k
    repo stars
  5. malware-analysis · zhaoxuya520 bundle
    Analyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
    12.8k
    repo stars
  6. analyzing-malicious-url-with-urlscan · mukul975 bundle
    Investigate phishing URLs, credential harvesting pages, and malicious redirects using URLScan.io's safe browsing environment and API.
    24.6k
    repo stars

Frequently asked questions

How do I install the extracting-iocs-from-malware-samples skill?

Run npx skillmds add mukul975/extracting-iocs-from-malware-samples in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the extracting-iocs-from-malware-samples skill do?

Extracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators, host artifacts, and behavioral patterns for threat intelligence sharing and detection rule creation. It is listed under Security, Incident Response on SkillMD.

Is extracting-iocs-from-malware-samples safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with extracting-iocs-from-malware-samples?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is extracting-iocs-from-malware-samples free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published extracting-iocs-from-malware-samples?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.