Extracting Iocs From Malware Samples
Overview
Cybersecurity skill for extracting iocs from malware samples. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"extracting iocs from malware samples"
"Extracts indicators of compromise (IOCs) from malware samples including file has"
A malware analysis (static or dynamic) is complete and actionable indicators need to be extracted for defense teams
Building blocklists for firewalls, proxies, and DNS sinkholes from analyzed samples
Creating YARA rules, Snort/Suricata signatures, or SIEM detection content from malware artifacts
Contributing to threat intelligence sharing platforms (MISP, OTX, ThreatConnect)
Tracking malware campaigns by correlating IOCs across multiple samples
Do not use for IOCs from unverified sources without validation; false positives in blocklists can disrupt legitimate business operations.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Python 3.8+ with
iocextract, pefile, yara-python libraries installed
- Completed malware analysis report (static analysis, dynamic analysis, or reverse engineering)
- Access to PCAP files, memory dumps, or sandbox reports from the analysis
- MISP instance or STIX/TAXII server for structured IOC sharing
- VirusTotal API key for IOC enrichment and validation
- CyberChef for decoding obfuscated indicators
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for iocs from malware samples.
- Gather Resources — Collect tools, data, and access needed for iocs from malware samples.
- Execute Process — Carry out iocs from malware samples operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: extracting-iocs-from-malware-samples3description: Use when extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples. . Use when working with extracting iocs from malware samples.4license: Apache-2.05---67# Extracting Iocs From Malware Samples89## Overview1011Cybersecurity skill for extracting iocs from malware samples. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "extracting iocs from malware samples"16- "Extracts indicators of compromise (IOCs) from malware samples including file has"171819- A malware analysis (static or dynamic) is complete and actionable indicators need to be extracted for defense teams20- Building blocklists for firewalls, proxies, and DNS sinkholes from analyzed samples21- Creating YARA rules, Snort/Suricata signatures, or SIEM detection content from malware artifacts22- Contributing to threat intelligence sharing platforms (MISP, OTX, ThreatConnect)23- Tracking malware campaigns by correlating IOCs across multiple samples2425**Do not use** for IOCs from unverified sources without validation; false positives in blocklists can disrupt legitimate business operations.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Python 3.8+ with `iocextract`, `pefile`, `yara-python` libraries installed38- Completed malware analysis report (static analysis, dynamic analysis, or reverse engineering)39- Access to PCAP files, memory dumps, or sandbox reports from the analysis40- MISP instance or STIX/TAXII server for structured IOC sharing41- VirusTotal API key for IOC enrichment and validation42- CyberChef for decoding obfuscated indicators4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Objectives** — Clarify the goals and scope for iocs from malware samples.622. **Gather Resources** — Collect tools, data, and access needed for iocs from malware samples.633. **Execute Process** — Carry out iocs from malware samples operations methodically.644. **Verify Quality** — Check results against acceptance criteria.655. **Document Outcomes** — Record findings, decisions, and next steps.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Reconnaissance** — Gather target information, identify attack surface, enumerate services761. **Analysis/Exploitation** — Execute the technique, analyze results, document findings771. **Reporting** — Document IOCs, write findings, provide remediation recommendations7879## Verification8081- [ ] All iocs from malware samples procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |