Malware Report Writer
Create professional, comprehensive malware analysis reports for enterprise security teams, incident response, and threat intelligence.
When to Use This Skill
Use this skill when the user needs to:
- Create a complete malware analysis report from analysis findings
- Structure analysis results into professional documentation
- Write executive summaries for malware samples
- Format IOCs and detection rules for delivery
- Review or improve existing malware reports
- Prepare report documentation for stakeholders
Quick Start
Creating a New Report
- Use the report template from
assets/report_template.md as the base structure
- Gather all analysis artifacts:
- Sample hashes and file information
- Static analysis findings (strings, imports, PE structure)
- Dynamic analysis observations (processes, registry, network, files)
- IOCs identified
- Detection rules created
- Populate each section systematically
- Review against best practices in
references/best_practices.md
Report Structure
The standard report includes these sections in order:
- Executive Summary - High-level overview for non-technical stakeholders
- Sample Information - Basic file metadata and hashes
- Static Analysis - File structure, strings, imports/exports, resources
- Dynamic Analysis - Runtime behavior, system changes, network activity
- IOCs - Organized by type (file, network, host indicators)
- Detection Rules - YARA rules and optionally Sigma rules
- Malware Classification - Family, type, capabilities
- Remediation and Mitigation - Actionable response steps
- Technical Details - Additional deep-dive analysis
- Conclusion - Final summary and assessment
- References - External resources and links
- Appendix - Timeline, tools used, screenshots
Key Principles
Professional Quality
- Use precise technical language with clear explanations
- Include all three hash types (MD5, SHA1, SHA256)
- Provide full context for every finding
- Document methodology and tools used
- Include timestamps and version information
Professional Report Requirements
Industry-standard reports require:
- Complete technical documentation of malware samples
- Professional format suitable for enterprise delivery
- Working detection rules based on malware characteristics
- Clear IOCs that can be operationalized
Critical: The quality of your report reflects your professionalism. Allocate sufficient time for writing and review.
Audience Awareness
Structure content for multiple audiences:
- Executive Summary: Non-technical decision makers
- Technical Sections: Security analysts and researchers
- IOCs/Detection: SOC teams and detection engineers
- Remediation: Incident responders
Writing Guidelines
Executive Summary
- 2-4 paragraphs maximum
- Plain language, minimal jargon
- Answer: What? How critical? What actions?
- Include key findings in bullet points
Technical Analysis
- Document both positive and negative findings
- Provide evidence for every claim
- Use code blocks for technical artifacts
- Include screenshots when they add value
- Connect behaviors to specific evidence
IOCs Section
Format:
- Group by type (file, network, host)
- Include context for each indicator
- Provide confidence levels if uncertain
- Test IOCs for accuracy before including
Avoid:
- Environment-specific artifacts
- Personal/analyst system information
- Common legitimate values
- Untested indicators
Detection Rules
YARA Rules:
- Test against sample (must detect)
- Test against clean files (must not false positive)
- Include metadata: author, date, description, hash
- Use meaningful string and variable names
- Add comments explaining detection logic
- Set appropriate conditions to balance detection and false positives
Best practices:
rule Malware_Family_Variant {
meta:
description = "Detects Malware_Family based on C2 configuration"
author = "Analyst Name"
date = "2025-10-25"
hash = "abc123..."
reference = "Internal analysis"
strings:
$c2_config = { 48 8B ?? ?? ?? ?? ?? 48 8D ?? ?? } // Config access pattern
$ua_string = "Mozilla/4.0 (Suspicious UA)" ascii
$mutex = "Global\\UniqueMalwareMutex" wide
condition:
uint16(0) == 0x5A4D and // MZ header
filesize < 2MB and
2 of them
}
Common Mistakes to Avoid
- Over-relying on automated tool output without interpretation
- Listing findings without explaining significance
- Missing critical hashes or file metadata
- Weak or untested detection rules
- Vague remediation recommendations
- Poor grammar/spelling
- Inconsistent formatting
- Environment-specific artifacts in IOCs
Best Practices Reference
For detailed guidance on report quality, writing style, and common pitfalls, see references/best_practices.md.
Key topics covered:
- Report writing principles (clarity, completeness, objectivity)
- Structure guidelines for each section
- IOC quality standards
- Detection rule best practices
- Audience considerations
- Quality checklist
- Efficient workflow strategies
Time Management Strategies
For efficient malware report creation:
Recommended workflow:
Pro tip: Start documenting in report format during analysis to save time.
Quality Checklist
Before submitting any report, verify:
Technical Accuracy:
Detection Rules:
IOCs:
Report Quality:
Professional Standards:
Output Format
Create reports in Markdown format using the template structure. For professional delivery:
- Create report in Markdown using the template
- Convert to PDF for professional appearance (if required)
- Ensure all sections are complete
- Include any screenshots as appendix items
- Verify detection rules are included and tested
Example Usage
User request: "Help me write a report for this ransomware sample I analyzed"
Workflow:
- Load the report template
- Ask user for key findings from their analysis
- Structure findings into appropriate sections
- Help craft executive summary
- Format IOCs properly
- Review and validate YARA rules
- Provide remediation recommendations
- Review final report against quality checklist
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: malware-report-writer3description: Professional malware analysis report creation for enterprise malware analysis and incident response. Use when the user needs to create, structure, or improve a malware analysis report, write technical documentation for malware samples, create executive summaries, or format IOCs and detection rules for professional delivery. Use when this capability is needed.4---56# Malware Report Writer78Create professional, comprehensive malware analysis reports for enterprise security teams, incident response, and threat intelligence.910## When to Use This Skill1112Use this skill when the user needs to:13- Create a complete malware analysis report from analysis findings14- Structure analysis results into professional documentation15- Write executive summaries for malware samples16- Format IOCs and detection rules for delivery17- Review or improve existing malware reports18- Prepare report documentation for stakeholders1920## Quick Start2122### Creating a New Report23241. Use the report template from `assets/report_template.md` as the base structure252. Gather all analysis artifacts:26 - Sample hashes and file information27 - Static analysis findings (strings, imports, PE structure)28 - Dynamic analysis observations (processes, registry, network, files)29 - IOCs identified30 - Detection rules created313. Populate each section systematically324. Review against best practices in `references/best_practices.md`3334### Report Structure3536The standard report includes these sections in order:37381. **Executive Summary** - High-level overview for non-technical stakeholders392. **Sample Information** - Basic file metadata and hashes403. **Static Analysis** - File structure, strings, imports/exports, resources414. **Dynamic Analysis** - Runtime behavior, system changes, network activity425. **IOCs** - Organized by type (file, network, host indicators)436. **Detection Rules** - YARA rules and optionally Sigma rules447. **Malware Classification** - Family, type, capabilities458. **Remediation and Mitigation** - Actionable response steps469. **Technical Details** - Additional deep-dive analysis4710. **Conclusion** - Final summary and assessment4811. **References** - External resources and links4912. **Appendix** - Timeline, tools used, screenshots5051## Key Principles5253### Professional Quality54- Use precise technical language with clear explanations55- Include all three hash types (MD5, SHA1, SHA256)56- Provide full context for every finding57- Document methodology and tools used58- Include timestamps and version information5960### Professional Report Requirements61Industry-standard reports require:62- Complete technical documentation of malware samples63- Professional format suitable for enterprise delivery64- Working detection rules based on malware characteristics65- Clear IOCs that can be operationalized6667**Critical:** The quality of your report reflects your professionalism. Allocate sufficient time for writing and review.6869### Audience Awareness70Structure content for multiple audiences:71- **Executive Summary**: Non-technical decision makers72- **Technical Sections**: Security analysts and researchers 73- **IOCs/Detection**: SOC teams and detection engineers74- **Remediation**: Incident responders7576## Writing Guidelines7778### Executive Summary79- 2-4 paragraphs maximum80- Plain language, minimal jargon81- Answer: What? How critical? What actions?82- Include key findings in bullet points8384### Technical Analysis85- Document both positive and negative findings86- Provide evidence for every claim87- Use code blocks for technical artifacts88- Include screenshots when they add value89- Connect behaviors to specific evidence9091### IOCs Section92**Format:**93- Group by type (file, network, host)94- Include context for each indicator95- Provide confidence levels if uncertain96- Test IOCs for accuracy before including9798**Avoid:**99- Environment-specific artifacts100- Personal/analyst system information101- Common legitimate values102- Untested indicators103104### Detection Rules105**YARA Rules:**106- Test against sample (must detect)107- Test against clean files (must not false positive)108- Include metadata: author, date, description, hash109- Use meaningful string and variable names110- Add comments explaining detection logic111- Set appropriate conditions to balance detection and false positives112113**Best practices:**114```yara115rule Malware_Family_Variant {116 meta:117 description = "Detects Malware_Family based on C2 configuration"118 author = "Analyst Name"119 date = "2025-10-25"120 hash = "abc123..."121 reference = "Internal analysis"122 123 strings:124 $c2_config = { 48 8B ?? ?? ?? ?? ?? 48 8D ?? ?? } // Config access pattern125 $ua_string = "Mozilla/4.0 (Suspicious UA)" ascii126 $mutex = "Global\\UniqueMalwareMutex" wide127 128 condition:129 uint16(0) == 0x5A4D and // MZ header130 filesize < 2MB and131 2 of them132}133```134135### Common Mistakes to Avoid136- Over-relying on automated tool output without interpretation137- Listing findings without explaining significance138- Missing critical hashes or file metadata139- Weak or untested detection rules140- Vague remediation recommendations141- Poor grammar/spelling142- Inconsistent formatting143- Environment-specific artifacts in IOCs144145## Best Practices Reference146147For detailed guidance on report quality, writing style, and common pitfalls, see `references/best_practices.md`.148149Key topics covered:150- Report writing principles (clarity, completeness, objectivity)151- Structure guidelines for each section152- IOC quality standards153- Detection rule best practices154- Audience considerations155- Quality checklist156- Efficient workflow strategies157158## Time Management Strategies159160For efficient malware report creation:161162**Recommended workflow:**163- **Phase 1-2**: Analysis164 - Document findings continuously (don't wait)165 - Take screenshots and capture evidence166 - Create detection rules during analysis167 - Organize notes by report section168169- **Phase 3-4**: Report writing170 - Draft all technical sections first171 - Write IOCs, detection rules, remediation172 - Create executive summary and conclusion173 - Final quality check and formatting174175**Pro tip:** Start documenting in report format during analysis to save time.176177## Quality Checklist178179Before submitting any report, verify:180181**Technical Accuracy:**182- [ ] All three hash types included and verified183- [ ] File paths are complete and accurate184- [ ] Timestamps include timezone185- [ ] Process IDs included for process activity186- [ ] Tool versions documented187188**Detection Rules:**189- [ ] YARA rules tested against sample (detects correctly)190- [ ] YARA rules tested against clean files (no false positives)191- [ ] Rules include complete metadata192- [ ] Conditions are appropriate and not over-matching193194**IOCs:**195- [ ] Grouped by type (file, network, host)196- [ ] Context provided for each IOC197- [ ] No environment-specific artifacts198- [ ] All IOCs validated199200**Report Quality:**201- [ ] Executive summary is non-technical and actionable202- [ ] All sections completed203- [ ] Grammar and spelling checked204- [ ] Consistent formatting throughout205- [ ] Evidence supports all claims206- [ ] Remediation steps are specific and prioritized207208**Professional Standards:**209- [ ] Report is professional and enterprise-ready210- [ ] Detection rules work and are well-documented211- [ ] Technical details demonstrate thorough analysis212- [ ] Report answers: What is it? What does it do? How to detect? How to remove?213214## Output Format215216Create reports in Markdown format using the template structure. For professional delivery:2171. Create report in Markdown using the template2182. Convert to PDF for professional appearance (if required)2193. Ensure all sections are complete2204. Include any screenshots as appendix items2215. Verify detection rules are included and tested222223## Example Usage224225**User request:** "Help me write a report for this ransomware sample I analyzed"226227**Workflow:**2281. Load the report template2292. Ask user for key findings from their analysis2303. Structure findings into appropriate sections2314. Help craft executive summary2325. Format IOCs properly2336. Review and validate YARA rules2347. Provide remediation recommendations2358. Review final report against quality checklist236237---238> Converted and distributed by [TomeVault](https://tomevault.io/claim/gl0bal01) — claim your Tome and manage your conversions.239<!-- tomevault:4.0:skill_md:2026-04-11 -->