Agent skill

static

Binary reverse engineering - PE/ELF analysis, Ghidra, capability detection

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/static

SKILL.md

Static Malware Analysis

Analyze binaries without execution:

  • File triage (type, packer, entropy)
  • String analysis (FLOSS)
  • PE/ELF structure analysis
  • Import/export analysis
  • Ghidra reverse engineering
  • Capability detection (capa)
  • IOC extraction

Required Context

  1. Sample: File path
  2. Depth: Quick triage or full analysis
  3. Focus: Persistence, C2, credentials, etc.
  4. Output: Report, IOCs, YARA rule

Tools Used

Ghidra, radare2, strings, floss, capa, binwalk, objdump, readelf

Example

/static
Sample: /samples/malware.exe
Depth: Full analysis
Output: IOCs + YARA rule

Expand your agent's capabilities with these related and highly-rated skills.

Didn't find tool you were looking for?

Be as detailed as possible for better results