yara-rule-authoring

3.0k
trailofbitstrailofbits

Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module.

192 days ago

clawdex by Koi

1.8k
openclawopenclaw

Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe.

securityclawhubmalware-detection
192 days ago

eicar-test

1.1k
cisco-ai-defensecisco-ai-defense

Test skill containing EICAR test file for malware detection

192 days ago

file-uploads

756
dadbodgeoffdadbodgeoff

Production-grade secure file upload pipeline with multi-stage validation, malware scanning (ClamAV), hash-based duplicate detection, and race condition protection using distributed locks.

192 days ago

YARA Rule Testing

71
PramodDuttaPramodDutta

Writing and testing YARA rules for malware detection, threat hunting, and file classification with rule validation and false-positive rate testing.

yaramalwarethreat-hunting+2
192 days ago

analysis-tshark

64
AgentSecOpsAgentSecOps

Network protocol analyzer and packet capture tool for traffic analysis, security investigations, and forensic examination using Wireshark's command-line interface. Use when: (1) Analyzing network traffic for security incidents and malware detection, (2) Capturing and filtering packets for forensic analysis, (3) Extracting credentials and sensitive data from network captures, (4) Investigating network anomalies and attack patterns, (5) Validating encryption and security controls, (6) Performing protocol analysis for vulnerability research.

packet-capturenetwork-analysisforensics+3
192 days ago

detection-engineer

11
gl0bal01gl0bal01

Create detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.

192 days ago

malware-report-writer

11
gl0bal01gl0bal01

Professional malware analysis report creation for enterprise malware analysis and incident response. Use when the user needs to create, structure, or improve a malware analysis report, write technical documentation for malware samples, create executive summaries, or format IOCs and detection rules for professional delivery.

192 days ago

pt-lotl-techniques

3
santosomarsantosomar

Demonstrates Living-off-the-Land (LotL) techniques using native OS tools to simulate realistic threat actor behavior during authorized penetration tests. Use when proving attack feasibility without custom malware, testing detection coverage, and validating what a real adversary could achieve with only built-in system capabilities.

192 days ago

implementing-google-workspace-phishing-protection

2
mukul975mukul975

Configure Google Workspace advanced phishing and malware protection settings including pre-delivery scanning, attachment protection, spoofing detection, and Enhanced Safe Browsing.

google-workspacegmailphishing+4
192 days ago

performing-malware-triage-with-yara

2
mukul975mukul975

Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.

malwareYARAtriage+2
192 days ago

detecting-mobile-malware-behavior

2
mukul975mukul975

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.

mobile-securityandroidios+3
192 days ago

analyzing-malware-family-relationships-with-malpedia

2
mukul975mukul975

Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.

malpediamalware-familyyara+5
192 days ago

detecting-process-injection-techniques

2
mukul975mukul975

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. Uses memory forensics, API monitoring, and behavioral analysis to identify injection artifacts. Activates for requests involving process injection detection, code injection analysis, hollowed process investigation, or in-memory threat detection.

malwareprocess-injectiondetection+2
192 days ago

detecting-fileless-malware-techniques

2
mukul975mukul975

Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing traditional executable files to disk. Activates for requests involving fileless threat detection, in-memory malware investigation, LOLBin abuse analysis, or WMI persistence examination.

malwarefilelessLOLBins+2
192 days ago

conducting-malware-incident-response

2
mukul975mukul975

Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment, analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal, worm containment, malware triage, or infected endpoint remediation.

malware-responsemalware-analysiseradication+2
192 days ago

detecting-fileless-attacks-on-endpoints

2
mukul975mukul975

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.

endpointfileless-malwarememory-attacks+2
192 days ago

extracting-iocs-from-malware-samples

2
mukul975mukul975

Extracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples.

malwareIOC-extractionthreat-intelligence+2
192 days ago

analyzing-network-covert-channels-in-malware

2
mukul975mukul975

Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.

covert-channelsdns-tunnelingicmp-exfiltration+4
192 days ago

performing-memory-forensics-with-volatility3-plugins

2
mukul975mukul975

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

memory-forensicsvolatility3malware-analysis+4
192 days ago

performing-memory-forensics-with-volatility3

2
mukul975mukul975

Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

forensicsmemory-forensicsvolatility+3
192 days ago

performing-malware-hash-enrichment-with-virustotal

2
mukul975mukul975

Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches, and contextual threat intelligence for incident triage and IOC validation.

virustotalmalware-analysishash-enrichment+5
192 days ago

analyzing-command-and-control-communication

2
mukul975mukul975

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.

malwareC2command-and-control+2
192 days ago

conducting-memory-forensics-with-volatility

2
mukul975mukul975

Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition.

memory-forensicsvolatilityRAM-analysis+2
192 days ago

analyzing-memory-dumps-with-volatility

2
mukul975mukul975

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation.

malwarememory-forensicsVolatility+2
192 days ago

performing-firmware-malware-analysis

2
mukul975mukul975

Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.

malwarefirmwareIoT+2
192 days ago

analyzing-bootkit-and-rootkit-samples

2
mukul975mukul975

Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.

malwarebootkitrootkit+2
192 days ago

performing-malware-persistence-investigation

2
mukul975mukul975

Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.

forensicsmalware-persistenceautoruns+4
192 days ago

analyzing-network-traffic-of-malware

2
mukul975mukul975

Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.

malwarenetwork-analysisPCAP+2
192 days ago

performing-yara-rule-development-for-detection

2
mukul975mukul975

Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.

yaramalware-detectionsignature-development+4
192 days ago

detecting-rootkit-activity

2
mukul975mukul975

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.

malwarerootkitdetection+2
192 days ago

gcp-vulnerable-components

hminooeihminooei

Use this skill when users need to audit, detect, or remediate Vulnerable and Outdated Components (OWASP A06:2021) on Google Cloud Platform. This includes auditing Binary Authorization enforcement on GKE clusters, scanning container images in Artifact Registry for known CVEs, reviewing Security Command Center findings for container threats (malicious scripts, reverse shells, cryptomining, malware) and vulnerability detections (outdated libraries), configuring Cloud Armor WAF rules to block exploitation of vulnerable endpoints (RCE, file inclusion), and monitoring GCP security bulletins. Activate for container scanning, Binary Authorization policy checks, CVE remediation, or OWASP A06 compliance.

192 days ago

VirusTotal

san-npmsan-npm

URL, file, domain, and IP scanning via VirusTotal CLI and API. Threat detection, reputation checks, malware analysis, phishing detection.

192 days ago