acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware,
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-linux-elf-malware --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-linux-elf-malwareContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware,
name: analyzing-linux-elf-malware description: 'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis. ' domain: cybersecurity subdomain: malware-analysis tags: - malware - Linux - ELF - reverse-engineering - server-malware version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - DE.AE-02 - RS.AN-03 - ID.RA-01 - DE.CM-01
**Do not use** for Windows PE binary analysis; use PEStudio, Ghidra, or IDA for Windows malware.
Examine the ELF header and basic properties:
# File type identification file suspect_binary # Detailed ELF header analysis readelf -h suspect_binary # Section headers readelf -S suspect_binary # Program headers (segments) readelf -l suspect_binary # Symbol table (if not stripped) readelf -s suspect_binary nm suspect_binary 2>/dev/null # Dynamic linking information readelf -d suspect_binary ldd suspect_binary 2>/dev/null # Only on matching architecture! # Compute hashes md5sum suspect_binary sha256sum suspect_binary # Check for packing/UPX upx -t suspect_binary
# Python-based ELF analysis
from elftools.elf.elffile import ELFFile
import hashlib
with open("suspect_binary", "rb") as f:
data = f.read()
sha256 = hashlib.sha256(data).hexdigest()
with open("suspect_binary", "rb") as f:
elf = ELFFile(f)
print(f"SHA-256: {sha256}")
print(f"Class: {elf.elfclass}-bit")
print(f"Endian: {elf.little_endian and 'Little' or 'Big'}")
print(f"Machine: {elf.header.e_machine}")
print(f"Type: {elf.header.e_type}")
print(f"Entry Point: 0x{elf.header.e_entry:X}")
# Check if stripped
symtab = elf.get_section_by_name('.symtab')
print(f"Stripped: {'Yes' if symtab is None else 'No'}")
# Section entropy analysis
import math
from collections import Counter
for section in elf.iter_sections():
data = section.data()
if len(data) > 0:
entropy = -sum((c/len(data)) * math.log2(c/len(data))
for c in Counter(data).values() if c > 0)
if entropy > 7.0:
print(f" [!] High entropy section: {section.name} ({entropy:.2f})")Search for embedded IOCs and functionality clues:
# ASCII strings
strings suspect_binary > strings_output.txt
# Search for network indicators
grep -iE "(http|https|ftp)://" strings_output.txt
grep -iE "([0-9]{1,3}\.){3}[0-9]{1,3}" strings_output.txt
grep -iE "[a-zA-Z0-9.-]+\.(com|net|org|io|ru|cn)" strings_output.txt
# Search for shell commands
grep -iE "(bash|sh|wget|curl|chmod|/tmp/|/dev/)" strings_output.txt
# Search for crypto mining indicators
grep -iE "(stratum|xmr|monero|pool\.|mining)" strings_output.txt
# Search for SSH/credential theft
grep -iE "(ssh|authorized_keys|id_rsa|shadow|passwd)" strings_output.txt
# Search for persistence mechanisms
grep -iE "(crontab|systemd|init\.d|rc\.local|ld\.so\.preload)" strings_output.txt
# FLOSS for obfuscated strings (if available)
floss suspect_binaryIdentify what system calls and libraries the malware uses:
# List imported functions (dynamically linked) readelf -r suspect_binary | grep -E "socket|connect|exec|fork|open|write|bind|listen" # Trace system calls during execution (in isolated VM only) strace -f -e trace=network,process,file -o strace_output.txt ./suspect_binary # Trace library calls ltrace -f -o ltrace_output.txt ./suspect_binary # Key system calls to watch: # Network: socket, connect, bind, listen, accept, sendto, recvfrom # Process: fork, execve, clone, kill, ptrace # File: open, read, write, unlink, rename, chmod # Persistence: inotify_add_watch (file monitoring)
Debug the malware to observe runtime behavior:
# Start GDB with the binary gdb ./suspect_binary # Set breakpoints on key functions (gdb) break main (gdb) break socket (gdb) break connect (gdb) break execve (gdb) break fork # Run and analyze (gdb) run (gdb) info registers # View register state (gdb) x/20s $rdi # Examine string argument (gdb) bt # Backtrace (gdb) continue # For stripped binaries, break on entry point (gdb) break *0x400580 # Entry point from readelf (gdb) run # Monitor network connections during execution # In another terminal: ss -tlnp # List listening sockets ss -tnp # List established connections
Perform deep code analysis on the ELF binary:
Ghidra Analysis for Linux ELF: ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1. Import: File -> Import -> Select ELF binary - Ghidra auto-dete
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative