acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-malware-sandbox-evasion-techniques --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-malware-sandbox-evasion-techniquesContext preview
The summary Claude sees to decide when to auto-load this skill.
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction
name: analyzing-malware-sandbox-evasion-techniques description: Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports domain: cybersecurity subdomain: malware-analysis tags: - sandbox-evasion - malware-analysis - cuckoo - anyrun - mitre-attack - virtualization-detection - behavioral-analysis version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques: - Platform Hardening - Restore Object - Process Analysis - System Call Filtering - Restore Software nist_csf: - DE.AE-02 - RS.AN-03 - ID.RA-01 - DE.CM-01
Sandbox evasion (MITRE ATT&CK T1497) allows malware to detect analysis environments and alter behavior to avoid detection. This skill analyzes behavioral reports from Cuckoo Sandbox and AnyRun for evasion indicators including timing-based checks (GetTickCount, QueryPerformanceCounter, sleep inflation), VM artifact detection (registry keys, MAC address prefixes, process names like vmtoolsd.exe), user interaction checks (mouse movement, keyboard input), and environment fingerprinting (disk size, CPU count, RAM). Detection rules flag samples exhibiting these behaviors for deeper manual analysis.
1. Parse Cuckoo/AnyRun behavioral report JSON files 2. Extract API call sequences for timing-related functions 3. Identify VM artifact detection via registry queries and WMI calls 4. Detect sleep inflation by comparing requested vs actual sleep durations 5. Flag user interaction checks (GetCursorPos, GetAsyncKeyState patterns) 6. Score evasion sophistication based on technique count and diversity 7. Map detected techniques to MITRE ATT&CK T1497 sub-techniques
JSON report listing detected evasion techniques with MITRE ATT&CK mapping, API call evidence, evasion sophistication score, and classification of evasion categories (timing, VM detection, user interaction, environment fingerprinting).
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative