abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Detect sandbox and VM evasion techniques in malware samples by analyzing
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-malware-sandbox-evasion-techniques --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-malware-sandbox-evasion-techniquesContext preview
The summary Claude sees to decide when to auto-load this skill.
Detect sandbox and VM evasion techniques in malware samples by analyzing
name: analyzing-malware-sandbox-evasion-techniques description: Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for evasion indicators, or when building detections for anti-analysis techniques. domain: cybersecurity subdomain: malware-analysis tags: - sandbox-evasion - malware-analysis - cuckoo - anyrun - mitre-attack - virtualization-detection - behavioral-analysis version: '1.0' author: mahipal license: Apache-2.0 d3fend_techniques: - Platform Hardening - Restore Object - Process Analysis - System Call Filtering - Restore Software nist_csf: - DE.AE-02 - RS.AN-03 - ID.RA-01 - DE.CM-01 mitre_attack: - T1497.001 - T1497.003 - T1480 - T1027.002
Sandbox evasion (MITRE ATT&CK T1497) allows malware to detect analysis environments and alter behavior to avoid detection. This skill analyzes behavioral reports from Cuckoo Sandbox and AnyRun for evasion indicators including timing-based checks (GetTickCount, QueryPerformanceCounter, sleep inflation), VM artifact detection (registry keys, MAC address prefixes, process names like vmtoolsd.exe), user interaction checks (mouse movement, keyboard input), and environment fingerprinting (disk size, CPU count, RAM). Detection rules flag samples exhibiting these behaviors for deeper manual analysis.
1. Parse Cuckoo/AnyRun behavioral report JSON files 2. Extract API call sequences for timing-related functions 3. Identify VM artifact detection via registry queries and WMI calls 4. Detect sleep inflation by comparing requested vs actual sleep durations 5. Flag user interaction checks (GetCursorPos, GetAsyncKeyState patterns) 6. Score evasion sophistication based on technique count and diversity 7. Map detected techniques to MITRE ATT&CK T1497 sub-techniques
JSON report listing detected evasion techniques with MITRE ATT&CK mapping, API call evidence, evasion sophistication score, and classification of evasion categories (timing, VM detection, user interaction, environment fingerprinting).
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…