‹ 首页

triage-malware

@dandye · 收录于 5 天前 · 上游提交 3 个月前

Triage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, and recommends containment actions.

适合你,如果经常需要快速分析可疑文件哈希并获取处置建议

/ 通过 npx 安装 校验哈希
npx oh-my-skill add dandye/ai-runbooks/triage-malware
/ 通过 bash 安装
curl -fsSL https://oh-my-skill.com/install.sh | bash -s -- dandye/ai-runbooks/triage-malware
/ 已经装过?验证本机副本,不用重装
npx oh-my-skill verify dandye/ai-runbooks/triage-malware
安装目标可用 --agent / --scope 或 --to 明确指定;省略时只会在唯一已存在的 agent 目录上自动选择,零命中或多命中会停止并提示。content_hash 缺失或不一致均拒装。
119GitHub stars
~837上下文体积 · 单文件
索引托管

怎么用

商店整理自技能原文 · 版本 086cbf6 · 表述以原文为准
它做什么

当你提供一个可疑文件哈希,Claude 会执行恶意软件分流分析:查询威胁情报、行为指标,搜索受影响的主机和网络连接,最后给出判定(恶意/可疑/干净)和处置建议。

什么时候触发

当你请求调查一个可疑文件哈希或处理恶意软件告警时触发。

装好后可以这样说
Claude 将运行完整的分流流程。
需要你提供告警中的文件哈希。
Claude 会检查执行历史和网络IOC。
技能原文 SKILL.md作者撰写 · Apache-2.0 · 086cbf6

Malware Triage Skill

Perform initial analysis and context gathering for a suspected malicious file hash identified during an investigation or alert.

Inputs
  • FILE_HASH - MD5, SHA1, or SHA256 hash of the suspected file
  • CASE_ID - SOAR case ID for documentation
  • ALERT_GROUP_IDENTIFIERS - Alert group identifiers from the case
  • (Optional) TIME_FRAME_HOURS - Lookback period (default: 72)
Workflow
Step 1: Get Case Context
secops-soar.get_case_full_details(case_id=CASE_ID)
Step 2: GTI File Report
gti-mcp.get_file_report(hash=FILE_HASH)

Record:

  • Detection ratio (e.g., 45/70 engines)
  • Malware family classification
  • First/last seen dates
  • Associated threat actors or campaigns
Step 3: GTI Behavior Summary
gti-mcp.get_file_behavior_summary(hash=FILE_HASH)

Extract behavioral indicators:

  • Network: Contacted IPs/domains → NETWORK_IOCs_GTI
  • File system: Dropped files, modified files
  • Registry: Modified keys
  • MITRE TTPs: Observed techniques from sandbox
Step 4: SIEM Execution Check

Search for file execution events:

secops-mcp.search_security_events(
    text='target.file.sha256 = "FILE_HASH" OR target.file.md5 = "FILE_HASH"',
    hours_back=TIME_FRAME_HOURS
)

Look for: PROCESS_LAUNCH, FILE_CREATION, FILE_MODIFICATION

Identify:

  • AFFECTED_HOSTS - Machines where file was seen
  • AFFECTED_USERS - Users who executed/accessed the file
Step 5: SIEM Network Activity

Search for network connections from processes with this hash:

secops-mcp.search_security_events(
    text='principal.process.file.sha256 = "FILE_HASH"',
    hours_back=TIME_FRAME_HOURS
)

Extract: NETWORK_IOCs_SIEM (contacted IPs/domains)

Step 6: Enrich Network IOCs

Combine NETWORK_IOCs_GTI + NETWORK_IOCs_SIEMALL_NETWORK_IOCs

For each network IOC, use /enrich-ioc:

  • Check GTI reputation
  • Check SIEM presence
  • Check IOC match status
Step 7: Check Related Cases

Use /find-relevant-case with:

SEARCH_TERMS = AFFECTED_HOSTS + AFFECTED_USERS + ALL_NETWORK_IOCs
Step 8: Synthesize & Document

Use /document-in-case with assessment:

Malware Triage for Hash FILE_HASH:
- GTI Classification: [family, detection ratio]
- Behavior: [network, files, registry]
- Affected Hosts: [list]
- Network IOCs: [with enrichment]
- Related Cases: [list]

Assessment: [severity level]

Recommendation:
- [ ] Isolate affected hosts
- [ ] Block network IOCs
- [ ] Escalate to IR
- [ ] Monitor only
Required Outputs

After completing this skill, you MUST report these outputs:

| Output | Description | |--------|-------------| | MALWARE_CLASSIFICATION | GTI verdict and malware family (e.g., "Emotet - Banking Trojan") | | BEHAVIORAL_IOCS | Network IOCs from sandbox analysis (contacted IPs/domains) | | AFFECTED_HOSTS | Hosts where this malware was executed or detected | | AFFECTED_USERS | Users who executed or accessed the malware | | TRIAGE_VERDICT | Overall verdict: malicious, suspicious, or clean |

Severity Assessment Matrix

| Factor | Low | Medium | High | Critical | |--------|-----|--------|------|----------| | GTI Detection | < 5 engines | 5-20 engines | 20-50 engines | > 50 engines | | Execution | Not executed | Downloaded only | Executed | Active C2 | | Spread | Single host | 2-5 hosts | 5-20 hosts | > 20 hosts | | Network IOCs | None observed | Benign | Suspicious | Known malicious | | Data at Risk | None | Low value | PII/credentials | Critical systems |

Recommended Actions by Severity

Critical/High:

  1. Immediately isolate affected hosts
  2. Block network IOCs at firewall
  3. Escalate to Incident Response
  4. Preserve forensic evidence

Medium:

  1. Monitor affected hosts closely
  2. Block known malicious IOCs
  3. Schedule endpoint scan
  4. Escalate to Tier 2

Low:

  1. Document findings
  2. Monitor for recurrence
  3. Close with detailed notes
按 Apache-2.0 许可原样转载,未经改动 · 在 GitHub 查看 →

评论

登录即可评论;带「已验证安装」的,是发布者名下有本店的安装或持有记录。