Behavioral analysis of a sample executed in an isolated VM. Use after triage when runtime behavior, C2 traffic, dropped files, persistence, or injection must be observed. Claude produces a tailored VM runbook from triage predictions, then parses the exported text evidence (Procmon CSV, Sysmon JSON/CSV, tshark output, autoruns, strings) on the host to reconstruct behavior and extract IOCs. The analyst runs the VM; Claude never executes the sample.
mdr add gl0bal01/malware-analysis-claude-skills/malware-dynamic-analysis@git:20260905.e1d9a1amdr add gl0bal01/malware-analysis-claude-skills/malware-dynamic-analysis@sha256:1a687c61aaee9620[](https://markdownregistry.com/a/art_6g6g3i3ze7fqugze)
0 badge views in 30 days
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260905.e1d9a1a latest | 2026-09-05 | e1d9a1a | 19,642 B | A | view · diff |
| git:20260905.fd80b2a | 2026-09-05 | fd80b2a | 19,247 B | A | view · diff |
| git:20260412.09f91e4 | 2026-04-12 | 09f91e4 | 21,178 B | A | view · diff |
| git:20251027.43cc347 | 2025-10-27 | 43cc347 | 21,151 B | A | view |
gl0bal01/malware-analysis-claude-skills · 46 stars · license MIT · pushed 2026-09-05 · branch main
GET https://markdownregistry.com/api/v1/artifacts/art_6g6g3i3ze7fqugze GET https://markdownregistry.com/api/v1/resolve?ref=gl0bal01/malware-analysis-claude-skills/malware-dynamic-analysis GET https://markdownregistry.com/api/v1/blob/1a687c61aaee962091b0477d9128a14798f0683aff02b2803e80040d2daaab38