{"enrichment":{"faq":[{"a":"ctf-malware teaches deobfuscation methods for PowerShell, Python, and other scripting languages. The skill covers static analysis techniques using tools like Capstone for disassembly, plus dynamic analysis with strace and ltrace to trace system calls. You'll learn to identify obfuscation patterns, decrypt encoded payloads, and extract malicious logic from trojanized plugins and custom implementations.","q":"How to analyze obfuscated scripts with ctf-malware?"},{"a":"ctf-malware equips you with both static and dynamic analysis approaches. Static techniques include PE binary reverse engineering, YARA rule creation for detection, and API hashing reverse lookup. Dynamic analysis covers memory forensics with Volatility, process injection detection, and sandbox behavior observation. The skill also addresses anti-analysis evasion detection and custom crypto protocol identification.","q":"What malware analysis techniques does ctf-malware cover?"},{"a":"Yes. ctf-malware guides you through extracting command-and-control indicators from network traffic using PCAP analysis and beacon identification. You'll learn decryption techniques for RC4 and AES encrypted communications, custom crypto protocol analysis, and malware configuration extraction from captured traffic. These methods help identify C2 servers and decode malicious commands.","q":"Can ctf-malware help with C2 traffic decryption?"},{"a":"ctf-malware teaches techniques to detect and bypass anti-analysis and sandbox evasion tactics. The skill covers VM sandbox detection methods, API hashing techniques used by malware, and process injection detection strategies. You'll learn to recognize evasion patterns and understand how malware avoids analysis, enabling you to circumvent these defenses in CTF scenarios.","q":"How does ctf-malware address sandbox evasion detection?"},{"a":"ctf-malware covers analysis of PE binaries, .NET malware using dnspy, PyInstaller-packed executables, and shellcode. It integrates tools like YARA for detection rules, Volatility for memory forensics, Capstone for disassembly, and strace/ltrace for dynamic tracing. The skill also addresses PCAP analysis for network indicators and custom protocol reverse engineering.","q":"What tools and formats does ctf-malware support?"},{"a":"Yes. ctf-malware is designed specifically for solving CTF challenges involving malware and forensics. It combines obfuscated code decryption, binary reverse engineering, network traffic analysis, and evasion detection into a cohesive framework. The skill prepares you for real competition scenarios requiring rapid malware dissection and indicator extraction under time pressure.","q":"Is ctf-malware suitable for CTF competition challenges?"}],"shadow_tags":["threat-intel","binary-exploitation","dynamic-analysis","encryption-breaking","incident-response","code-deobfuscation","network-forensics","evasion-detection","payload-extraction","ctf-competition"],"summary_rewrite":"ctf-malware equips you with techniques for dissecting malware in CTF competitions, covering obfuscated scripts, binary analysis, network traffic decryption, and evasion detection. It guides you through static analysis with tools like YARA and Capstone, dynamic analysis with strace and ltrace, and memory forensics with Volatility, plus custom crypto protocol identification and malware configuration extraction."},"files":[{"bytes":8379,"path":"ctf-malware/SKILL.md","sha256":"3a73e3ea43b2a39d146e4af7616b8a8ed29a92c77485ce3a85788512bebf7a67","url":"https://skillfed.io/files/ljagiello/ctf-skills/ctf-malware/125f033a/SKILL.md"}],"id":"ljagiello/ctf-skills/ctf-malware","links":{"html":"https://skillfed.io/ljagiello/ctf-skills/ctf-malware","md":"https://skillfed.io/ljagiello/ctf-skills/ctf-malware.md","repo":"https://github.com/ljagiello/ctf-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":334,"language":"Python","last_updated":"2026-07-24","license":"MIT","name":"ctf-malware","publisher":"ljagiello","stars":2840},"relations":{"similar":[{"id":"ljagiello/ctf-skills/ctf-reverse"},{"id":"trailofbits/skills/yara-rule-authoring"},{"id":"hypnguyen1209/offensive-claude/malware-analysis"},{"id":"Aradotso/security-skills/claude-code-cybersecurity-skill"},{"id":"FrancescoStabile/numasec/forensics-kit"},{"id":"hypnguyen1209/offensive-claude/shellcode-dev"},{"id":"yaklang/hack-skills/windows-av-evasion"},{"id":"Aradotso/security-skills/bitdefender-malware-investigation"},{"id":"dariushoule/x64dbg-skills/find-oep"},{"id":"gmh5225/awesome-game-security/reverse-engineering"}]},"slug":{"owner":"ljagiello","repo":"ctf-skills","skill":"ctf-malware"},"version":"125f033a"}
