File Static Triage
Safely triage suspicious files and scripts using static analysis, MITRE ATT&CK mapping, and heuristic scoring.
$6.99
Works with the AI tools you already use
File Static Triage
Example session with this skill installed
Analyze this triage report for a suspicious file named 'invoice_copy.exe' that was flagged by a user. It has high entropy and imports VirtualAllocEx and WriteProcessMemory.
- Read your context and instructions
- Compiled the file static triage
- Generated the document
The file invoice_copy.exe is classified as High Suspicion (Score: 75) due to indicative patterns of process injection and packing.
Triage Report: invoice_copy.exe
| Metric | Value |
|---|---|
| Verdict | High Suspicion (Score: 75) |
| SHA256 | 85c3275965106658444ed305c6d542c830157053361039f60c45fe70b135b927 |
| File Type | Win32 EXE (PE32) |
| Entropy | 7.85 (Likely Packed/Encrypted) |
| Compile Time | 2023-11-12 04:15:22 |
Detected Behaviors & ATT&CK Mapping
Process Injection (T1055): Combined use of VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread indicates intent to inject code into a remote process.
Obfuscated Files or Information (T1027): High entropy in the .text section suggests the presence of a packer or encrypted payload.
- Suspicious Imports: Usage of
IsDebuggerPresentandCheckRemoteDebuggerPresentfor anti-analysis evasion.
Summary
The sample displays classic downloader/injector behavior. The high entropy combined with memory manipulation APIs suggests a packed malicious payload designed to bypass basic static signatures.
Next steps
- Search the environment for the SHA256 hash in EDR logs to identify other infected hosts.
- Perform dynamic analysis in a sandbox to capture the secondary payload URL.
- Create a YARA rule targeting the specific import pattern and high-entropy section.
file-static-triage.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
Analyzing suspicious files manually is slow and dangerous. This skill provides a systematic framework for triaging potential malware using static analysis techniques, ensuring you identify threats without ever executing malicious code.
What it does
- Multi-algorithm hashing generates MD5, SHA1, SHA256, and fuzzy hashes like ssdeep or TLSH for threat intelligence lookups.
- Deep PE analysis inspects compile times, section permissions, packers, and imports grouped by malicious behavior like credential theft or evasion.
- Document inspection extracts VBA macros, auto-exec entry points, and remote templates from Office files and PDFs.
- Script deobfuscation identifies download cradles, AMSI bypasses, and Windows Defender tampering in PowerShell, VBS, and JS.
- Verdict scoring calculates a risk score from 0 to 60+ based on heuristics like entropy, magic bytes, and MITRE ATT&CK mapping.
How to work
- Initialize analysis by running the triage script against a single file or a directory of samples.
- Review the verdict to see the calculated risk score and the top three technical reasons for the classification.
- Map behaviors to MITRE ATT&CK techniques based on identified strings, APIs, and file structures.
- Export findings into a JSON report for integration with EDR or threat intel platforms.
Frameworks & tools
The skill utilizes python3 with pefile for header analysis, ssdeep and python-tlsh for similarity matching, and focuses on MITRE ATT&CK alignment.
Why this beats prompting it yourself
Generic LLM prompts often miss subtle indicators like imphashes or specific PE section characteristics. This skill enforces a strict safety protocol and a weighted scoring system that ensures consistent, repeatable verdicts backed by actual file telemetry.
Use cases
- Triage suspicious email attachments or web downloads before detonation.
- Analyze obfuscated PowerShell scripts found in system logs.
- Identify packed or signed-but-malicious binaries during incident response.
- Generate technical summaries and ATT&CK mappings for SOC reports.
Known limitations
Analysis is strictly static and does not account for runtime behavior or multi-stage payloads downloaded after execution. Requires an isolated analysis environment.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean today
- Passed all security checks, Safe to install