offensive-ctf/malware-ctf/SKILL.md
Lab/CTF: malware-analysis challenges; obfuscated scripts, PE/.NET/ELF, shellcode artifacts, memory/PCAP, configs, encrypted traffic.
npx skillsauth add aeondave/malskill malware-ctfInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Goal: solve malware-analysis challenge solving tasks with professional offensive methodology, preserved imported technique coverage, and reproducible evidence.
offensive-techniques methodology before selecting tools.Primary methodology to load:
reversing-techniqueforensic-techniquenetwork-techniquecrypto-techniqueUse these as decision engines. This skill adds challenge-oriented triage, time-boxing, and preserved specialized patterns from the imported corpus.
Prefer these tool families when the corresponding signal appears:
capayaravolatility3ghidrax64dbgfridawiresharkTool syntax belongs in the tool skills. This skill decides when a tool family fits and what output should validate progress.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.