Analyzing Malware Persistence With Autoruns:网络安全 skill: analyzing-malware-persistence-with-aut,适用于安全分析、取证与威胁排查场景。
Analyzing Malware Persistence With Autoruns:网络安全 skill: analyzing-malware-persistence-with-aut,适用于安全分析、取证与威胁排查场景。
> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集
> 原文件: skills/analyzing-malware-persistence-with-autoruns/SKILL.md
> 模型推荐: claude-opus-4-7 (安全分析深度推理)
mukul975 整理的 100+ 个网络安全专业 skill — 覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。
michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。
---
1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时触发对应 skill
2. skill 按操作步骤执行(取证镜像 / 解析日志 / 跑威胁情报)
3. 涉及破坏性操作前必须 ask user 确认
4. 完工后跑自检
5. 区分"防御性分析" vs "恶意代码审计"
1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)
2. 按 Agent 提示提供文件/镜像/日志/哈希
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
---
name: analyzing-malware-persistence-with-autoruns
description: Use Sysinternals Autoruns to systematically enumerate and analyze malware
persistence mechanisms across Windows registry run keys, scheduled tasks, services,
drivers, and startup locations. Use when hunting for persistence during Windows
incident response, triaging a compromised endpoint, or validating that malware
autostart entries have been fully identified and removed.
domain: cybersecurity
subdomain: malware-analysis
tags:
mitre_attack:
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
nist_csf:
---
Sysinternals Autoruns extracts data from hundreds of Auto-Start Extensibility Points (ASEPs) on Windows, scanning 18+ categories including Run/RunOnce keys, services, scheduled tasks, drivers, Winlogon entries, LSA providers, print monitors, WMI subscriptions, and AppInit DLLs. Digital signature verification filters Microsoft-signed entries. The compare function identifies newly added persistence via baseline diffing. VirusTotal integration checks hash reputation. Offline analysis via -z flag enables forensic disk image examination.
#!/usr/bin/env python3
"""Automate Autoruns-based persistence analysis."""
import subprocess
import csv
import json
import sys
def scan_and_analyze(autorunsc_path="autorunsc64.exe", csv_path="scan.csv"):
cmd = [autorunsc_path, "-a", "*", "-c", "-h", "-s", "-nobanner", "*"]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=600)
with open(csv_path, 'w') as f:
f.write(result.stdout)
return parse_and_flag(csv_path)
def parse_and_flag(csv_path):
suspicious = []
with open(csv_path, 'r', errors='replace') as f:
for row in csv.DictReader(f):
reasons = []
signer = row.get("Signer", "")
if not signer or signer == "(Not verified)":
reasons.append("Unsigned binary")
if not row.get("Description") and not row.get("Company"):
reasons.append("Missing metadata")
path = row.get("Image Path", "").lower()
for sp in ["\temp\\", "\appdata\local\temp", "\users\public\\"]:
if sp in path:
reasons.append(f"Suspicious path")
launch = row.get("Launch String", "").lower()
for kw in ["powershell", "cmd /c", "wscript", "mshta", "regsvr32"]:
if kw in launch:
reasons.append(f"LOLBin: {kw}")
if reasons:
row["reasons"] = reasons
suspicious.append(row)
return suspicious
if __name__ == "__main__":
if len(sys.argv) > 1:
results = parse_and_flag(sys.argv[1])
print(f"[!] {len(results)} suspicious entries")
for r in results:
print(f" {r.get('Entry','')} - {r.get('Image Path','')}")
for reason in r.get('reasons', []):
print(f" - {reason}")
本 skill 专注于Analyzing Malw,网络安全 skill: analyzing-malware-persistence-with-autoruns。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Analyzing Malware Persistence With Autoruns相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。
1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)
2. 按 Agent 提示提供文件/镜像/日志/哈希
3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"
4. 全程 Agent 自动化,你只需提供数据 + 回答决策点
---
本 skill 专注于Analyzing Malw,网络安全 skill: analyzing-malware-persistence-with-autoruns。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。
当你需要在Analyzing Malware Persistence With Autoruns相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。
需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。