Skip to content
Back to skills

Extracting Iocs From Malware Samples

ASecurity

Use when extracts indicators of compromise (IOCs) from malware samples

  • 12 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 8, 2026
ai-agentspythonrustgotestinggitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 8, 2026

npx -y skills add oyi77/1ai-skills --skill extracting-iocs-from-malware-samples --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Extracting Iocs From Malware Samples?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Extracting Iocs From Malware Samples
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/oyi77-extracting-iocs-from-malware-samples/badge)](https://www.skillsdirectory.com/skills/oyi77-extracting-iocs-from-malware-samples)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: extracting-iocs-from-malware-samples
description: Use when extracts indicators of compromise (IOCs) from malware samples
  including file hashes, network indicators (IPs, domains, URLs), host artifacts (file
  paths, registry keys, mutexes), and behavioral patterns for threat intelligence
  sharing and detection rule creation. Activates for requests involving IOC extraction,
  threat indicator harvesting, malware indicator collection, or building detection
  content from samples. . Use when working with extracting iocs from malware samples.
domain: cybersecurity
tags:
- malware
- IOC-extraction
- threat-intelligence
- indicators
- detection
subdomain: malware-analysis
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- DE.AE-02
- RS.AN-03
- ID.RA-01
- DE.CM-01
category: cybersecurity
---

# Extracting Iocs From Malware Samples

## Overview

Cybersecurity skill for extracting iocs from malware samples. Follows industry best practices and security standards.

## When to Use
**Trigger phrases:**
- "extracting iocs from malware samples"
- "Extracts indicators of compromise (IOCs) from malware samples including file has"


- A malware analysis (static or dynamic) is complete and actionable indicators need to be extracted for defense teams
- Building blocklists for firewalls, proxies, and DNS sinkholes from analyzed samples
- Creating YARA rules, Snort/Suricata signatures, or SIEM detection content from malware artifacts
- Contributing to threat intelligence sharing platforms (MISP, OTX, ThreatConnect)
- Tracking malware campaigns by correlating IOCs across multiple samples

**Do not use** for IOCs from unverified sources without validation; false positives in blocklists can disrupt legitimate business operations.


## When NOT to Use

- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope


## Prerequisites

- Python 3.8+ with `iocextract`, `pefile`, `yara-python` libraries installed
- Completed malware analysis report (static analysis, dynamic analysis, or reverse engineering)
- Access to PCAP files, memory dumps, or sandbox reports from the analysis
- MISP instance or STIX/TAXII server for structured IOC sharing
- VirusTotal API key for IOC enrichment and validation
- CyberChef for decoding obfuscated indicators

## Workflow

```python
# Example: IOC detection
import re

IOC_PATTERNS = {
    "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
    "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
    "hash_md5": r"\b[a-f0-9]{32}\b",
    "hash_sha256": r"\b[a-f0-9]{64}\b",
}

def extract_iocs(text: str) -> dict:
    return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```

1. **Define Objectives** — Clarify the goals and scope for iocs from malware samples.
2. **Gather Resources** — Collect tools, data, and access needed for iocs from malware samples.
3. **Execute Process** — Carry out iocs from malware samples operations methodically.
4. **Verify Quality** — Check results against acceptance criteria.
5. **Document Outcomes** — Record findings, decisions, and next steps.

## Tools

- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing


## Process

1. **Reconnaissance** — Gather target information, identify attack surface, enumerate services
1. **Analysis/Exploitation** — Execute the technique, analyze results, document findings
1. **Reporting** — Document IOCs, write findings, provide remediation recommendations

## Verification

- [ ] All iocs from malware samples procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization

## Anti-Rationalization Table

| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…