.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/meltedinhex/analyst-ai-pack
home/skills/meltedinhex/analyst-ai-pack
meltedinhex avatar

meltedinhex/analyst-ai-pack

59 skills

View on GitHub
$npx skills add meltedinhex/analyst-ai-pack
SkillInstalls
analyzing-android-dex-malwareReverses Android malware: unpacking APKs, decompiling DEX bytecode to readable—analyzing-api-call-tracesAnalyzes API call traces from a sandbox or API monitor (JSON) to group calls by—analyzing-authenticode-signaturesAnalyzes Windows Authenticode signatures on PE files: checking for a signature,—analyzing-banking-trojan-webinjectsAnalyzes banking trojan webinject configurations to extract targeted institutions,—analyzing-compiled-python-malwareAnalyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting—analyzing-cryptominer-malwareAnalyzes cryptojacking/coinminer malware by extracting mining pool endpoints—analyzing-dotnet-malware-internalsReverses .NET/managed malware: decompiling MSIL back to C#, defeating common—analyzing-elf-binaries-on-linuxStatically analyzes Linux ELF malware: ELF header and sections, dynamic symbols—analyzing-excel-4-macro-malwareAnalyzes legacy Excel 4.0 (XLM) macro malware by parsing extracted macro-sheet—analyzing-golang-malware-internalsAnalyzes Go-compiled malware by recovering function names from the pclntab, detecting—analyzing-infostealer-credential-theftAnalyzes infostealer samples by mapping the browser, credential store, wallet, and—analyzing-java-jar-malwareAnalyzes Java/JAR malware (such as Adwind/jRAT-class cross-platform RATs) by—analyzing-loaders-and-droppersAnalyzes loader and dropper samples by identifying staging behavior — embedded or—analyzing-mach-o-binaries-on-macosStatically analyzes macOS Mach-O malware: parsing the header and load commands,—analyzing-malicious-iso-and-container-filesAnalyzes malicious ISO, IMG, VHD, and similar container files used to smuggle payloads—analyzing-malicious-lnk-filesAnalyzes weaponized Windows shortcut (.lnk) files: parsing the shell link structure—analyzing-malicious-office-macrosAnalyzes malicious Office documents by extracting and reviewing VBA macros and—analyzing-malicious-onenote-and-html-smugglingAnalyzes two modern delivery techniques: malicious OneNote (.one) attachments with—analyzing-malicious-pdfsAnalyzes malicious PDF documents: parsing the object structure for JavaScript,—analyzing-malicious-vbscript-and-wsfAnalyzes malicious VBScript, WSF, and HTA scripts: parsing WSF/HTA containers,—analyzing-malware-in-memory-with-volatility3Analyzes a memory image with Volatility 3 to find malware: rogue processes,—analyzing-pe-imports-and-exportsAnalyzes a PE file''s import and export tables to infer capability: mapping imported—analyzing-position-independent-codeAnalyzes position-independent code and shellcode by identifying GetPC/PEB-walk—analyzing-ransomware-encryption-behaviorAnalyzes how a ransomware sample encrypts files: identifying the crypto scheme—analyzing-rat-command-and-controlAnalyzes remote access trojan command-and-control by mapping the RAT command set,—analyzing-rich-header-and-compiler-artifactsAnalyzes the PE Rich header and related compiler artifacts to fingerprint the build—analyzing-rust-malware-internalsAnalyzes Rust-compiled malware by detecting the Rust toolchain signature, demangling—analyzing-webshellsAnalyzes suspected webshells (PHP, ASPX/ASP, JSP) by detecting dynamic-execution—analyzing-windows-driver-malwareAnalyzes malicious and vulnerable Windows kernel drivers (.sys) by parsing the PE for—analyzing-wiper-malwareAnalyzes destructive wiper malware by identifying raw-disk and MBR/VBR overwrite—automating-analysis-with-r2pipeAutomates radare2/rizin analysis through r2pipe to script function enumeration, string—building-a-sample-management-workflowEstablishes a disciplined malware sample repository: content-addressed storage by—building-a-threat-hunt-hypothesisFrames a structured, testable threat-hunting hypothesis: grounding it in adversary—building-config-extractorsBuilds reusable malware configuration extractors by applying a declarative JSON spec—building-zeek-analytics-for-huntingBuilds Zeek-based network hunting analytics by writing scripts and analyzing Zeek logs—bypassing-anti-vm-and-sandbox-checksBypasses anti-VM and sandbox checks during analysis by locating the specific detection—capturing-and-analyzing-malware-network-trafficCaptures and analyzes malware network traffic from a detonation: extracting C2—collecting-volatile-evidence-from-a-suspect-hostCollects volatile evidence from a potentially compromised host in correct order of—debugging-malware-with-x64dbgUses x64dbg to dynamically debug Windows malware: setting strategic breakpoints—decrypting-embedded-configurationDecrypts statically embedded malware configuration blobs by trying common schemes—defanging-and-sharing-iocsPrepares indicators of compromise for safe sharing: defanging URLs, domains, IPs,—defeating-control-flow-flatteningDefeats control-flow-flattening obfuscation by identifying the dispatcher/state-—defeating-string-and-api-obfuscationRecovers obfuscated strings and resolves dynamically loaded APIs in malware:—deobfuscating-malicious-javascriptDeobfuscates malicious JavaScript from droppers, web pages, and HTA/scriptlets:—deobfuscating-malicious-powershellDeobfuscates malicious PowerShell by decoding -EncodedCommand, reversing string—detecting-process-injection-in-memoryDetects process injection in a memory image by identifying private executable regions—detecting-sandbox-evasion-behaviorDetects sandbox and analysis evasion techniques in a sample by scanning static—diffing-malware-samples-to-find-changesCompares two related malware samples to surface what changed between variants using—dissecting-boot-and-kernel-rootkitsAnalyzes bootkit and rootkit samples by identifying boot-process tampering (MBR/VBR/—dumping-and-rebuilding-a-pe-from-memoryRebuilds a usable PE file from a memory dump by fixing the section alignment—emulating-shellcode-with-unicornEmulates position-independent shellcode in a controlled CPU emulator (Unicorn) to—enriching-iocs-with-threat-intel-sourcesEnriches indicators with context from threat-intel sources: planning lookups against—establishing-telemetry-baselinesEstablishes behavioral baselines from historical telemetry (process, network, or—extracting-and-classifying-stringsExtracts ASCII and Unicode strings from a binary and classifies them into—extracting-cobalt-strike-beacon-configExtracts and interprets a Cobalt Strike Beacon configuration: decoding the—extracting-config-from-a-running-sampleExtracts an embedded malware configuration (C2 hosts, ports, campaign IDs, keys) from—extracting-encryption-keys-from-binariesLocates candidate encryption keys in a binary by finding high-entropy fixed-size—extracting-iocs-from-analysis-outputExtracts indicators of compromise from raw analysis artifacts: parsing strings—generating-capability-reports-with-capaUses capa to identify malware capabilities from a binary: running rule-based—