Malware analysis and threat intelligence — unpacking, configuration extraction, behavior profiling, C2 protocol decoding, IOC extraction, YARA/Sigma rule authoring, and detection engineering. Use when the workspace contains a suspicious sample, a memory dump with injected code, or PCAP with C2 traffic, or the task involves sandbox triage, family classification, TTP mapping, or detection rule development. 处理恶意软件、恶意样本、样本分析、木马分析、病毒分析、C2分析、脱壳分析、威胁分析、IOC、YARA、应急响应时使用。
获得授权的协作者可安装: