Skip to content

Malware triage

Malware triage is the rapid assessment of a suspicious file to decide what it is, what it does, and how dangerous it is, without the full exhaustive analysis. In an incident, triage gives actionable answers (IOCs, family, capabilities) in minutes. It links to the Malware area (Static Malware Analysis/Dynamic Malware Analysis).

- is it malicious? what family/type? (ransomware, stealer, RAT, loader...)
- what does it do? (persistence, C2, encryption, theft) and with what capabilities
- actionable IOCs NOW: hashes, C2 (domains/IPs), mutex, created files
-> feed containment (dfir-incidentes), hunting (def-hunting), and TI (cti-ioc)
# 1. identify
file sample ; sha256sum sample # type and hash
# 2. reputation (by hash, NEVER upload the sample if it's confidential)
VirusTotal / hash lookup; known? -> family and verdict
# 3. basic static (see mal-static)
strings / floss ; PE header (pefile) ; imports; packed? (entropy, DIE)
# 4. rule-based detection
YARA rules (mal-yara) -> family/capabilities; capa -> capabilities by imports (MITRE)
# 5. controlled dynamic (see mal-dynamic)
sandbox (CAPE/Cuckoo/Any.run) or isolated lab with a simulated network -> behavior + IOCs
- isolated VM (no real network access), snapshots, simulated network (INetSim/FakeNet)
- never run on a production machine or with corporate network access
- if the sample is sensitive, OFFLINE analysis (don't upload to public services)
IOCs hashes, C2, URLs, mutex, file names, registry keys
Capabilities persistence, injection/evasion (mal-evasion), encryption, C2 (mal-c2)
Family via YARA/reputation -> TI context (cti-fund) and TTPs (cti-attack)
Verdict malicious/suspicious/benign + priority for the IR
Identification DIE (Detect It Easy), pefile, exiftool
Static strings/floss, capa, YARA (mal-yara), CyberChef (deobfuscate)
Dynamic/sandbox CAPEv2, Cuckoo, Any.run, Joe Sandbox, Hybrid Analysis
Disassembly Ghidra/IDA (if you need to go deeper, see pwn-reversing)
  • Triage with YARA + sandbox identifies ransomware/loader families in minutes during an IR.
  • Triage IOCs (C2, hashes) feed immediate blocking and retrospective hunting (Detection & logging).
  • Services like Any.run/VirusTotal speed up triage, with the caveat of not uploading confidential samples.
  • Isolated lab with snapshots and a simulated network
  • Identify type and hash (file/sha256)
  • Reputation by hash (without uploading sensitive samples)
  • Basic static (strings/floss, imports, packing)
  • YARA + capa for family and capabilities
  • Dynamic in a sandbox for behavior and IOCs
  • Extract IOCs and verdict → containment/hunting/TI
  • Escalate to reversing (pwn-reversing) if depth is needed