Malware triage
Malware triage is the rapid assessment of a suspicious file to decide what it is, what it does, and how dangerous it is, without the full exhaustive analysis. In an incident, triage gives actionable answers (IOCs, family, capabilities) in minutes. It links to the Malware area (Static Malware Analysis/Dynamic Malware Analysis).
Triage goal
Section titled “Triage goal”- is it malicious? what family/type? (ransomware, stealer, RAT, loader...)- what does it do? (persistence, C2, encryption, theft) and with what capabilities- actionable IOCs NOW: hashes, C2 (domains/IPs), mutex, created files-> feed containment (dfir-incidentes), hunting (def-hunting), and TI (cti-ioc)Fast flow (safe, in an isolated lab)
Section titled “Fast flow (safe, in an isolated lab)”# 1. identifyfile sample ; sha256sum sample # type and hash# 2. reputation (by hash, NEVER upload the sample if it's confidential)VirusTotal / hash lookup; known? -> family and verdict# 3. basic static (see mal-static)strings / floss ; PE header (pefile) ; imports; packed? (entropy, DIE)# 4. rule-based detectionYARA rules (mal-yara) -> family/capabilities; capa -> capabilities by imports (MITRE)# 5. controlled dynamic (see mal-dynamic)sandbox (CAPE/Cuckoo/Any.run) or isolated lab with a simulated network -> behavior + IOCsSafe environment
Section titled “Safe environment”- isolated VM (no real network access), snapshots, simulated network (INetSim/FakeNet)- never run on a production machine or with corporate network access- if the sample is sensitive, OFFLINE analysis (don't upload to public services)What to extract (triage deliverables)
Section titled “What to extract (triage deliverables)”IOCs hashes, C2, URLs, mutex, file names, registry keysCapabilities persistence, injection/evasion (mal-evasion), encryption, C2 (mal-c2)Family via YARA/reputation -> TI context (cti-fund) and TTPs (cti-attack)Verdict malicious/suspicious/benign + priority for the IRIdentification DIE (Detect It Easy), pefile, exiftoolStatic strings/floss, capa, YARA (mal-yara), CyberChef (deobfuscate)Dynamic/sandbox CAPEv2, Cuckoo, Any.run, Joe Sandbox, Hybrid AnalysisDisassembly Ghidra/IDA (if you need to go deeper, see pwn-reversing)Blue Team / DFIR
Section titled “Blue Team / DFIR”- Triage is fast and actionable: IOCs and family first; deep analysis (reversing) later if needed.
- Always work in an isolated lab; protect the sample’s confidentiality.
- Triage IOCs trigger containment (Incident response) and hunting across the fleet (Threat hunting).
- Links to the Malware analysis cycle: static (Static Malware Analysis), dynamic (Dynamic Malware Analysis), YARA (YARA Rules).
Real-world cases
Section titled “Real-world cases”- Triage with YARA + sandbox identifies ransomware/loader families in minutes during an IR.
- Triage IOCs (C2, hashes) feed immediate blocking and retrospective hunting (Detection & logging).
- Services like Any.run/VirusTotal speed up triage, with the caveat of not uploading confidential samples.
Testing checklist
Section titled “Testing checklist”- Isolated lab with snapshots and a simulated network
- Identify type and hash (file/sha256)
- Reputation by hash (without uploading sensitive samples)
- Basic static (strings/floss, imports, packing)
- YARA + capa for family and capabilities
- Dynamic in a sandbox for behavior and IOCs
- Extract IOCs and verdict → containment/hunting/TI
- Escalate to reversing (pwn-reversing) if depth is needed