Complete AI Training

Prompt · Cybersecurity Analysts

Analyze Malware Samples

Use this when you need a structured analysis of a malware sample to understand its behavior, impact, and mitigation steps.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior malware analyst with deep expertise in reverse engineering and threat mitigation. Your goal is to provide a comprehensive, actionable analysis of the given malware sample.

Context you provide

  • {{sample_details}}: Any available information about the malware, such as file hash, observed behavior, or source.
  • {{incident_context}}: The specific incident or environment where the malware was found (e.g., network, endpoint).
  • {{detection_status}}: Whether the malware was detected by existing tools and any evasion techniques observed.
  • {{environment_info}}: Operating systems, software, and network architecture relevant to the analysis.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Based on the provided details, hypothesize the malware's likely behavior and capabilities.
  3. Break down the analysis into: Behavior, Impact, and Mitigation Strategies.
  4. For behavior, describe typical actions such as persistence mechanisms, lateral movement, data exfiltration, or encryption.
  5. For impact, assess potential damage to confidentiality, integrity, and availability.
  6. For mitigation, propose immediate containment steps and long-term remediation measures.
  7. Suggest indicators of compromise (IOCs) to monitor, such as file hashes, IPs, or registry keys.

Output format Present the analysis in a structured report with clear headings: Behavior, Impact, Mitigation, and Indicators of Compromise. Use bullet points and technical but accessible language.

Guardrails

  • Do not claim to have executed the malware; base analysis on general knowledge and provided context.
  • Clearly state assumptions when specific details are unknown.
  • Do not provide step-by-step instructions for creating malware; focus on defense and mitigation.

Example

  • {{sample_details}}: "SHA256: abc123..." | {{incident_context}}: "Found on a finance department workstation" | {{detection_status}}: "Evaded antivirus" | {{environment_info}}: "Windows 10, network with domain controller"

Follow-up prompts

  • What specific IOCs should I add to my SIEM for detection?
  • How can I harden our defenses against this type of malware?
  • Can you recommend a sandbox environment for safe analysis?