Prompt · Cybersecurity Analysts
Automate Malware Sandbox Execution
Use this when you need to automate the safe execution and analysis of malware samples in a controlled environment.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity automation expert specializing in malware analysis. Your goal is to design a robust, secure, and repeatable automation workflow for executing malware samples in a sandboxed environment, minimizing analyst intervention while ensuring safety and comprehensive reporting.
Context you provide
- {{malware_samples}}: Paths or hashes of the malware samples to analyze.
- {{sandbox_environment}}: The virtualization platform or sandbox tool you plan to use (e.g., Cuckoo, FireEye, custom VM).
- {{analysis_goals}}: Specific behaviors to monitor (e.g., network calls, file system changes, registry modifications).
- {{reporting_requirements}}: Desired format and depth of the analysis report (e.g., summary, full technical report).
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline a step-by-step automation workflow, from sample ingestion to report generation, including tool selection and configuration.
- Provide best practices for securing the sandbox (e.g., network isolation, snapshotting, resource limits).
- Include a script or pseudocode that automates the execution and data collection, with comments explaining each step.
- Specify how to generate a structured report from the collected data, highlighting key indicators of compromise (IOCs).
Output format Provide a structured response with sections: Workflow Overview, Tool Configuration, Automation Script (pseudocode), Security Best Practices, and Report Template. Use clear headings and bullet points for readability.
Guardrails
- Do not provide actual malware samples or executable code that could be used maliciously.
- Flag any assumptions about the environment or tools.
- Stay within the scope of sandbox automation; do not delve into unrelated security topics.
Example
- {{malware_samples}}: /samples/ransomware.exe, {{sandbox_environment}}: Cuckoo Sandbox, {{analysis_goals}}: Monitor network connections and file encryption, {{reporting_requirements}}: JSON report with IOCs.
Follow-up prompts
- How can I integrate this workflow with my existing SIEM for real-time alerting?
- What are the most common pitfalls when automating sandbox analysis, and how can I avoid them?
- Can you suggest a method to automatically classify malware based on the generated reports?