What problem does it solve? Security analysts need to turn scattered public threat intelligence—hashes, IOCs, sandbox reports, and vendor write-ups—into a traceable, evidence-graded assessment of a malware family without ever handling live samples. This Skill structures that research workflow and separates confirmed facts from speculation. ## Core Features & Use Cases - Family and IOC Analysis: Normalizes malware family names and aliases, validates and deduplicates IOCs, and maps observed behavior to MITRE ATT&CK techniques with evidence and confidence levels. - Evidence-Graded Reporting: Produces a fixed-structure report covering infection chain, ATT&CK mapping, IOC freshness and false-positive risk, detection hypotheses, alternative explanations, and prioritized response actions. - Taiwan Financial Sector Module: Loads a dedicated reference when the analysis involves Taiwanese banks, insurers, or securities firms, adding industry-specific exposure analysis and compliance checkpoints. - Use Case: A SOC analyst receives a SHA256 hash flagged in an alert. The Skill cross-checks public sources like MalwareBazaar and URLhaus, identifies the likely family and its ATT&CK techniques, and delivers detection hunting ideas plus a 24-hour and 7-day action plan. ## Quick Start Analyze this malware family and its IOCs using only public threat intelligence, then provide detection and response recommendations for a Taiwan financial institution.