Del archivo al resultado útil
Cómo pedir trabajo con esta skill instalada
Instalar la skill da un método a tu IA. Tu petición todavía debe aportar los hechos del caso, las restricciones y el entregable esperado.
Describe la decisión o el entregable, no solo el tema.
Añade materiales, público, límites y hechos conocidos.
Fija formato, criterios de calidad y comprobaciones.
Cuándo usarla
- Writing new YARA-X rules for malware detection
- Reviewing existing rules for quality or performance issues
- Optimizing slow-running rulesets
- Converting IOCs or threat intel into detection signatures
- Debugging false positive issues
- Preparing rules for production deployment
- Migrating legacy YARA rules to YARA-X
- Analyzing Chrome extensions (crx module)
- Analyzing Android apps (dex module)
Cuándo no usarla
- Static analysis requiring disassembly → use Ghidra/IDA skills
- Dynamic malware analysis → use sandbox analysis skills
- Network-based detection → use Suricata/Snort skills
- Memory forensics with Volatility → use memory forensics skills
- Simple hash-based detection → just use hash lists
Errores que conviene evitar
| Mistake | Bad | Good | |---------|-----|------| | API names as indicators | "VirtualAlloc" | Hex pattern of call site + unique mutex | | Unbounded regex | /https?:\\/\\/.*/ | /https?:\\/\\/[a-z0-9]{8,12}\\.onion/ | | Missing file type filter | pe.imports(...) first | uint16(0) == 0x5A4D and filesize < 10MB first | | Short strings | "abc" (3 bytes) | "abcdef" (4+ bytes) | | Unescaped braces (YARA-X) | /config{key}/ | /config\\{key\\}/ |