Back to workflows

Malware workflow

Review a malware reference defensively.

A workflow for reading malware names, hashes, and reports without operational misuse.

Passive and safe research workflow

When to use it

You have Malware name and want to check it through safe, legal, source-based research.

What you get

Defensive malware context note and IOC summary.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Define the reference

    Separate malware name, hash, report link, and IOC list.

    Check: The source type is clear.

  2. Read public reports

    Extract behavior summaries from open analysis reports.

    Check: No sample is downloaded or run.

  3. Separate IOC and TTP

    Keep domains, IPs, hashes, and behaviors in separate lists.

    Check: IOC dates are visible.

  4. Write defensive output

    Summarize detection or monitoring steps with confidence.

    Check: Misuse detail is not included.

Report language

The malware reference is handled as defensive context only; no execution, evasion, or abuse steps are included.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • Access Now Digital Security Helpline logo

    Access Now Digital Security Helpline

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • CISA Cybersecurity Best Practices logo

    CISA Cybersecurity Best Practices

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • EFF Surveillance Self-Defense logo

    EFF Surveillance Self-Defense

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • Freedom of the Press Foundation Training logo

    Freedom of the Press Foundation Training

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • MISP Project logo

    MISP Project

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source