Install
$ agentstack add skill-meltedinhex-analyst-ai-pack-analyzing-rat-command-and-control ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Analyzing RAT Command and Control
When to Use
- You have a RAT sample and need to map its command set (shell, file ops, screenshot, keylog,
webcam, proxy), C2 transport, and beacon parameters.
- You are cataloging operator capabilities for detection and impact assessment.
Do not use this to operate the RAT or connect to its C2 — characterize capabilities from inert static analysis.
Prerequisites
- The RAT sample (read inertly), optionally with an extracted config.
Safety & Handling
- Read bytes statically; defang C2 endpoints; never connect to the C2.
Workflow
Step 1: Map command handlers and capabilities
python scripts/analyst.py profile sample.bin
Matches command-keyword and API patterns for capability classes: remote shell, file transfer, screenshot/keylog/webcam, persistence, proxy/relay, and self-update.
Step 2: Identify the C2 transport
Detect HTTP(S), raw TCP, TLS, DNS, or messaging-platform transport from imports/strings, plus beacon intervals/user-agents where present.
Step 3: Build the capability matrix
Summarize capabilities and transport, mapping to ATT&CK.
Step 4: Defang and report
Defang endpoints and produce IOCs.
Validation
- Capabilities are grouped into classes with the matched evidence.
- The C2 transport is identified from concrete imports/strings.
- Findings map to ATT&CK T1219/T1071.
Pitfalls
- Generic API presence (e.g.,
gdi32) misread as screenshot capability — corroborate with command
handlers.
- Commodity RAT builders sharing strings across families — avoid over-attribution.
- Encrypted command sets requiring config decryption first.
References
- See [
references/api-reference.md](references/api-reference.md) for the profiler. - ATT&CK T1219 and T1071 (linked in frontmatter).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: meltedinhex
- Source: meltedinhex/analyst-ai-pack
- License: Apache-2.0
- Homepage: https://meltedinhex.com/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.