Ragnhild — Malware Analyst & Reverse Engineer AI Skill
Instant download · 30-day money-back guarantee. Pay once, keep forever — no subscription. Refund policy
Analyse a malicious sample end to end: unpack it, extract the config and IOCs, and ship a tested YARA rule with an analyst report.
- Static and dynamic triage, unpacking and deobfuscation
- Ghidra, IDA and x64dbg workflow plus sandbox detonation
- IOC, C2 config and capability extraction mapped to ATT&CK
- YARA rules and family attribution by code similarity
Incident response and detection teams sitting on an unknown sample who need capability, IOCs and a detection rule fast.A senior malware reverse engineer bills $165+/hr, this is one file, yours forever.
Drop Ragnhild into Claude and get a malware reverse engineer who unpacks the sample, extracts the config, and hands the SOC a tested YARA rule the same day.
Ragnhild analyses suspected malicious samples in a contained lab and turns them into detections: static and dynamic triage, unpacking and deobfuscation, PE, ELF and Mach-O internals, disassembly and decompilation in Ghidra, IDA and x64dbg, sandbox detonation with anti-analysis handling, capability and behaviour profiling mapped to ATT&CK, IOC and C2 configuration extraction, YARA authoring from real families, code-similarity comparison and family attribution, and triage of loaders, stealers, RATs, ransomware payloads and script-based lures. Authorized defensive analysis only: she studies samples to build detections and size the impact, and never writes or improves malicious code.
What you get
- →Static and dynamic triage, unpacking and deobfuscation
- →Ghidra, IDA and x64dbg workflow plus sandbox detonation
- →IOC, C2 config and capability extraction mapped to ATT&CK
- →YARA rules and family attribution by code similarity
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Ragnhild builds the answer. Includes a full worked example so you see exactly what you get.
# Ragnhild - Malware Analyst & Reverse Engineer You are Ragnhild, a senior malware analyst and reverse engineer. You work only on samples the client is authorized to hold, in an isolated lab, and your output is detection and impact, never new malicious code. ## How you work 1. Confirm authorization and lab isolation before the sample is opened 2. Static triage first: hashes, format, imports, strings, packer indicators 3. Unpack and deobfuscate, then detonate to confirm behaviour 4. Extract config, C2 and capabilities; map to ATT&CK 5. Write and test a YARA rule against a clean corpus before shipping it Authorized defensive analysis only. Validate every IOC in your own environment before acting on it.
Excerpt from the actual file you'll download.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot — whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required. No subscription. Pay once, keep forever.
Works with every major AI chat.
Drop the file into your AI's system prompt, Project instructions, or custom instructions. No setup. No code. No vendor lock-in.
- Claude
- ChatGPT
- Gemini
- Grok
- Copilot
Works with any AI chat that accepts a system prompt or custom instructions.
Ready to specialise your AI?
One drop-in file. Pay once, keep forever — works with Claude & ChatGPT.