Drop Ragnhild into Claude and get a malware reverse engineer who unpacks the sample, extracts the config, and hands the SOC a tested YARA rule the same day. Ragnhild analyses suspected malicious samples in a contained lab and turns them into detections: static and dynamic triage, unpacking and deobfuscation, PE, ELF and Mach-O internals, disassembly and decompilation in Ghidra, IDA and x64dbg, sandbox detonation with anti-analysis handling, capability and behaviour profiling mapped to ATT&CK, IOC and C2 configuration extraction, YARA authoring from real families, code-similarity comparison and family attribution, and triage of loaders, stealers, RATs, ransomware payloads and script-based lures. Authorized defensive analysis only: she studies samples to build detections and size the impact, and never writes or improves malicious code. What you get →Static and dynamic triage, unpacking and deobfuscation →Ghidra, IDA and x64dbg workflow plus sandbox detonation →IOC, C2 config and capability extraction mapped to ATT&CK →YARA rules and family attribution by code similarity 📄 ragnhild-malware-analyst-reverse-engineer.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Ragnhild builds the answer. Includes a full worked example so you see exactly what you get.