<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Anushkairis</title>
    <description>The latest articles on DEV Community by Anushkairis (@anushkairis).</description>
    <link>https://dev.to/anushkairis</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4147147%2F609619d8-c269-4cb6-a5c0-90f9e1ebf272.png</url>
      <title>DEV Community: Anushkairis</title>
      <link>https://dev.to/anushkairis</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/anushkairis"/>
    <language>en</language>
    <item>
      <title>Building a Malware Pre-Triage Pipeline with TrID, Capa, and Shannon Entropy</title>
      <dc:creator>Anushkairis</dc:creator>
      <pubDate>Mon, 28 Sep 2026 14:44:22 +0000</pubDate>
      <link>https://dev.to/anushkairis/building-a-malware-pre-triage-pipeline-with-trid-capa-and-shannon-entropy-4ii7</link>
      <guid>https://dev.to/anushkairis/building-a-malware-pre-triage-pipeline-with-trid-capa-and-shannon-entropy-4ii7</guid>
      <description>&lt;p&gt;&lt;strong&gt;How a simple entropy-based malware detector evolved into a multi-signal analysis workflow&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;While learning about malware analysis workflows, I kept coming back to the same question:&lt;/p&gt;

&lt;p&gt;Do we really need to send every uploaded file into a sandbox before deciding whether it's worth investigating?&lt;/p&gt;

&lt;p&gt;Dynamic analysis provides valuable visibility into process creation, network communication, persistence mechanisms, registry modifications, and other behaviors that static analysis cannot easily observe.&lt;/p&gt;

&lt;p&gt;The downside is that dynamic analysis is expensive. Running every file through a sandbox consumes time, infrastructure, and analyst attention.&lt;/p&gt;

&lt;p&gt;To explore whether some triage decisions could be made earlier, I built a proof-of-concept malware pre-triage pipeline that combines:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;TrID for file identification&lt;/li&gt;
&lt;li&gt;Shannon Entropy for randomness analysis&lt;/li&gt;
&lt;li&gt;Mandiant Capa for capability extraction&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The analysis components were validated locally, while the overall architecture was designed around an event-driven AWS deployment model.&lt;/p&gt;

&lt;p&gt;This article covers the design decisions, mistakes I made, lessons learned, and how the workflow evolved during testing.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frthzlmblpkmy4awsnoi8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frthzlmblpkmy4awsnoi8.png" alt="Architecture overview" width="800" height="774"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Initial Assumption&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;My first implementation was deliberately simple.&lt;/p&gt;

&lt;p&gt;The logic looked something like this:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;if entropy &amp;gt; 7.2:&lt;br&gt;
    quarantine()&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;At first, it seemed reasonable.&lt;/p&gt;

&lt;p&gt;Packed, encrypted, and obfuscated malware often exhibits elevated entropy because the byte stream appears more random.&lt;/p&gt;

&lt;p&gt;On paper, a high entropy threshold looked like a quick way to identify suspicious files.&lt;/p&gt;

&lt;p&gt;Then I started testing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Problem With Entropy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The first thing I discovered was that entropy alone generates a lot of noise.&lt;/p&gt;

&lt;p&gt;Many completely legitimate files produced entropy values above my threshold:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ZIP archives&lt;/li&gt;
&lt;li&gt;Software installers&lt;/li&gt;
&lt;li&gt;Compressed documents&lt;/li&gt;
&lt;li&gt;Packaged applications&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;File Type&lt;/th&gt;
&lt;th&gt;Entropy Trend&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Plain Text&lt;/td&gt;
&lt;td&gt;Low&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ZIP Archive&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Packed Executable&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Encrypted File&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The problem became obvious.&lt;/p&gt;

&lt;p&gt;A compressed archive and an encrypted malware payload can produce very similar entropy values despite representing completely different security risks.&lt;/p&gt;

&lt;p&gt;At that point, entropy stopped being useful as a standalone verdict mechanism.&lt;/p&gt;

&lt;p&gt;The challenge shifted from threat detection to false-positive reduction.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Understanding Shannon Entropy&lt;/strong&gt;&lt;br&gt;
Shannon Entropy measures statistical randomness within a dataset.&lt;/p&gt;

&lt;p&gt;The formula is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Entropy = -Σ P(x) log₂ P(x)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Where:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;P(x) represents the probability of a specific byte value occurring within the file.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Entropy values generally range between:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;0.0&lt;/td&gt;
&lt;td&gt;Highly predictable data&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8.0&lt;/td&gt;
&lt;td&gt;Highly random data&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;In malware analysis, elevated entropy may indicate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Packing&lt;/li&gt;
&lt;li&gt;Compression&lt;/li&gt;
&lt;li&gt;Encryption&lt;/li&gt;
&lt;li&gt;Obfuscation&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The important word is &amp;gt; may.&lt;/p&gt;

&lt;p&gt;Entropy describes the structure of data, not whether that data is malicious.&lt;/p&gt;

&lt;p&gt;That distinction became one of the most important lessons of the project.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why I Added TrID&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Once entropy proved insufficient on its own, I needed more context.&lt;/p&gt;

&lt;p&gt;The first question became:&lt;br&gt;
What is this file actually supposed to be?&lt;/p&gt;

&lt;p&gt;Initially, I considered relying on file extensions.&lt;/p&gt;

&lt;p&gt;That quickly seemed unreliable.&lt;/p&gt;

&lt;p&gt;A file named:&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;strong&gt;invoice.pdf&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;might actually contain:&lt;br&gt;
&lt;strong&gt;&lt;em&gt;Win32 Portable Executable&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;if intentionally disguised.&lt;/p&gt;

&lt;p&gt;To address this, I integrated TrID.&lt;br&gt;
TrID identifies files using internal signatures rather than trusting filenames.&lt;/p&gt;

&lt;p&gt;This provided several benefits:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Accurate file identification&lt;/li&gt;
&lt;li&gt;Detection of extension spoofing&lt;/li&gt;
&lt;li&gt;Better interpretation of entropy results&lt;/li&gt;
&lt;li&gt;Additional context for analysts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;Filename: invoice.pdf&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;TrID Result:&lt;br&gt;
&lt;strong&gt;&lt;em&gt;85.4% (.EXE) Win32 Executable&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That immediately raises questions worth investigating.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Introducing Capa&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;At this point, I could identify file types and measure randomness.&lt;/p&gt;

&lt;p&gt;However, another important question remained:&lt;br&gt;
What can this executable actually do?&lt;/p&gt;

&lt;p&gt;To answer that, I integrated Mandiant Capa.&lt;/p&gt;

&lt;p&gt;Capa analyzes executable code and identifies capabilities associated with known behaviors.&lt;/p&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Credential access&lt;/li&gt;
&lt;li&gt;Registry modification&lt;/li&gt;
&lt;li&gt;Persistence mechanisms&lt;/li&gt;
&lt;li&gt;Defense evasion&lt;/li&gt;
&lt;li&gt;Anti-analysis techniques&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Rather than looking only at file structure, Capa provides behavioral context.&lt;/p&gt;

&lt;p&gt;A file exhibiting elevated entropy and multiple suspicious capabilities is generally more interesting than a file exhibiting elevated entropy alone.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Workflow That Emerged&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;By the end of local testing, the workflow looked very different from the original entropy-only design.&lt;/p&gt;

&lt;p&gt;The analysis process became:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;File&lt;/strong&gt;&lt;br&gt;
 │&lt;br&gt;
 ▼&lt;br&gt;
&lt;strong&gt;TrID File Identification&lt;/strong&gt;&lt;br&gt;
 │&lt;br&gt;
 ▼&lt;br&gt;
&lt;strong&gt;Shannon Entropy Analysis&lt;/strong&gt;&lt;br&gt;
 │&lt;br&gt;
 ▼&lt;br&gt;
&lt;strong&gt;Capa Capability Extraction&lt;/strong&gt;&lt;br&gt;
 │&lt;br&gt;
 ▼&lt;br&gt;
&lt;strong&gt;Risk Evaluation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Instead of relying on a single indicator, the workflow combines multiple signals:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Signal 1: File Identity&lt;/strong&gt;&lt;br&gt;
What is the file actually?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Signal 2: Entropy&lt;/strong&gt;&lt;br&gt;
Does the file exhibit characteristics associated with compression, packing, encryption, or obfuscation?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Signal 3: Capability Matches&lt;/strong&gt;&lt;br&gt;
Does the executable contain capabilities that warrant additional investigation?&lt;/p&gt;

&lt;p&gt;No single signal is treated as a definitive answer.&lt;br&gt;
Each contributes context.&lt;/p&gt;

&lt;p&gt;Current Implementation&lt;br&gt;
The current proof-of-concept uses:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Shannon Entropy calculations&lt;/li&gt;
&lt;li&gt;TrID file identification&lt;/li&gt;
&lt;li&gt;Capa capability extraction&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The local decision logic currently relies primarily on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Entropy threshold evaluation&lt;/li&gt;
&lt;li&gt;Capa rule-match counts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;TrID currently provides identification and analyst context, while future iterations could incorporate file-type-aware decision making directly into the risk evaluation process.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why AWS Lambda?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Although testing was performed locally, the architecture was designed around AWS Lambda from the beginning.&lt;/p&gt;

&lt;p&gt;File uploads are naturally event-driven.&lt;/p&gt;

&lt;p&gt;When a new object arrives:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Upload triggers an event.&lt;/li&gt;
&lt;li&gt;Analysis begins automatically.&lt;/li&gt;
&lt;li&gt;Results are generated.&lt;/li&gt;
&lt;li&gt;Suspicious files can be routed for deeper investigation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Potential advantages include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Event-driven execution&lt;/li&gt;
&lt;li&gt;Automatic scaling&lt;/li&gt;
&lt;li&gt;Reduced infrastructure management&lt;/li&gt;
&lt;li&gt;Pay-per-use economics&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For lightweight static triage, serverless architecture aligns well with the workload.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- Operational Considerations&lt;/strong&gt;&lt;br&gt;
Several practical considerations emerged during the design process.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- Dependency Packaging&lt;/strong&gt;&lt;br&gt;
Both TrID and Capa require additional binaries and supporting resources.&lt;br&gt;
Packaging those dependencies for deployment requires planning.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- Cold Starts&lt;/strong&gt;&lt;br&gt;
Serverless environments introduce initialization overhead when loading analysis tools and rule sets.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- File Size Constraints&lt;/strong&gt;&lt;br&gt;
Large archives and software packages may require alternative processing strategies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- False Positives&lt;/strong&gt;&lt;br&gt;
False positives remain unavoidable when working with static indicators.&lt;/p&gt;

&lt;p&gt;The goal is not perfect detection.&lt;br&gt;
The goal is prioritization.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Future Improvements&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If I continue developing this project, I would like to explore:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Automated archive extraction&lt;/li&gt;
&lt;li&gt;Digital signature validation&lt;/li&gt;
&lt;li&gt;Threat intelligence enrichment&lt;/li&gt;
&lt;li&gt;Risk scoring models&lt;/li&gt;
&lt;li&gt;SIEM integration&lt;/li&gt;
&lt;li&gt;SOAR workflows&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Rather than generating simple "clean" or "suspicious" outcomes, future versions could produce weighted risk scores derived from multiple signals.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Takeaways&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The biggest lesson from this project was that security decisions become more reliable when multiple weak signals are combined.&lt;/p&gt;

&lt;p&gt;I learned that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Entropy alone generates excessive false positives.&lt;/li&gt;
&lt;li&gt;File identification alone cannot establish intent.&lt;/li&gt;
&lt;li&gt;Capability extraction alone lacks sufficient context.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Combining all three creates a more useful first-pass assessment workflow.&lt;/p&gt;

&lt;p&gt;Although this remains a locally validated proof-of-concept, the underlying principle is broadly applicable:&lt;/p&gt;

&lt;p&gt;Establish context early, prioritize intelligently, and reserve expensive investigative resources for the cases that genuinely require deeper analysis.&lt;/p&gt;

&lt;p&gt;Source Code&lt;br&gt;
GitHub Repository:(&lt;a href="https://github.com/Anushkairis/serverless-malware-triage-aws" rel="noopener noreferrer"&gt;https://github.com/Anushkairis/serverless-malware-triage-aws&lt;/a&gt;)&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>python</category>
      <category>malwareanalysis</category>
      <category>aws</category>
    </item>
  </channel>
</rss>
