Skill collection

mukul975/Anthropic-Cybersecurity-Skills agent skills

Every skill in the mukul975/Anthropic-Cybersecurity-Skills repository on GitHub, ranked by score, with the commands to install them.
skills
644
GitHub stars
34k
Collection

GitHub description: “817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0”

Stars
34,116 (4,149 forks)
Licence
Apache-2.0
Last push
Aug 2026
Created
Feb 2026
  • ai-agents
  • claude-code
  • cybersecurity
  • incident-response
  • mitre-attack
  • penetration-testing
  • red-team
  • security
  • cloud-security
  • malware-analysis
  • devsecops
  • ethical-hacking
  • infosec
  • llm
  • mcp
  • osint

Install all skills

skills CLI (any agent)
npx skills add mukul975/Anthropic-Cybersecurity-Skills

Add --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).

Skills in mukul975/Anthropic-Cybersecurity-Skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills in mukul975/Anthropic-Cybersecurity-Skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
2

Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
3

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
4

Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
5

Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
6

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
7

Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
8

Reconstructs folder browsing history from Windows Shellbag registry data using SBECmd and Shellbags Explorer, even for folders that were later deleted.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
9

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
10

Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
11

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.01 mo ago
12

Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
13

Build structured communication templates for malware incidents (ransomware, wiper, trojan, worm), covering internal stakeholder notifications, executive briefings, technical advisories for IT teams…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
14

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
15

Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis, to discover optimal RBAC roles from existing user-permission assignments…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
16

Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
17

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender…

mukul975/Anthropic-Cybersecurity-Skills34k—~893Automated safety check: PassApache-2.01 mo ago
18

Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
19

Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
20

Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
21

Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
22

Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
23

Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: NotesApache-2.01 mo ago
24

Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
25

Configure AWS Verified Access to provide VPN-less zero trust network access to internal apps, combining identity trust providers (IAM Identity Center, Okta/OIDC), device posture providers…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: PassApache-2.01 mo ago
26

Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL…

mukul975/Anthropic-Cybersecurity-Skills34k—~879Automated safety check: PassApache-2.01 mo ago
27

Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
28

Configures Hardware Security Modules for cryptographic key storage using the PKCS11 standard interface, covering key generation, signing, encryption, and key management on physical HSMs and SoftHSM2…

mukul975/Anthropic-Cybersecurity-Skills34k—~984Automated safety check: PassApache-2.01 mo ago
29

Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, including IAM bindings, Access Context…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
30

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
31

Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.01 mo ago
32

Configures Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring identity- and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.01 mo ago
33

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
34

Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.01 mo ago
35

Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: NotesApache-2.01 mo ago
36

Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
37

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
38

Build automated AWS GuardDuty finding response pipelines using EventBridge and Lambda to trigger real-time incident response, automatically quarantine compromised resources, and route security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
39

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
40

Detects unauthorized runtime drift in containers by monitoring binary execution, filesystem changes, and configuration deviation from the original immutable image, using Falco and Microsoft Defender…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
41

Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
42

Writes and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: NotesApache-2.01 mo ago
43

Detect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
44

Detect DLL side-loading and search-order hijacking (MITRE T1574) where adversaries plant malicious DLLs for legitimate signed applications to load, by analyzing Sysmon Event ID 7 DLL-load events…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.1kAutomated safety check: PassApache-2.01 mo ago
45

Detect malicious inbox/mail-flow forwarding rules that adversaries create to maintain persistent access to email communications for intelligence collection and business email compromise.

mukul975/Anthropic-Cybersecurity-Skills34k—~918Automated safety check: PassApache-2.01 mo ago
46

Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.01 mo ago
47

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
48

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.

mukul975/Anthropic-Cybersecurity-Skills34k—~897Automated safety check: PassApache-2.01 mo ago

Questions, answered from the data.

What is the best skill in mukul975/Anthropic-Cybersecurity-Skills?

Campaign Attribution Evidence Analysis from mukul975/Anthropic-Cybersecurity-Skills ranks first of the 644 skills in mukul975/Anthropic-Cybersecurity-Skills listed here, with the highest score: its repository has 34k GitHub stars, its SKILL.md loads about 2.3k tokens and it passes the automated safety check with no findings. Next come Go Malware Analysis in Ghidra and LNK and Jump List Forensics.

Are the skills in mukul975/Anthropic-Cybersecurity-Skills official?

None yet. All 644 skills in mukul975/Anthropic-Cybersecurity-Skills listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How do I install all skills from mukul975/Anthropic-Cybersecurity-Skills?

Run npx skills add mukul975/Anthropic-Cybersecurity-Skills in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.