Skill collection

mukul975/Anthropic-Cybersecurity-Skills agent skills, page 11

Skills #481–528 of 644, ranked by score.

Skills in mukul975/Anthropic-Cybersecurity-Skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills in mukul975/Anthropic-Cybersecurity-Skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
481

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns.

mukul975/Anthropic-Cybersecurity-Skills34k—~543Automated safety check: PassApache-2.01 mo ago
482

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets.

mukul975/Anthropic-Cybersecurity-Skills34k—~626Automated safety check: PassApache-2.01 mo ago
483

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
484

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
485

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string…

mukul975/Anthropic-Cybersecurity-Skills34k—~719Automated safety check: PassApache-2.01 mo ago
486

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.

mukul975/Anthropic-Cybersecurity-Skills34k—~666Automated safety check: PassApache-2.01 mo ago
487

Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.01 mo ago
488

Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and…

mukul975/Anthropic-Cybersecurity-Skills34k—~796Automated safety check: PassApache-2.01 mo ago
489

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
490

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
491

Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
492

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns.

mukul975/Anthropic-Cybersecurity-Skills34k—~644Automated safety check: PassApache-2.01 mo ago
493

Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
494

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
495

Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
496

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

mukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.01 mo ago
497

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: NotesApache-2.01 mo ago
498

Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
499

Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.01 mo ago
500

Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
501

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
502

Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
503

Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations (PAWs)…

mukul975/Anthropic-Cybersecurity-Skills34k—~687Automated safety check: PassApache-2.01 mo ago
504

Hardens LDAP directory services against credential harvesting, LDAP injection, anonymous binding, and channel-binding bypass by enforcing LDAPS, channel binding, and LDAP signing.

mukul975/Anthropic-Cybersecurity-Skills34k—~756Automated safety check: PassApache-2.01 mo ago
505

Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
506

Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions, using the…

mukul975/Anthropic-Cybersecurity-Skills34k—~732Automated safety check: PassApache-2.01 mo ago
507

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~849Automated safety check: PassApache-2.01 mo ago
508

This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.01 mo ago
509

Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

mukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.01 mo ago
510

Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.

mukul975/Anthropic-Cybersecurity-Skills34k—~677Automated safety check: PassApache-2.01 mo ago
511

Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat…

mukul975/Anthropic-Cybersecurity-Skills34k—~738Automated safety check: PassApache-2.01 mo ago
512

Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: NotesApache-2.01 mo ago
513

Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks.

mukul975/Anthropic-Cybersecurity-Skills34k—~4.7kAutomated safety check: PassApache-2.01 mo ago
514

Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis with Sysmon…

mukul975/Anthropic-Cybersecurity-Skills34k—~787Automated safety check: PassApache-2.01 mo ago
515

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702.

mukul975/Anthropic-Cybersecurity-Skills34k—~741Automated safety check: PassApache-2.01 mo ago
516

Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.01 mo ago
517

Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM.

mukul975/Anthropic-Cybersecurity-Skills34k—~717Automated safety check: PassApache-2.01 mo ago
518

Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.01 mo ago
519

Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.01 mo ago
520

Detect unauthorized SaaS and cloud service usage (shadow IT) by parsing proxy access logs, DNS query logs, and firewall/netflow data with Python pandas to aggregate traffic by domain, classify…

mukul975/Anthropic-Cybersecurity-Skills34k—~637Automated safety check: PassApache-2.01 mo ago
521

Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns.

mukul975/Anthropic-Cybersecurity-Skills34k—~564Automated safety check: PassApache-2.01 mo ago
522

Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
523

Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
524

Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
525

Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
526

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
527

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
528

Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~642Automated safety check: PassApache-2.01 mo ago