Agent skill

Configuring Network Segmentation With Vlans

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths.

Apache-2.0Auto-check passedLegal & Compliance

Install Configuring Network Segmentation With Vlans

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-network-segmentation-with-vlans -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills configuring-network-segmentation-with-vlans --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/configuring-network-segmentation-with-vlans .claude/skills/configuring-network-segmentation-with-vlans && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuring-network-segmentation-with-vlans
GitHub stars
34k
Token cost
~3.4k tokens
SKILL.md length
624 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths.

  • Works in 6 steps: Design the VLAN Architecture → Configure VLANs on Cisco Catalyst Switch → Harden Switch Against VLAN Hopping → …
  • Segmenting an enterprise network into isolated security zones
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl; reaches google.com

What it does

Configuring Network Segmentation With Vlans is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths. Use when segmenting an enterprise network into isolated security zones, meeting compliance mandates (PCI-DSS, HIPAA, SOC 2) for network isolation, or reducing blast radius from a security incident.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Legal & Compliance, covering Healthcare and finance regulation, Security operations and Red teaming and adversary simulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Segmenting an enterprise network into isolated security zones
  • Meeting compliance mandates (PCI-DSS
  • For network isolation
  • Reducing blast radius from a security incident

Example prompts

  • “Use the configuring-network-segmentation-with-vlans skill to design and implements VLAN-based (802.1Q) network segmentation on managed switches to…”
  • “/configuring-network-segmentation-with-vlans”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Design the VLAN Architecture
  2. Configure VLANs on Cisco Catalyst Switch
  3. Harden Switch Against VLAN Hopping
  4. Configure Inter-VLAN Routing with ACLs
  5. Configure DHCP and DNS per VLAN
  6. Verify and Test Segmentation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuring Network Segmentation With Vlans loads about 3.4k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 624 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 624 words, ~3,394 tokens.

Download SKILL.mdSave it as .claude/skills/configuring-network-segmentation-with-vlans/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
configuring-network-segmentation-with-vlans
description
Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths. Use when segmenting an enterprise network into isolated security zones, meeting compliance mandates (PCI-DSS, HIPAA, SOC 2) for network isolation, or reducing blast radius from a security incident.
domain
cybersecurity
subdomain
network-security
tags
network-security, vlan, network-segmentation, switch-security, 802.1q
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557.002, T1021, T1018

Configuring Network Segmentation with VLANs

When to Use

  • Segmenting an enterprise network into isolated security zones (corporate, servers, DMZ, guest, IoT)
  • Meeting compliance requirements (PCI-DSS, HIPAA, SOC 2) that mandate network isolation for sensitive data
  • Reducing blast radius of security incidents by preventing lateral movement between network segments
  • Isolating high-risk devices (IoT, BYOD, legacy systems) from critical infrastructure
  • Implementing defense-in-depth by combining VLANs with firewall rules and access control lists

Do not use VLANs as the sole security control without Layer 3 filtering, for isolating networks that require air-gapping, or without proper switch hardening against VLAN hopping attacks.

Prerequisites

  • Managed switches supporting 802.1Q VLAN trunking (Cisco Catalyst, HP Aruba, Juniper EX, etc.)
  • Layer 3 switch or firewall for inter-VLAN routing and access control
  • Network design document specifying VLAN assignments, IP subnets, and traffic flow requirements
  • Console or SSH access to switches with privileged configuration mode
  • Understanding of 802.1Q trunking, STP, and inter-VLAN routing concepts

Workflow

Step 1: Design the VLAN Architecture
# Define VLANs based on security zones and function

VLAN Plan:
  VLAN 10  - CORPORATE    (10.10.10.0/24)  - Employee workstations
  VLAN 20  - SERVERS      (10.10.20.0/24)  - Internal servers
  VLAN 30  - DMZ          (10.10.30.0/24)  - Internet-facing servers
  VLAN 40  - GUEST        (10.10.40.0/24)  - Guest WiFi
  VLAN 50  - IOT          (10.10.50.0/24)  - IoT/OT devices
  VLAN 60  - VOIP         (10.10.60.0/24)  - VoIP phones
  VLAN 100 - MANAGEMENT   (10.10.100.0/24) - Switch/AP management
  VLAN 999 - QUARANTINE   (10.10.99.0/24)  - Isolated/compromised hosts
  VLAN 998 - NATIVE_UNUSED                  - Native VLAN (no traffic)

# Traffic flow matrix:
# CORPORATE -> SERVERS: Allowed (specific ports)
# CORPORATE -> DMZ: Allowed (HTTP/HTTPS only)
# CORPORATE -> GUEST: Denied
# CORPORATE -> IOT: Denied
# GUEST -> Any Internal: Denied
# IOT -> SERVERS: Allowed (specific ports to specific hosts only)
# DMZ -> SERVERS: Allowed (database ports only)
# MANAGEMENT -> All: Allowed (from management stations only)
Step 2: Configure VLANs on Cisco Catalyst Switch
! Enter configuration mode
enable
configure terminal

! Create VLANs
vlan 10
  name CORPORATE
  exit
vlan 20
  name SERVERS
  exit
vlan 30
  name DMZ
  exit
vlan 40
  name GUEST
  exit
vlan 50
  name IOT
  exit
vlan 60
  name VOIP
  exit
vlan 100
  name MANAGEMENT
  exit
vlan 998
  name NATIVE_UNUSED
  exit
vlan 999
  name QUARANTINE
  exit

! Configure access ports for workstations (VLAN 10)
interface range GigabitEthernet1/0/1-24
  switchport mode access
  switchport access vlan 10
  switchport nonegotiate
  spanning-tree portfast
  spanning-tree bpduguard enable
  no shutdown
  exit

! Configure access ports for servers (VLAN 20)
interface range GigabitEthernet1/0/25-36
  switchport mode access
  switchport access vlan 20
  switchport nonegotiate
  spanning-tree portfast
  spanning-tree bpduguard enable
  no shutdown
  exit

! Configure trunk ports to other switches
interface GigabitEthernet1/0/48
  switchport mode trunk
  switchport trunk encapsulation dot1q
  switchport trunk native vlan 998
  switchport trunk allowed vlan 10,20,30,40,50,60,100
  switchport nonegotiate
  no shutdown
  exit

! Configure trunk to firewall/router
interface GigabitEthernet1/0/47
  switchport mode trunk
  switchport trunk encapsulation dot1q
  switchport trunk native vlan 998
  switchport trunk allowed vlan 10,20,30,40,50,60,100
  switchport nonegotiate
  no shutdown
  exit

! Shutdown unused ports
interface range GigabitEthernet1/0/37-46
  shutdown
  switchport mode access
  switchport access vlan 999
  exit
Step 3: Harden Switch Against VLAN Hopping
! Disable DTP on all ports (prevents switch spoofing)
interface range GigabitEthernet1/0/1-46
  switchport nonegotiate
  exit

! Set native VLAN to unused VLAN on all trunks
interface range GigabitEthernet1/0/47-48
  switchport trunk native vlan 998
  exit

! Enable DHCP Snooping
ip dhcp snooping
ip dhcp snooping vlan 10,20,30,40,50,60
interface GigabitEthernet1/0/47
  ip dhcp snooping trust
  exit

! Enable Dynamic ARP Inspection
ip arp inspection vlan 10,20,30,40,50,60
interface GigabitEthernet1/0/47
  ip arp inspection trust
  exit

! Enable IP Source Guard (prevents IP spoofing)
interface range GigabitEthernet1/0/1-36
  ip verify source
  exit

! Enable Port Security
interface range GigabitEthernet1/0/1-24
  switchport port-security
  switchport port-security maximum 2
  switchport port-security violation restrict
  switchport port-security aging time 60
  exit

! Set VTP to transparent mode (prevents VTP attacks)
vtp mode transparent

! Enable BPDU Guard globally
spanning-tree portfast bpduguard default

! Enable Storm Control
interface range GigabitEthernet1/0/1-36
  storm-control broadcast level 10
  storm-control multicast level 10
  storm-control action shutdown
  exit
Step 4: Configure Inter-VLAN Routing with ACLs
! On the Layer 3 switch or firewall, configure SVIs
interface Vlan10
  ip address 10.10.10.1 255.255.255.0
  no shutdown
  exit
interface Vlan20
  ip address 10.10.20.1 255.255.255.0
  no shutdown
  exit
interface Vlan30
  ip address 10.10.30.1 255.255.255.0
  no shutdown
  exit
interface Vlan40
  ip address 10.10.40.1 255.255.255.0
  no shutdown
  exit
interface Vlan50
  ip address 10.10.50.1 255.255.255.0
  no shutdown
  exit

! ACL: Corporate to Servers (allow specific services)
ip access-list extended CORP-TO-SERVERS
  permit tcp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255 eq 80
  permit tcp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255 eq 443
  permit tcp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255 eq 445
  permit udp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255 eq 53
  permit icmp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255 echo
  deny ip any any log
  exit

! ACL: Guest to Internet only (deny all internal)
ip access-list extended GUEST-OUTBOUND
  deny ip 10.10.40.0 0.0.0.255 10.0.0.0 0.255.255.255
  deny ip 10.10.40.0 0.0.0.255 172.16.0.0 0.15.255.255
  deny ip 10.10.40.0 0.0.0.255 192.168.0.0 0.0.255.255
  permit tcp 10.10.40.0 0.0.0.255 any eq 80
  permit tcp 10.10.40.0 0.0.0.255 any eq 443
  permit udp 10.10.40.0 0.0.0.255 any eq 53
  deny ip any any log
  exit

! ACL: IoT limited access
ip access-list extended IOT-OUTBOUND
  permit tcp 10.10.50.0 0.0.0.255 host 10.10.20.10 eq 443
  permit tcp 10.10.50.0 0.0.0.255 any eq 443
  permit udp 10.10.50.0 0.0.0.255 host 10.10.20.1 eq 53
  deny ip 10.10.50.0 0.0.0.255 10.10.50.0 0.0.0.255 log
  deny ip any any log
  exit

! Apply ACLs to VLAN interfaces
interface Vlan10
  ip access-group CORP-TO-SERVERS out
  exit
interface Vlan40
  ip access-group GUEST-OUTBOUND in
  exit
interface Vlan50
  ip access-group IOT-OUTBOUND in
  exit
Step 5: Configure DHCP and DNS per VLAN
! DHCP pools for each VLAN
ip dhcp pool CORPORATE
  network 10.10.10.0 255.255.255.0
  default-router 10.10.10.1
  dns-server 10.10.20.10
  domain-name corp.example.com
  lease 1
  exit

ip dhcp pool GUEST
  network 10.10.40.0 255.255.255.0
  default-router 10.10.40.1
  dns-server 1.1.1.1 8.8.8.8
  lease 0 4
  exit

ip dhcp pool IOT
  network 10.10.50.0 255.255.255.0
  default-router 10.10.50.1
  dns-server 10.10.20.10
  lease 7
  exit

! Exclude gateway and server IPs from DHCP pools
ip dhcp excluded-address 10.10.10.1 10.10.10.10
ip dhcp excluded-address 10.10.40.1 10.10.40.10
ip dhcp excluded-address 10.10.50.1 10.10.50.10
Step 6: Verify and Test Segmentation
bash
# From a workstation on VLAN 10 (Corporate):
# Should succeed:
ping 10.10.20.10          # Server access
curl https://10.10.20.10  # HTTPS to server

# Should fail:
ping 10.10.40.100         # Guest VLAN - should be blocked
ping 10.10.50.100         # IoT VLAN - should be blocked

# From a device on VLAN 40 (Guest):
# Should succeed:
ping 8.8.8.8              # Internet access
curl https://www.google.com

# Should fail:
ping 10.10.10.1           # Corporate gateway - blocked
ping 10.10.20.10          # Server - blocked

# Verify switch configuration
show vlan brief
show interfaces trunk
show ip arp inspection statistics
show ip dhcp snooping binding
show port-security
show ip access-lists

# Run VLAN hopping tests (from authorized pentest)
# These should all fail if hardening is correct:
# 1. DTP negotiation - should fail (nonegotiate)
# 2. Double tagging - should fail (native VLAN 998)
# 3. ARP spoofing - should fail (DAI enabled)

Key Concepts

TermDefinition
VLAN (Virtual LAN)Logical network partition at Layer 2 that groups switch ports into isolated broadcast domains, regardless of physical location
802.1Q TrunkingIEEE standard for VLAN tagging that adds a 4-byte header to Ethernet frames, identifying which VLAN a frame belongs to across trunk links
Inter-VLAN RoutingLayer 3 forwarding of traffic between VLANs using a router, Layer 3 switch, or firewall with access control lists
Native VLANVLAN assigned to untagged frames on trunk ports; should be set to an unused VLAN to prevent VLAN hopping attacks
DHCP SnoopingSwitch feature that validates DHCP messages and builds a binding table of IP-MAC-port mappings, preventing rogue DHCP servers
Port SecuritySwitch feature that limits the number of MAC addresses per port and takes action (shutdown, restrict) when violated

Tools & Systems

  • Cisco Catalyst/Nexus: Enterprise managed switches with comprehensive VLAN, trunking, and security feature support
  • HP Aruba CX: Enterprise switches with REST API management and VLAN segmentation capabilities
  • pfSense/OPNsense: Open-source firewalls for inter-VLAN routing with stateful access control
  • NetBox: Open-source IPAM and DCIM tool for documenting VLAN assignments, IP addressing, and network topology
  • Nmap: Network scanner for verifying segmentation effectiveness by testing reachability across VLAN boundaries
Show full SKILL.md (228 more words)Show less

Common Scenarios

Scenario: Implementing PCI-DSS Compliant Network Segmentation for Retail

Context: A retail chain must isolate their payment card processing systems from the general corporate network to meet PCI-DSS requirements. The current flat network has point-of-sale terminals, employee workstations, inventory servers, and guest WiFi on a single VLAN. The environment uses Cisco Catalyst 9300 switches.

Approach:

  1. Design VLAN architecture: POS terminals on VLAN 50 (CDE), corporate on VLAN 10, servers on VLAN 20, guest on VLAN 40
  2. Create VLANs on all access-layer switches and configure access ports by function
  3. Configure trunk links between switches with explicit VLAN allowed lists (no "all" trunks)
  4. Set native VLAN to 998 (unused) on all trunks and disable DTP on every port
  5. Configure ACLs on the Layer 3 switch: CDE VLAN can only reach the payment processor's IP on port 443; no other inter-VLAN traffic to/from CDE
  6. Enable DHCP snooping, DAI, and port security on all access ports
  7. Verify segmentation with penetration testing from each VLAN, confirming CDE is fully isolated

Pitfalls:

  • Leaving DTP enabled on access ports, allowing VLAN hopping to reach the CDE
  • Using VLAN 1 as the native VLAN, enabling double-tagging attacks
  • Not restricting trunk allowed VLANs, carrying all VLANs including CDE to non-essential switches
  • Creating ACLs that allow "any" source to reach CDE servers instead of specific POS terminal IPs

Output Format

## Network Segmentation Implementation Report

**Network**: Retail Store #42
**Switch Platform**: Cisco Catalyst 9300
**VLANs Configured**: 8

### VLAN Summary

| VLAN ID | Name | Subnet | Ports | Purpose |
|---------|------|--------|-------|---------|
| 10 | CORPORATE | 10.10.10.0/24 | Gi1/0/1-24 | Employee workstations |
| 20 | SERVERS | 10.10.20.0/24 | Gi1/0/25-36 | Internal servers |
| 30 | DMZ | 10.10.30.0/24 | Gi2/0/1-4 | Internet-facing |
| 40 | GUEST | 10.10.40.0/24 | WiFi AP trunk | Guest WiFi |
| 50 | CDE | 10.10.50.0/24 | Gi2/0/5-12 | POS terminals |
| 100 | MGMT | 10.10.100.0/24 | Gi1/0/48 | Switch management |
| 998 | NATIVE | N/A | Trunks only | Unused native |
| 999 | QUARANTINE | 10.10.99.0/24 | Unused ports | Isolation |

### Security Hardening Status

| Control | Status |
|---------|--------|
| DTP Disabled (nonegotiate) | All ports |
| Native VLAN (998) | All trunks |
| DHCP Snooping | VLANs 10,20,40,50 |
| Dynamic ARP Inspection | VLANs 10,20,40,50 |
| Port Security | Access ports |
| BPDU Guard | Access ports |
| Unused Ports Shutdown | 10 ports in VLAN 999 |
| VTP Transparent Mode | Enabled |

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/configuring-network-segmentation-with-vlans of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Configuring Network Segmentation With Vlans next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuring Network Segmentation With Vlans compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuring Network Segmentation With Vlans this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Configuring Network Segmentation With Vlans

What does Configuring Network Segmentation With Vlans do?

Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths. Configuring Network Segmentation With Vlans is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths.

When should I use Configuring Network Segmentation With Vlans?

Configuring Network Segmentation With Vlans fits situations like: segmenting an enterprise network into isolated security zones; meeting compliance mandates (PCI-DSS; for network isolation; reducing blast radius from a security incident.

How do I install Configuring Network Segmentation With Vlans in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-network-segmentation-with-vlans -a claude-code`. Or copy the skill folder (skills/configuring-network-segmentation-with-vlans in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/configuring-network-segmentation-with-vlans in your project. Claude Code loads it when a task matches its description.

How do I install Configuring Network Segmentation With Vlans in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-network-segmentation-with-vlans -a codex`. Or copy the skill folder (skills/configuring-network-segmentation-with-vlans in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/configuring-network-segmentation-with-vlans in your project. Codex loads it when a task matches its description.

Can I use Configuring Network Segmentation With Vlans in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-network-segmentation-with-vlans -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-network-segmentation-with-vlans, .gemini/skills/configuring-network-segmentation-with-vlans, .github/skills/configuring-network-segmentation-with-vlans and .opencode/skills/configuring-network-segmentation-with-vlans in your project.

What does Configuring Network Segmentation With Vlans need to run?

Going by SKILL.md and its folder, Configuring Network Segmentation With Vlans needs Python for the scripts in its folder and the command-line tools its instructions call (curl). Our summary lists: Python 3.

Does Configuring Network Segmentation With Vlans access the network?

SKILL.md names 1 domain. In commands or code: google.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Configuring Network Segmentation With Vlans safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Configuring Network Segmentation With Vlans use?

Configuring Network Segmentation With Vlans is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuring Network Segmentation With Vlans use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 598 tokens, read only when the agent opens those files.

What are the alternatives to Configuring Network Segmentation With Vlans?

Skills that share tags, products or a category with Configuring Network Segmentation With Vlans: Audit Report (harness/harness-skills, 115 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuring Network Segmentation With Vlans?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.