Agent skill

Deploying Decoy Files For Ransomware Detection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.

Apache-2.0Auto-check passedDevOps & Cloud

Install Deploying Decoy Files For Ransomware Detection

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-decoy-files-for-ransomware-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills deploying-decoy-files-for-ransomware-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploying-decoy-files-for-ransomware-detection .claude/skills/deploying-decoy-files-for-ransomware-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploying-decoy-files-for-ransomware-detection
GitHub stars
34k
Token cost
~2k tokens
SKILL.md length
480 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.

  • Works in 5 steps: Design Canary File Strategy → Generate Realistic Canary Files → Deploy File System Watcher → …
  • Alerts when ransomware modifies
  • SKILL.md covers When to Use, Prerequisites, Workflow and Verification, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Deploying Decoy Files For Ransomware Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Alerts when ransomware modifies
  • Tasks that involve Deployment

Example prompts

  • “Use the deploying-decoy-files-for-ransomware-detection skill to deploy canary files (honeytokens) across file systems to detect ransomware…”
  • “/deploying-decoy-files-for-ransomware-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Design Canary File Strategy
  2. Generate Realistic Canary Files
  3. Deploy File System Watcher
  4. Configure Alerting and Response
  5. Validate Detection Coverage

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploying Decoy Files For Ransomware Detection loads about 2k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 480 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 480 words, ~2,046 tokens.

Download SKILL.mdSave it as .claude/skills/deploying-decoy-files-for-ransomware-detection/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
deploying-decoy-files-for-ransomware-detection
description
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, detection, canary-files, honeytokens, deception, file-integrity
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1486, T1083, T1490, T1485
mitre_f3.version
1.1
mitre_f3.tactics
monetization, positioning, stealth

Deploying Decoy Files for Ransomware Detection

When to Use

  • Setting up early-warning detection for ransomware on file servers or endpoints
  • Supplementing EDR/AV with a deception-based detection layer that catches unknown ransomware variants
  • Creating high-fidelity ransomware alerts that have very low false-positive rates (legitimate users have no reason to touch decoy files)
  • Testing ransomware response procedures by validating that canary file modifications trigger the expected alerting pipeline
  • Protecting high-value file shares (finance, HR, legal) with tripwire files that indicate unauthorized encryption activity

Do not use decoy files as the sole ransomware defense. They are a detection mechanism, not a prevention mechanism, and should complement backups, EDR, and access controls.

Prerequisites

  • Python 3.8+ with watchdog library for cross-platform file system monitoring
  • Administrative access to target file shares or endpoints for canary placement
  • File integrity monitoring (FIM) tool or SIEM integration for alert routing
  • Understanding of target directory structure to place canaries in high-value locations
  • Windows: NTFS change journal or ReadDirectoryChangesW API access
  • Linux: inotify support in kernel (standard in modern kernels)

Workflow

Step 1: Design Canary File Strategy

Plan file placement for maximum detection coverage:

Canary File Placement Strategy:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Naming Convention:
  - Use names that sort FIRST and LAST alphabetically in each directory
  - Ransomware typically enumerates directories A-Z or Z-A
  - Examples: _AAAA_budget_2024.docx, ~zzzz_report_final.xlsx

Placement Locations:
  - Root of every file share (\\server\share\_AAAA_canary.docx)
  - Desktop, Documents, Downloads on each endpoint
  - Department-specific shares (Finance, HR, Legal)
  - Backup staging directories
  - Home directories of high-privilege accounts

File Types:
  - .docx, .xlsx, .pdf (most targeted by ransomware)
  - .sql, .bak (database files, high value)
  - Mix of file types to detect ransomware that targets specific extensions
Step 2: Generate Realistic Canary Files

Create decoy files with realistic content and metadata:

python
import os
import time

def create_canary_docx(filepath, content="Q4 Financial Summary - Confidential"):
    """Create a realistic .docx canary file using python-docx."""
    from docx import Document
    doc = Document()
    doc.add_heading("Financial Report - CONFIDENTIAL", level=1)
    doc.add_paragraph(content)
    doc.add_paragraph(f"Generated: {time.strftime('%Y-%m-%d')}")
    doc.save(filepath)

def create_canary_txt(filepath):
    """Create a simple text canary with known content for hash verification."""
    content = "CANARY_TOKEN_DO_NOT_MODIFY\n"
    content += f"Created: {time.strftime('%Y-%m-%dT%H:%M:%S')}\n"
    content += "This file is monitored for unauthorized changes.\n"
    with open(filepath, "w") as f:
        f.write(content)
Step 3: Deploy File System Watcher

Monitor canary files for any modification, rename, or deletion:

python
from watchdog.observers import Observer
from watchdog.events import FileSystemEventHandler

class CanaryHandler(FileSystemEventHandler):
    def __init__(self, canary_paths, alert_callback):
        self.canary_paths = set(canary_paths)
        self.alert_callback = alert_callback

    def on_modified(self, event):
        if event.src_path in self.canary_paths:
            self.alert_callback("MODIFIED", event.src_path)

    def on_deleted(self, event):
        if event.src_path in self.canary_paths:
            self.alert_callback("DELETED", event.src_path)

    def on_moved(self, event):
        if event.src_path in self.canary_paths:
            self.alert_callback("RENAMED", event.src_path)
Step 4: Configure Alerting and Response

Define automated responses when canary files are triggered:

Alert Response Matrix:
━━━━━━━━━━━━━━━━━━━━━
Event: Canary MODIFIED
  → Severity: CRITICAL
  → Action: Alert SOC, identify modifying process (PID), isolate endpoint

Event: Canary DELETED
  → Severity: HIGH
  → Action: Alert SOC, check for ransomware note in same directory

Event: Canary RENAMED (new extension added)
  → Severity: CRITICAL
  → Action: Alert SOC, check extension against known ransomware extensions
  → Automated: Kill modifying process, disable network interface

Event: Multiple canaries triggered within 60 seconds
  → Severity: EMERGENCY
  → Action: Network-wide isolation, activate incident response plan
Step 5: Validate Detection Coverage

Test that canary files detect actual ransomware behavior:

bash
# Simulate ransomware encryption (safe test - modifies canary content)
echo "ENCRYPTED_BY_TEST" > /path/to/canary/_AAAA_budget.docx

# Simulate ransomware rename (adds extension)
mv /path/to/canary/report.xlsx /path/to/canary/report.xlsx.locked

# Verify alerts were generated in SIEM/alerting system

Verification

  • Confirm all canary files are present and unmodified using stored hash baselines
  • Verify that modifying any canary file generates an alert within the expected timeframe (under 30 seconds)
  • Test that alert routing to SOC/SIEM is functional with a controlled modification
  • Validate that automated response actions (process kill, network isolation) execute correctly
  • Check that canary files survive normal backup and restore operations
  • Ensure legitimate users and processes are excluded from false-positive alerts (backup agents, AV scans)
Show full SKILL.md (165 more words)Show less

Key Concepts

TermDefinition
Canary FileA decoy file placed in a directory that is monitored for any access or modification, serving as a tripwire for unauthorized activity
HoneytokenA broader category of deception artifacts (files, credentials, database records) designed to alert when accessed
File Integrity MonitoringContinuous monitoring of file attributes (hash, size, permissions, timestamps) to detect unauthorized changes
ReadDirectoryChangesWWindows API for monitoring file system changes in a directory; used by the watchdog library on Windows
inotifyLinux kernel subsystem for monitoring file system events; provides near-instant notification of file changes

Tools & Systems

  • watchdog (Python): Cross-platform file system event monitoring library supporting Windows, Linux, and macOS
  • Canarytokens (Thinkst): Free hosted service for generating various types of canary tokens including files, URLs, and DNS tokens
  • OSSEC/Wazuh: Open-source HIDS with built-in file integrity monitoring and alerting capabilities
  • Elastic Endpoint: Uses canary files internally for ransomware protection and key capture
  • Sysmon: Windows system monitor that logs file creation events (Event ID 11) for canary file monitoring

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/deploying-decoy-files-for-ransomware-detection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Deploying Decoy Files For Ransomware Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploying Decoy Files For Ransomware Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploying Decoy Files For Ransomware Detection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Mirrord Operatormetalbear-co/mirrord5.4k1 repos~4.6kAutomated safety check: PassMIT
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion63k—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    63k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Deploying Decoy Files For Ransomware Detection

What does Deploying Decoy Files For Ransomware Detection do?

Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Deploying Decoy Files For Ransomware Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.

When should I use Deploying Decoy Files For Ransomware Detection?

Deploying Decoy Files For Ransomware Detection fits situations like: alerts when ransomware modifies; tasks that involve Deployment.

How do I install Deploying Decoy Files For Ransomware Detection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-decoy-files-for-ransomware-detection -a claude-code`. Or copy the skill folder (skills/deploying-decoy-files-for-ransomware-detection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/deploying-decoy-files-for-ransomware-detection in your project. Claude Code loads it when a task matches its description.

How do I install Deploying Decoy Files For Ransomware Detection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-decoy-files-for-ransomware-detection -a codex`. Or copy the skill folder (skills/deploying-decoy-files-for-ransomware-detection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/deploying-decoy-files-for-ransomware-detection in your project. Codex loads it when a task matches its description.

Can I use Deploying Decoy Files For Ransomware Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-decoy-files-for-ransomware-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-decoy-files-for-ransomware-detection, .gemini/skills/deploying-decoy-files-for-ransomware-detection, .github/skills/deploying-decoy-files-for-ransomware-detection and .opencode/skills/deploying-decoy-files-for-ransomware-detection in your project.

What does Deploying Decoy Files For Ransomware Detection need to run?

Going by SKILL.md and its folder, Deploying Decoy Files For Ransomware Detection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Deploying Decoy Files For Ransomware Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Deploying Decoy Files For Ransomware Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deploying Decoy Files For Ransomware Detection use?

Deploying Decoy Files For Ransomware Detection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploying Decoy Files For Ransomware Detection use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 801 tokens, read only when the agent opens those files.

What are the alternatives to Deploying Decoy Files For Ransomware Detection?

Skills that share tags, products or a category with Deploying Decoy Files For Ransomware Detection: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Mirrord Operator (metalbear-co/mirrord, 5.4k stars) and KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploying Decoy Files For Ransomware Detection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.