Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue…
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .claude/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .agents/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .cursor/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .gemini/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .github/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "detecting-anomalies-in-industrial-control-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-anomalies-in-industrial-control-systems into .opencode/skills/detecting-anomalies-in-industrial-control-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-anomalies-in-industrial-control-systems", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
detecting-anomalies-in-industrial-control-systems
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
355 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0
At a glance
Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue…
Continuous OT monitoring
SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
Runs Python scripts from its folder
Baselining deterministic SCADA polling
What it does
Detecting Anomalies In Industrial Control Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for continuous OT monitoring, baselining deterministic SCADA polling, or investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Data & Analytics, covering Anomaly detection and Machine learning. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
When your agent uses it
Continuous OT monitoring
Baselining deterministic SCADA polling
Investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis
Example prompts
“Use the detecting-anomalies-in-industrial-control-systems skill to deploy anomaly detection for OT/ICS environments using machine learning on OT…”
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Detecting Anomalies In Industrial Control Systems loads about 3.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 355 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~113
When it runs· the whole SKILL.md, loaded when a task matches
~3.2k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~3.6k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/detecting-anomalies-in-industrial-control-systems/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-anomalies-in-industrial-control-systems
description
Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for continuous OT monitoring, baselining deterministic SCADA polling, or investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
When deploying continuous monitoring for OT environments that lack intrusion detection
When building behavior-based detection to complement signature-based IDS in OT networks
When establishing baselines for deterministic SCADA communications to detect deviations
When integrating machine learning anomaly detection with OT security monitoring platforms
When investigating alerts from Nozomi Guardian or Dragos Platform that require deeper analysis
Do not use for signature-based detection of known exploits (see detecting-attacks-on-scada-systems), for IT network anomaly detection without OT protocols, or as a replacement for process safety systems (SIS).
Prerequisites
Passive network monitoring sensors on OT network SPAN/TAP ports
Minimum 2-4 weeks of baseline traffic capture during normal operations
Python 3.9+ with scikit-learn, numpy, pandas for ML model training
Process historian access for physical process correlation data
Understanding of normal operational patterns including shift changes, batch processes, and maintenance windows
Workflow
Step 1: Build Multi-Dimensional Baseline Model
Capture and model the deterministic behavior of ICS communications across multiple dimensions: timing, protocol behavior, and network topology.
python
#!/usr/bin/env python3
"""ICS Anomaly Detection System.
Builds multi-dimensional baselines from OT network traffic and
detects anomalies using statistical and machine learning methods.
Designed for deterministic SCADA communication patterns.
"""
import json
import sys
import time
import warnings
from collections import defaultdict
from datetime import datetime, timedelta
from dataclasses import dataclass, field
import numpy as np
import pandas as pd
from sklearn.ensemble import IsolationForest
from sklearn.preprocessing import StandardScaler
warnings.filterwarnings("ignore")
@dataclass
class CommunicationProfile:
"""Profile for a single master-slave communication pair."""
src_ip: str
dst_ip: str
protocol: str
port: int
avg_interval_ms: float = 0.0
std_interval_ms: float = 0.0
avg_payload_size: float = 0.0
function_codes: dict = field(default_factory=dict)
packets_per_minute: float = 0.0
first_seen: str = ""
last_seen: str = ""
class ICSAnomalyDetector:
"""Multi-dimensional anomaly detection for ICS environments."""
def __init__(self):
self.profiles = {}
self.topology_baseline = set()
self.timing_model = None
self.isolation_forest = None
self.scaler = StandardScaler()
self.anomalies = []
self.training_data = []
def build_baseline_from_pcap(self, pcap_data):
"""Build baselines from parsed pcap data (list of flow records)."""
print("[*] Building ICS communication baselines...")
for flow in pcap_data:
key = f"{flow['src']}->{flow['dst']}:{flow['port']}"
if key not in self.profiles:
self.profiles[key] = CommunicationProfile(
src_ip=flow["src"],
dst_ip=flow["dst"],
protocol=flow.get("protocol", "TCP"),
port=flow["port"],
first_seen=flow.get("timestamp", ""),
)
profile = self.profiles[key]
profile.last_seen = flow.get("timestamp", "")
# Track function codes for industrial protocols
fc = flow.get("function_code")
if fc is not None:
profile.function_codes[fc] = profile.function_codes.get(fc, 0) + 1
# Add to topology baseline
self.topology_baseline.add((flow["src"], flow["dst"], flow["port"]))
# Calculate interval statistics
self._calculate_timing_stats(pcap_data)
print(f" Communication pairs: {len(self.profiles)}")
print(f" Topology entries: {len(self.topology_baseline)}")
def _calculate_timing_stats(self, flows):
"""Calculate packet timing statistics per communication pair."""
timestamps = defaultdict(list)
for flow in flows:
key = f"{flow['src']}->{flow['dst']}:{flow['port']}"
ts = flow.get("timestamp_epoch")
if ts:
timestamps[key].append(ts)
for key, ts_list in timestamps.items():
if key in self.profiles and len(ts_list) > 1:
ts_sorted = sorted(ts_list)
intervals = [
(ts_sorted[i+1] - ts_sorted[i]) * 1000
for i in range(len(ts_sorted) - 1)
]
self.profiles[key].avg_interval_ms = np.mean(intervals)
self.profiles[key].std_interval_ms = np.std(intervals)
duration_min = (ts_sorted[-1] - ts_sorted[0]) / 60
if duration_min > 0:
self.profiles[key].packets_per_minute = len(ts_list) / duration_min
def train_isolation_forest(self, features_df):
"""Train Isolation Forest model on feature vectors from baseline traffic."""
print("[*] Training Isolation Forest model...")
feature_cols = [
"interval_ms", "payload_size", "packets_per_window",
"unique_func_codes", "new_connection_flag",
]
available_cols = [c for c in feature_cols if c in features_df.columns]
X = features_df[available_cols].fillna(0).values
X_scaled = self.scaler.fit_transform(X)
self.isolation_forest = IsolationForest(
n_estimators=200,
contamination=0.01, # Expect 1% anomaly rate in baseline
random_state=42,
n_jobs=-1,
)
self.isolation_forest.fit(X_scaled)
scores = self.isolation_forest.decision_function(X_scaled)
print(f" Model trained on {len(X)} samples")
print(f" Anomaly score range: [{scores.min():.4f}, {scores.max():.4f}]")
print(f" Threshold: {np.percentile(scores, 1):.4f}")
def detect_topology_anomaly(self, src_ip, dst_ip, port):
"""Detect new/unauthorized communication pairs."""
if (src_ip, dst_ip, port) not in self.topology_baseline:
return {
"type": "NEW_COMMUNICATION_PAIR",
"severity": "high",
"detail": f"New connection: {src_ip} -> {dst_ip}:{port} not in baseline",
"recommendation": "Verify if this is an authorized new device or configuration change",
}
return None
def detect_timing_anomaly(self, src_ip, dst_ip, port, interval_ms):
"""Detect polling interval deviations."""
key = f"{src_ip}->{dst_ip}:{port}"
profile = self.profiles.get(key)
if profile and profile.std_interval_ms > 0:
z_score = abs(interval_ms - profile.avg_interval_ms) / profile.std_interval_ms
if z_score > 4.0:
return {
"type": "TIMING_ANOMALY",
"severity": "medium",
"detail": (
f"Interval {interval_ms:.1f}ms deviates from baseline "
f"{profile.avg_interval_ms:.1f}ms (z-score: {z_score:.1f})"
),
"recommendation": "Check for network congestion, device malfunction, or MITM attack",
}
return None
def detect_function_code_anomaly(self, src_ip, dst_ip, port, func_code):
"""Detect unauthorized Modbus/DNP3 function codes."""
key = f"{src_ip}->{dst_ip}:{port}"
profile = self.profiles.get(key)
if profile and func_code not in profile.function_codes:
severity = "critical" if func_code in {5, 6, 15, 16, 8} else "high"
return {
"type": "UNAUTHORIZED_FUNCTION_CODE",
"severity": severity,
"detail": (
f"Function code {func_code} from {src_ip} to {dst_ip}:{port} "
f"not in baseline. Allowed: {list(profile.function_codes.keys())}"
),
"recommendation": "Investigate source - possible command injection attack",
}
return None
def analyze_flow(self, flow):
"""Analyze a single network flow against all detection models."""
results = []
# Topology check
topo = self.detect_topology_anomaly(flow["src"], flow["dst"], flow["port"])
if topo:
results.append(topo)
# Timing check
if "interval_ms" in flow:
timing = self.detect_timing_anomaly(
flow["src"], flow["dst"], flow["port"], flow["interval_ms"])
if timing:
results.append(timing)
# Function code check
if "function_code" in flow:
fc = self.detect_function_code_anomaly(
flow["src"], flow["dst"], flow["port"], flow["function_code"])
if fc:
results.append(fc)
self.anomalies.extend(results)
return results
def generate_report(self):
"""Generate anomaly detection report."""
print(f"\n{'='*60}")
print(f"ICS ANOMALY DETECTION REPORT")
print(f"{'='*60}")
print(f"Baseline Profiles: {len(self.profiles)}")
print(f"Anomalies Detected: {len(self.anomalies)}")
severity_counts = defaultdict(int)
for a in self.anomalies:
severity_counts[a["severity"]] += 1
for sev in ["critical", "high", "medium", "low"]:
if severity_counts[sev]:
print(f" {sev.upper()}: {severity_counts[sev]}")
for a in self.anomalies[:20]:
print(f"\n [{a['severity'].upper()}] {a['type']}")
print(f" {a['detail']}")
if __name__ == "__main__":
print("ICS Anomaly Detection System")
print("Load baseline data and call analyze_flow() for real-time detection")
Show full SKILL.md (186 more words)Show less
Key Concepts
Term
Definition
Deterministic Traffic
ICS networks exhibit highly predictable communication patterns where the same master polls the same slaves at fixed intervals with identical function codes
Isolation Forest
Unsupervised machine learning algorithm that isolates anomalies by randomly partitioning feature space, effective for OT traffic with low anomaly rates
Polling Interval
Time between consecutive SCADA master requests to a slave device, typically fixed and configurable (100ms to 10s)
Function Code Allowlist
Set of permitted industrial protocol operations for each communication pair, enforced by anomaly detection rules
Topology Baseline
Complete map of all authorized device-to-device communication paths in the OT network
Physics-Based Detection
Using physical process models (thermodynamics, fluid dynamics) to detect attacks that manipulate the process while spoofing sensor data
Tools & Systems
Nozomi Networks Guardian: OT anomaly detection with AI-powered baseline learning and industrial protocol analysis
Dragos Platform: Threat detection using behavioral analytics and threat intelligence specific to ICS environments
Scikit-learn: Python ML library with Isolation Forest, One-Class SVM, and Local Outlier Factor for anomaly detection
Zeek with OT plugins: Network security monitor with Modbus, DNP3, and BACnet protocol analyzers for baseline building
Detecting Anomalies In Industrial Control Systems next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detecting Anomalies In Industrial Control Systems compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Detecting Anomalies In Industrial Control Systems this skillmukul975/Anthropic-Cybersecurity-Skills
Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…
Guides time series machine learning with the aeon toolkit: classification, regression, clustering, forecasting, anomaly detection, segmentation and similarity search.
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Questions about Detecting Anomalies In Industrial Control Systems
What does Detecting Anomalies In Industrial Control Systems do?
Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue…. Detecting Anomalies In Industrial Control Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data.
When should I use Detecting Anomalies In Industrial Control Systems?
Detecting Anomalies In Industrial Control Systems fits situations like: continuous OT monitoring; baselining deterministic SCADA polling; investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
How do I install Detecting Anomalies In Industrial Control Systems in Claude Code?
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a claude-code`. Or copy the skill folder (skills/detecting-anomalies-in-industrial-control-systems in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-anomalies-in-industrial-control-systems in your project. Claude Code loads it when a task matches its description.
How do I install Detecting Anomalies In Industrial Control Systems in Codex?
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a codex`. Or copy the skill folder (skills/detecting-anomalies-in-industrial-control-systems in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-anomalies-in-industrial-control-systems in your project. Codex loads it when a task matches its description.
Can I use Detecting Anomalies In Industrial Control Systems in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-anomalies-in-industrial-control-systems -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-anomalies-in-industrial-control-systems, .gemini/skills/detecting-anomalies-in-industrial-control-systems, .github/skills/detecting-anomalies-in-industrial-control-systems and .opencode/skills/detecting-anomalies-in-industrial-control-systems in your project.
What does Detecting Anomalies In Industrial Control Systems need to run?
Going by SKILL.md and its folder, Detecting Anomalies In Industrial Control Systems needs Python for the scripts in its folder. Our summary lists: Python 3.
Does Detecting Anomalies In Industrial Control Systems access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Detecting Anomalies In Industrial Control Systems safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Detecting Anomalies In Industrial Control Systems use?
Detecting Anomalies In Industrial Control Systems is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Detecting Anomalies In Industrial Control Systems use?
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 443 tokens, read only when the agent opens those files.
What are the alternatives to Detecting Anomalies In Industrial Control Systems?
Skills that share tags, products or a category with Detecting Anomalies In Industrial Control Systems: Time Series Analytics User (open-edge-platform/edge-ai-libraries, 171 stars), Aeon Time Series Machine Learning (davila7/claude-code-templates, 33k stars), Automl Skill (LeoYeAI/openclaw-master-skills, 2.2k stars) and Scikit Learn (zLanqing/codex-claude-academic-skills, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Detecting Anomalies In Industrial Control Systems?
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.