Agent skill

Detecting Arp Poisoning In Network Traffic

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…

Apache-2.0Auto-check: notesSecurity

Install Detecting Arp Poisoning In Network Traffic

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-arp-poisoning-in-network-traffic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-arp-poisoning-in-network-traffic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-arp-poisoning-in-network-traffic .claude/skills/detecting-arp-poisoning-in-network-traffic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-arp-poisoning-in-network-traffic
GitHub stars
34k
Token cost
~3.8k tokens
SKILL.md length
532 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…

  • Works in 4 steps: Deploy ARPWatch for Continuous Monitoring → Configure Dynamic ARP Inspection (DAI)… → Wireshark Detection Filters → …
  • Investigating suspected man-in-the-middle interception
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder; calls apt-get

What it does

Detecting Arp Poisoning In Network Traffic is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC mapping changes, and duplicate IP addresses. Use when investigating suspected man-in-the-middle interception or session hijacking on a local network segment, or when building layer-2 anomaly detection for a SOC.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Network security, Anomaly detection and Security operations. It works with Wireshark and Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Investigating suspected man-in-the-middle interception
  • Session hijacking on a local network segment
  • Building layer-2 anomaly detection for a SOC

Example prompts

  • “/detecting-arp-poisoning-in-network-traffic”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Deploy ARPWatch for Continuous Monitoring
  2. Configure Dynamic ARP Inspection (DAI) on Switches
  3. Wireshark Detection Filters
  4. Custom Python ARP Monitor

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • csrc.nist.gov
    • cisco.com
    • comparitech.com
    • okta.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Arp Poisoning In Network Traffic loads about 3.8k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 532 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:93
    sudo apt-get install -y arpwatch
  • NoteRuns commands with sudoSKILL.md:96
    sudo vi /etc/default/arpwatch
  • NoteRuns commands with sudoSKILL.md:101
    sudo systemctl enable arpwatch
  • NoteRuns commands with sudoSKILL.md:102
    sudo systemctl start arpwatch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 532 words, ~3,785 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-arp-poisoning-in-network-traffic/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-arp-poisoning-in-network-traffic
description
Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC mapping changes, and duplicate IP addresses. Use when investigating suspected man-in-the-middle interception or session hijacking on a local network segment, or when building layer-2 anomaly detection for a SOC.
domain
cybersecurity
subdomain
network-security
tags
arp-poisoning, arp-spoofing, mitm, dynamic-arp-inspection, arpwatch, network-security, man-in-the-middle, layer-2-security
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1557.002, T1557, T1040, T1200

Detecting ARP Poisoning in Network Traffic

Overview

ARP poisoning (ARP spoofing) is a Layer 2 attack where an adversary sends falsified ARP messages to associate their MAC address with the IP address of a legitimate host, enabling man-in-the-middle (MitM) interception, session hijacking, or denial of service. Since ARP has no built-in authentication mechanism, any device on a broadcast domain can forge ARP replies. Detection requires monitoring ARP traffic for anomalies such as gratuitous ARP floods, IP-to-MAC mapping changes, and duplicate IP addresses. This skill covers deploying multiple detection layers including ARPWatch, Dynamic ARP Inspection (DAI), Wireshark-based analysis, and custom Python monitoring tools.

When to Use

  • When investigating security incidents that require detecting arp poisoning in network traffic
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Access to the target network segment (broadcast domain)
  • Linux host for ARPWatch and custom monitoring tools
  • Managed switches supporting Dynamic ARP Inspection (Cisco Catalyst, Aruba, Juniper EX)
  • Wireshark or tcpdump for packet capture
  • DHCP snooping configured (prerequisite for DAI)
  • Network monitoring infrastructure (SIEM, syslog server)

Core Concepts

ARP Protocol Fundamentals

ARP maps IP addresses to MAC addresses on a local network segment. The protocol operates statelessly with no authentication:

Normal ARP Process:
1. Host A broadcasts: "Who has 10.0.1.1? Tell 10.0.1.100"
2. Router replies: "10.0.1.1 is at AA:BB:CC:DD:EE:01"
3. Host A caches the mapping

ARP Poisoning Attack:
1. Attacker sends unsolicited ARP reply to Host A:
   "10.0.1.1 is at EV:IL:MA:CA:DD:RR" (attacker's MAC)
2. Host A updates cache, sends traffic to attacker
3. Attacker forwards to real gateway (MitM position)
Attack Indicators
IndicatorDescriptionSeverity
MAC flip-floppingSame IP mapped to different MACs rapidlyHigh
Gratuitous ARP floodUnsolicited ARP replies targeting multiple hostsHigh
Duplicate IP addressTwo different MACs claiming same IPCritical
Unusual ARP volumeSpike in ARP packets per secondMedium
ARP from non-DHCP sourceStatic IP claims from unknown devicesMedium
Gateway MAC changeDefault gateway MAC address changedCritical

Workflow

Step 1: Deploy ARPWatch for Continuous Monitoring
bash
# Install ARPWatch
sudo apt-get install -y arpwatch

# Configure ARPWatch
sudo vi /etc/default/arpwatch
# INTERFACES="eth0"
# ARGS="-N -p -i eth0 -f /var/lib/arpwatch/arp.dat"

# Start monitoring
sudo systemctl enable arpwatch
sudo systemctl start arpwatch

# View current ARP database
cat /var/lib/arpwatch/arp.dat

# Monitor logs for changes
tail -f /var/log/syslog | grep arpwatch

ARPWatch alert types:

  • new station - Previously unseen MAC address
  • changed ethernet address - IP mapped to different MAC (potential poisoning)
  • flip flop - MAC alternating between two addresses (active attack)
  • reused old ethernet address - Previously seen mapping returned
Show full SKILL.md (206 more words)Show less
Step 2: Configure Dynamic ARP Inspection (DAI) on Switches

Cisco Catalyst configuration:

! Enable DHCP snooping (prerequisite for DAI)
ip dhcp snooping
ip dhcp snooping vlan 10,20,30

! Configure trusted ports (uplinks, DHCP servers)
interface GigabitEthernet1/0/1
 description Uplink to Distribution
 ip dhcp snooping trust

interface GigabitEthernet1/0/48
 description DHCP Server
 ip dhcp snooping trust

! Enable Dynamic ARP Inspection
ip arp inspection vlan 10,20,30

! Configure trusted ports for DAI
interface GigabitEthernet1/0/1
 ip arp inspection trust

! Set rate limits to prevent ARP flood DoS
interface range GigabitEthernet1/0/2-47
 ip arp inspection limit rate 15

! Enable additional validation checks
ip arp inspection validate src-mac dst-mac ip

! Configure ARP ACL for static IP devices (servers, printers)
arp access-list STATIC-ARP-ENTRIES
 permit ip host 10.0.10.100 mac host 0011.2233.4455
 permit ip host 10.0.10.101 mac host 0011.2233.4456

ip arp inspection filter STATIC-ARP-ENTRIES vlan 10

! Verify DAI status
show ip arp inspection vlan 10
show ip arp inspection statistics
show ip dhcp snooping binding
Step 3: Wireshark Detection Filters
# Detect gratuitous ARP (sender and target IP are the same)
arp.src.proto_ipv4 == arp.dst.proto_ipv4

# Detect ARP replies (focus on unsolicited)
arp.opcode == 2

# Detect duplicate IP address claims
arp.duplicate-address-detected

# Detect ARP packets from specific attacker MAC
eth.src == ev:il:ma:ca:dd:rr

# Detect ARP storms (high volume)
# Use Statistics > I/O Graphs > Display filter: arp

# Detect gateway impersonation
arp.src.proto_ipv4 == 10.0.1.1 && arp.src.hw_mac != aa:bb:cc:dd:ee:01
Step 4: Custom Python ARP Monitor
python
#!/usr/bin/env python3
"""
Real-time ARP poisoning detection using packet capture.
Monitors ARP traffic for spoofing indicators and alerts on anomalies.
"""

import subprocess
import sys
import json
import time
from collections import defaultdict
from datetime import datetime

try:
    from scapy.all import sniff, ARP, Ether, get_if_hwaddr, conf
    SCAPY_AVAILABLE = True
except ImportError:
    SCAPY_AVAILABLE = False


class ARPPoisonDetector:
    def __init__(self, interface: str, gateway_ip: str, gateway_mac: str):
        self.interface = interface
        self.gateway_ip = gateway_ip
        self.gateway_mac = gateway_mac.lower()
        self.arp_table = {}  # IP -> MAC mapping
        self.arp_history = defaultdict(list)  # IP -> list of (MAC, timestamp)
        self.alerts = []
        self.arp_count = defaultdict(int)  # Source MAC -> count per interval
        self.last_reset = time.time()
        self.arp_rate_threshold = 50  # ARP packets per 10 seconds

    def alert(self, severity: str, message: str, details: dict):
        """Generate alert for detected anomaly."""
        alert_data = {
            'timestamp': datetime.now().isoformat(),
            'severity': severity,
            'message': message,
            'details': details,
        }
        self.alerts.append(alert_data)
        print(f"\n[{severity}] {datetime.now().strftime('%H:%M:%S')} - {message}")
        for key, value in details.items():
            print(f"  {key}: {value}")

    def check_gateway_spoofing(self, src_ip: str, src_mac: str):
        """Check if someone is spoofing the gateway."""
        if src_ip == self.gateway_ip and src_mac != self.gateway_mac:
            self.alert('CRITICAL', 'Gateway ARP Spoofing Detected', {
                'gateway_ip': self.gateway_ip,
                'expected_mac': self.gateway_mac,
                'spoofed_mac': src_mac,
                'action': 'Potential MitM attack on default gateway',
            })
            return True
        return False

    def check_mac_change(self, src_ip: str, src_mac: str):
        """Check if IP-to-MAC mapping has changed."""
        if src_ip in self.arp_table:
            known_mac = self.arp_table[src_ip]
            if known_mac != src_mac:
                self.alert('HIGH', 'ARP Cache Poisoning Attempt', {
                    'ip_address': src_ip,
                    'previous_mac': known_mac,
                    'new_mac': src_mac,
                    'action': 'IP-to-MAC mapping changed unexpectedly',
                })
                return True
        return False

    def check_flip_flop(self, src_ip: str, src_mac: str):
        """Check for MAC address flip-flopping (active attack indicator)."""
        self.arp_history[src_ip].append((src_mac, time.time()))

        # Keep only last 60 seconds of history
        cutoff = time.time() - 60
        self.arp_history[src_ip] = [
            (mac, ts) for mac, ts in self.arp_history[src_ip]
            if ts > cutoff
        ]

        unique_macs = set(mac for mac, ts in self.arp_history[src_ip])
        if len(unique_macs) > 2:
            self.alert('CRITICAL', 'ARP Flip-Flop Detected (Active Attack)', {
                'ip_address': src_ip,
                'mac_addresses': list(unique_macs),
                'changes_in_60s': len(self.arp_history[src_ip]),
            })
            return True
        return False

    def check_arp_rate(self, src_mac: str):
        """Check for ARP flood (DoS or scanning)."""
        self.arp_count[src_mac] += 1

        # Reset counters every 10 seconds
        if time.time() - self.last_reset > 10:
            for mac, count in self.arp_count.items():
                if count > self.arp_rate_threshold:
                    self.alert('MEDIUM', 'ARP Flood Detected', {
                        'source_mac': mac,
                        'arp_packets_10s': count,
                        'threshold': self.arp_rate_threshold,
                    })
            self.arp_count.clear()
            self.last_reset = time.time()

    def process_packet(self, packet):
        """Process captured ARP packet."""
        if not packet.haslayer(ARP):
            return

        arp = packet[ARP]

        # Only process ARP replies (opcode 2) and requests (opcode 1)
        if arp.op not in (1, 2):
            return

        src_ip = arp.psrc
        src_mac = arp.hwsrc.lower()

        # Run detection checks
        self.check_gateway_spoofing(src_ip, src_mac)
        self.check_mac_change(src_ip, src_mac)
        self.check_flip_flop(src_ip, src_mac)
        self.check_arp_rate(src_mac)

        # Update ARP table
        self.arp_table[src_ip] = src_mac

    def start_monitoring(self):
        """Start real-time ARP monitoring."""
        print(f"[*] Starting ARP Poison Detection on {self.interface}")
        print(f"[*] Gateway: {self.gateway_ip} ({self.gateway_mac})")
        print(f"[*] Monitoring... (Ctrl+C to stop)\n")

        if SCAPY_AVAILABLE:
            sniff(
                iface=self.interface,
                filter="arp",
                prn=self.process_packet,
                store=False,
            )
        else:
            print("[-] Scapy not available. Install with: pip install scapy")
            print("[*] Falling back to tcpdump-based monitoring...")
            self._monitor_with_tcpdump()

    def _monitor_with_tcpdump(self):
        """Fallback monitoring using tcpdump."""
        cmd = ['tcpdump', '-i', self.interface, '-l', '-n', 'arp']
        proc = subprocess.Popen(cmd, stdout=subprocess.PIPE,
                                stderr=subprocess.DEVNULL, text=True)
        try:
            for line in proc.stdout:
                parts = line.strip().split()
                if 'is-at' in parts:
                    try:
                        ip_idx = parts.index('is-at') - 1
                        mac_idx = parts.index('is-at') + 1
                        src_ip = parts[ip_idx]
                        src_mac = parts[mac_idx].lower()
                        self.check_gateway_spoofing(src_ip, src_mac)
                        self.check_mac_change(src_ip, src_mac)
                        self.arp_table[src_ip] = src_mac
                    except (IndexError, ValueError):
                        continue
        except KeyboardInterrupt:
            proc.terminate()

    def generate_report(self) -> dict:
        """Generate summary report of detected anomalies."""
        return {
            'monitoring_interface': self.interface,
            'gateway': {'ip': self.gateway_ip, 'mac': self.gateway_mac},
            'total_alerts': len(self.alerts),
            'arp_table_size': len(self.arp_table),
            'alerts': self.alerts,
        }


if __name__ == '__main__':
    if len(sys.argv) < 4:
        print("Usage: python process.py <interface> <gateway_ip> <gateway_mac>")
        print("Example: python process.py eth0 10.0.1.1 aa:bb:cc:dd:ee:01")
        sys.exit(1)

    detector = ARPPoisonDetector(
        interface=sys.argv[1],
        gateway_ip=sys.argv[2],
        gateway_mac=sys.argv[3],
    )

    try:
        detector.start_monitoring()
    except KeyboardInterrupt:
        print("\n\n[*] Monitoring stopped.")
        report = detector.generate_report()
        print(f"[*] Total alerts generated: {report['total_alerts']}")
        print(f"[*] ARP table entries: {report['arp_table_size']}")

Prevention Measures

Layer 2 Controls
  1. Dynamic ARP Inspection (DAI) - Validates ARP packets against DHCP snooping binding table
  2. DHCP Snooping - Builds trusted IP-MAC-port binding database
  3. Port Security - Limits MAC addresses per port
  4. Private VLANs - Restricts communication between hosts in the same VLAN
Network Controls
  1. Static ARP Entries - For critical infrastructure (gateways, DNS, DHCP)
  2. Network Segmentation - Reduce broadcast domain size with VLANs
  3. 802.1X Authentication - Authenticate devices before network access
  4. Encrypted Protocols - Use SSH, HTTPS, TLS to protect data even if intercepted

Best Practices

  • Defense in Depth - Combine DAI, ARPWatch, and custom monitoring for comprehensive coverage
  • DHCP Snooping First - Always enable DHCP snooping before DAI (DAI depends on snooping database)
  • Static ARP for Gateways - Configure static ARP entries on critical servers for the default gateway
  • Monitor Gratuitous ARP - Pay special attention to unsolicited ARP replies
  • Small Broadcast Domains - Use VLANs to limit the scope of ARP-based attacks
  • Regular Audits - Periodically compare ARP tables across devices to identify anomalies

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/detecting-arp-poisoning-in-network-traffic of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Arp Poisoning In Network Traffic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Arp Poisoning In Network Traffic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Arp Poisoning In Network Traffic this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0
Re Iot Protodslsdzc/rev-skills135—~3.2kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Dfirtransilienceai/communitytools563—~1.5kAutomated safety check: PassMIT
Protocol Reverse Engineeringwshobson/agents40k8 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Re Iot Proto

    dslsdzc/rev-skills

    物联网协议:MQTT/CoAP/BLE/Zigbee;BLE 链路层(广播解析/配对加密)与 NFC/智能卡(ISO14443/APDU/MIFARE)。

    135 GitHub stars~3.2k tokensUpdated 6 days ago
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.

    40k GitHub starsUsed in 8 repos~3.2k tokens
    SecurityAuto-check passed
  • Traffic Analysis Pcap

    yaklang/hack-skills

    Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.8k tokensUpdated 28 days ago
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Detecting Arp Poisoning In Network Traffic

What does Detecting Arp Poisoning In Network Traffic do?

Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…. Detecting Arp Poisoning In Network Traffic is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC mapping changes, and duplicate IP addresses.

When should I use Detecting Arp Poisoning In Network Traffic?

Detecting Arp Poisoning In Network Traffic fits situations like: investigating suspected man-in-the-middle interception; session hijacking on a local network segment; building layer-2 anomaly detection for a SOC.

How do I install Detecting Arp Poisoning In Network Traffic in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-arp-poisoning-in-network-traffic -a claude-code`. Or copy the skill folder (skills/detecting-arp-poisoning-in-network-traffic in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-arp-poisoning-in-network-traffic in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Arp Poisoning In Network Traffic in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-arp-poisoning-in-network-traffic -a codex`. Or copy the skill folder (skills/detecting-arp-poisoning-in-network-traffic in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-arp-poisoning-in-network-traffic in your project. Codex loads it when a task matches its description.

Can I use Detecting Arp Poisoning In Network Traffic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-arp-poisoning-in-network-traffic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-arp-poisoning-in-network-traffic, .gemini/skills/detecting-arp-poisoning-in-network-traffic, .github/skills/detecting-arp-poisoning-in-network-traffic and .opencode/skills/detecting-arp-poisoning-in-network-traffic in your project.

What does Detecting Arp Poisoning In Network Traffic need to run?

Going by SKILL.md and its folder, Detecting Arp Poisoning In Network Traffic needs Python for the scripts in its folder and the command-line tools its instructions call (apt-get). Our summary lists: Python 3.

Does Detecting Arp Poisoning In Network Traffic access the network?

SKILL.md names 4 domains. As links in the text: csrc.nist.gov, cisco.com, comparitech.com and okta.com. This is read from the text; nothing was executed.

Is Detecting Arp Poisoning In Network Traffic safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Arp Poisoning In Network Traffic use?

Detecting Arp Poisoning In Network Traffic is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Arp Poisoning In Network Traffic use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 440 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Arp Poisoning In Network Traffic?

Skills that share tags, products or a category with Detecting Arp Poisoning In Network Traffic: Re Iot Proto (dslsdzc/rev-skills, 135 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars) and Dfir (transilienceai/communitytools, 563 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Arp Poisoning In Network Traffic?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.