Oracle Flashloan Analysis
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .claude/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .claude/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloudType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .agents/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .agents/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .cursor/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .cursor/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/detecting-cryptomining-in-cloud--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .gemini/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .gemini/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloudInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .github/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .github/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .opencode/skills/detecting-cryptomining-in-cloud && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "detecting-cryptomining-in-cloud" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/detecting-cryptomining-in-cloud into .opencode/skills/detecting-cryptomining-in-cloud/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detecting-cryptomining-in-cloud", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
detecting-cryptomining-in-cloudThis skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.
Detecting Cryptomining In Cloud is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Business, Finance & HR, covering Crypto and DeFi analysis. It works with Microsoft Azure. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
awsjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Detecting Cryptomining In Cloud loads about 3.6k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 692 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 692 words, ~3,628 tokens.
.claude/skills/detecting-cryptomining-in-cloud/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for legitimate cryptocurrency mining operations, for non-cloud mining detection on physical hardware, or for general malware analysis unrelated to mining activity.
Deploy detection across four signal categories: cost anomalies, compute utilization, network traffic, and runtime processes.
# AWS Cost Anomaly Detection
aws ce create-anomaly-monitor \
--anomaly-monitor '{
"MonitorName": "EC2CostSpike",
"MonitorType": "DIMENSIONAL",
"MonitorDimension": "SERVICE"
}'
aws ce create-anomaly-subscription \
--anomaly-subscription '{
"SubscriptionName": "CryptoMiningAlert",
"MonitorArnList": ["arn:aws:ce::123456789012:anomalymonitor/monitor-id"],
"Subscribers": [{"Address": "security@company.com", "Type": "EMAIL"}],
"Threshold": 50.0,
"Frequency": "IMMEDIATE"
}'
# CloudWatch alarm for CPU utilization spike
aws cloudwatch put-metric-alarm \
--alarm-name HighCPUUtilization \
--namespace AWS/EC2 \
--metric-name CPUUtilization \
--statistic Average \
--period 300 \
--threshold 90 \
--comparison-operator GreaterThanThreshold \
--evaluation-periods 3 \
--alarm-actions "arn:aws:sns:us-east-1:123456789012:security-alerts"Configure alerting for GuardDuty findings specific to cryptocurrency mining activity on EC2, ECS, and EKS workloads.
Key GuardDuty finding types for cryptomining:
CryptoCurrency:EC2/BitcoinTool.B - Network connections to crypto-related domainsCryptoCurrency:Runtime/BitcoinTool.B - Runtime detection of mining process executionImpact:EC2/BitcoinTool.B - EC2 instance communicating with known Bitcoin mining poolsImpact:Runtime/CryptoMinerExecuted - Crypto mining binary execution detected by runtime agent# EventBridge rule for cryptocurrency findings
aws events put-rule \
--name CryptoMiningDetection \
--event-pattern '{
"source": ["aws.guardduty"],
"detail-type": ["GuardDuty Finding"],
"detail": {
"type": [
{"prefix": "CryptoCurrency:"},
{"prefix": "Impact:EC2/BitcoinTool"},
{"prefix": "Impact:Runtime/CryptoMiner"}
]
}
}'
# Auto-remediation Lambda for crypto findings
aws events put-targets \
--rule CryptoMiningDetection \
--targets '[{
"Id": "CryptoAutoRemediate",
"Arn": "arn:aws:lambda:us-east-1:123456789012:function/crypto-remediate"
}]'Monitor VPC Flow Logs and DNS queries for connections to known cryptocurrency mining pools operating on common ports (3333, 4444, 5555, 8333, 9999, 14444).
// Sentinel KQL query for mining pool connections
AzureNetworkAnalytics_CL
| where TimeGenerated > ago(24h)
| where DestPort_d in (3333, 4444, 5555, 8333, 9999, 14444, 14433, 45700)
| summarize ConnectionCount = count(), BytesSent = sum(BytesSent_d)
by SrcIP_s, DestIP_s, DestPort_d, bin(TimeGenerated, 1h)
| where ConnectionCount > 10
| project TimeGenerated, SrcIP_s, DestIP_s, DestPort_d, ConnectionCount, BytesSent# AWS Athena query for VPC Flow Logs mining pool detection
cat << 'EOF' > mining-detection.sql
SELECT srcaddr, dstaddr, dstport, protocol,
COUNT(*) as connection_count,
SUM(bytes) as total_bytes
FROM vpc_flow_logs
WHERE dstport IN (3333, 4444, 5555, 8333, 9999, 14444)
AND action = 'ACCEPT'
AND start >= date_add('hour', -24, now())
GROUP BY srcaddr, dstaddr, dstport, protocol
HAVING COUNT(*) > 10
ORDER BY connection_count DESC
EOFMonitor ECS task definitions and EKS pod deployments for known mining container images and suspicious process execution.
# Check for recently registered ECS task definitions with suspicious images
aws ecs list-task-definitions --sort DESC --max-items 50 | \
jq -r '.taskDefinitionArns[]' | while read arn; do
aws ecs describe-task-definition --task-definition "$arn" \
--query 'taskDefinition.containerDefinitions[*].[name,image]' --output text
done
# Known malicious mining images to watch for:
# - Images with high pull counts from unknown registries
# - Images containing xmrig, cpuminer, minergate, or ccminer binaries
# - Images with entrypoint pointing to /tmp/.hidden or /dev/shm paths
# Monitor CloudTrail for suspicious ECS/EKS activity
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=RegisterTaskDefinition \
--start-time $(date -d '-24 hours' +%Y-%m-%dT%H:%M:%S) \
--query 'Events[*].[EventName,Username,EventTime]'Execute immediate containment actions when mining is confirmed, preserving forensic evidence before terminating the malicious workloads.
# Auto-remediation Lambda for cryptomining incidents
import boto3
import json
def lambda_handler(event, context):
finding = event['detail']
resource_type = finding['resource']['resourceType']
if resource_type == 'Instance':
instance_id = finding['resource']['instanceDetails']['instanceId']
ec2 = boto3.client('ec2')
# Snapshot EBS volumes for forensics before isolation
volumes = ec2.describe_instances(InstanceIds=[instance_id])
for reservation in volumes['Reservations']:
for instance in reservation['Instances']:
for vol in instance['BlockDeviceMappings']:
volume_id = vol['Ebs']['VolumeId']
ec2.create_snapshot(
VolumeId=volume_id,
Description=f'Forensic snapshot - crypto mining - {instance_id}',
TagSpecifications=[{
'ResourceType': 'snapshot',
'Tags': [{'Key': 'Incident', 'Value': 'CryptoMining'},
{'Key': 'SourceInstance', 'Value': instance_id}]
}]
)
# Disable API termination protection if set by attacker
ec2.modify_instance_attribute(
InstanceId=instance_id,
DisableApiTermination={'Value': False}
)
# Isolate instance with empty security group
vpc_id = finding['resource']['instanceDetails']['networkInterfaces'][0]['vpcId']
isolation_sg = ec2.create_security_group(
GroupName=f'crypto-isolation-{instance_id}',
Description='Cryptomining isolation - no traffic allowed',
VpcId=vpc_id
)
# Revoke default egress rule
ec2.revoke_security_group_egress(
GroupId=isolation_sg['GroupId'],
IpPermissions=[{'IpProtocol': '-1', 'IpRanges': [{'CidrIp': '0.0.0.0/0'}]}]
)
ec2.modify_instance_attribute(
InstanceId=instance_id,
Groups=[isolation_sg['GroupId']]
)
return {'status': 'contained', 'instance': instance_id}Investigate CloudTrail logs to determine how the attacker gained access to deploy mining workloads. Common vectors include compromised IAM credentials, exposed access keys, and supply chain attacks through container images.
# Trace the initial access for the compromised identity
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=Username,AttributeValue=compromised-user \
--start-time 2025-02-01T00:00:00Z \
--query 'Events[?EventName==`ConsoleLogin` || EventName==`GetSessionToken`].[EventTime,SourceIPAddress,EventName]' \
--output table
# Check for RunInstances calls in unusual regions
for region in $(aws ec2 describe-regions --query 'Regions[*].RegionName' --output text); do
count=$(aws cloudtrail lookup-events \
--region $region \
--lookup-attributes AttributeKey=EventName,AttributeValue=RunInstances \
--start-time $(date -d '-7 days' +%Y-%m-%dT%H:%M:%S) \
--query 'Events | length(@)')
if [ "$count" -gt 0 ]; then
echo "Region: $region - RunInstances calls: $count"
fi
done| Term | Definition |
|---|---|
| Cryptojacking | Unauthorized use of cloud compute resources to mine cryptocurrency, typically Monero (XMR) due to its CPU-friendly algorithm |
| Stratum Protocol | Mining pool communication protocol operating on TCP ports 3333, 4444, or custom ports, identifiable in network flow logs |
| XMRig | Open-source Monero mining software commonly found in cryptojacking attacks, often deployed as a hidden binary in containers |
| API Termination Protection | EC2 attribute that attackers enable to prevent security teams from quickly terminating compromised mining instances |
| Cost Anomaly Detection | AWS service that uses machine learning to identify unusual spending patterns that may indicate unauthorized resource usage |
| Runtime Monitoring | GuardDuty capability that deploys agents to detect process-level activity including crypto mining binary execution |
| Attack Sequence | GuardDuty Extended Threat Detection finding correlating credential theft, infrastructure deployment, and mining execution into a single Critical event |
Context: Exposed IAM credentials from a public GitHub repository are used to launch 200 GPU instances across 8 AWS regions within 10 minutes. The attacker enables API termination protection and disables CloudTrail in each region.
Approach:
Pitfalls: Failing to check all AWS regions for mining instances leaves active miners running in overlooked regions. Not disabling API termination protection before attempting to stop instances wastes response time.
Cryptomining Incident Response Report
=======================================
Incident ID: INC-2025-0223-CRYPTO
Detection Time: 2025-02-23T14:23:00Z
Containment Time: 2025-02-23T14:41:00Z (18 minutes)
INITIAL ACCESS:
Vector: Exposed IAM access key in public GitHub repository
Credential: AKIAIOSFODNN7EXAMPLE (user: ci-deploy)
First Malicious Activity: 2025-02-23T14:12:00Z
IMPACT:
Instances Launched: 200 (p3.2xlarge GPU instances)
Regions Affected: 8 (us-east-1, us-west-2, eu-west-1, eu-central-1, ...)
Estimated Cost: $4,200 (18 minutes at $15,400/hour)
Mining Pool: stratum+tcp://pool.supportxmr.com:3333
Cryptocurrency: Monero (XMR)
DETECTION SIGNALS:
[14:15] GuardDuty: Stealth:IAMUser/CloudTrailLoggingDisabled (HIGH)
[14:18] Cost Anomaly: EC2 spend 4,200% above baseline
[14:23] GuardDuty: CryptoCurrency:EC2/BitcoinTool.B (HIGH) x 200
CONTAINMENT ACTIONS:
[14:25] IAM access key AKIAIOSFODNN7EXAMPLE deactivated
[14:30] CloudTrail re-enabled in all 8 regions
[14:35] API termination protection disabled on 200 instances
[14:41] All 200 instances terminated
REMEDIATION:
- Compromised access key deleted
- GitHub repository secret scanning enabled
- AWS Config rule deployed: cloudtrail-enabled (auto-remediate)
- SCP deployed: deny ec2:RunInstances for GPU instance types without approval© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/detecting-cryptomining-in-cloud of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Detecting Cryptomining In Cloud next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Detecting Cryptomining In Cloud this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Oracle Flashloan Analysisquillai-network/quillshield_skills | 129 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Defi Amm Securityaffaan-m/ECC | 274k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Soroban Oracle Data Feed Auditsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Technical Analysttradermonty/claude-trading-skills | 3k | 5 repos | ~4.6k | Automated safety check: Pass | MIT | |
| Polyclawchainstacklabs/polyclaw | 360 | 1 repos | ~2k | Automated safety check: Pass | Apache-2.0 |
quillai-network/quillshield_skills
Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.
affaan-m/ECC
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
sickn33/agentic-awesome-skills
DeFi price oracle integration and safety audit register: heartbeat bounds, stale price threshold reversion, and TWAP medianizer validation.
tradermonty/claude-trading-skills
This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.
chainstacklabs/polyclaw
Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.
helsome/folio
Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. Detecting Cryptomining In Cloud is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.
Detecting Cryptomining In Cloud fits situations like: tasks that involve Crypto and DeFi analysis.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a claude-code`. Or copy the skill folder (skills/detecting-cryptomining-in-cloud in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-cryptomining-in-cloud in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a codex`. Or copy the skill folder (skills/detecting-cryptomining-in-cloud in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-cryptomining-in-cloud in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-cryptomining-in-cloud, .gemini/skills/detecting-cryptomining-in-cloud, .github/skills/detecting-cryptomining-in-cloud and .opencode/skills/detecting-cryptomining-in-cloud in your project.
Going by SKILL.md and its folder, Detecting Cryptomining In Cloud needs Python for the scripts in its folder and the command-line tools its instructions call (aws and jq). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Detecting Cryptomining In Cloud is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 539 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Detecting Cryptomining In Cloud: Oracle Flashloan Analysis (quillai-network/quillshield_skills, 129 stars), Defi Amm Security (affaan-m/ECC, 274k stars), Soroban Oracle Data Feed Audit (sickn33/agentic-awesome-skills, 47k stars) and Technical Analyst (tradermonty/claude-trading-skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.