Agent skill

Detecting Cryptomining In Cloud

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.

Apache-2.0Auto-check passedBusiness, Finance & HR

Install Detecting Cryptomining In Cloud

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-cryptomining-in-cloud --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-cryptomining-in-cloud .claude/skills/detecting-cryptomining-in-cloud && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-cryptomining-in-cloud
GitHub stars
34k
Token cost
~3.6k tokens
SKILL.md length
692 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.

  • Works in 6 steps: Establish Detection Through Multiple… → Monitor GuardDuty CryptoCurrency Findings → Analyze Network Traffic for Mining Pool… → …
  • Tasks that involve Crypto and DeFi analysis
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws and jq

What it does

Detecting Cryptomining In Cloud is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Business, Finance & HR, covering Crypto and DeFi analysis. It works with Microsoft Azure. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Crypto and DeFi analysis

Example prompts

  • “/detecting-cryptomining-in-cloud”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish Detection Through Multiple Signals
  2. Monitor GuardDuty CryptoCurrency Findings
  3. Analyze Network Traffic for Mining Pool Connections
  4. Detect Mining in Container Environments
  5. Respond and Contain Mining Activity
  6. Trace Initial Access Vector

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Cryptomining In Cloud loads about 3.6k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 692 words, ~3,628 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-cryptomining-in-cloud/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-cryptomining-in-cloud
description
This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
domain
cybersecurity
subdomain
cloud-security
tags
cryptomining-detection, cloud-abuse, resource-hijacking, guardduty-crypto, cost-anomaly
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1071
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, resource-development, monetization

Detecting Cryptomining in Cloud

When to Use

  • When cloud billing alerts indicate unexpected compute cost spikes
  • When GuardDuty generates CryptoCurrency or Impact finding types
  • When investigating compromised IAM credentials that may be used to launch mining instances
  • When monitoring container workloads for unauthorized process execution
  • When establishing proactive detection controls against resource hijacking attacks

Do not use for legitimate cryptocurrency mining operations, for non-cloud mining detection on physical hardware, or for general malware analysis unrelated to mining activity.

Prerequisites

  • Amazon GuardDuty enabled with Runtime Monitoring for EC2, ECS, and EKS
  • CloudWatch or Azure Monitor configured for compute utilization alerting
  • VPC Flow Logs enabled for network traffic analysis to mining pool IPs
  • AWS Cost Anomaly Detection or Azure Cost Management alerts configured

Workflow

Step 1: Establish Detection Through Multiple Signals

Deploy detection across four signal categories: cost anomalies, compute utilization, network traffic, and runtime processes.

bash
# AWS Cost Anomaly Detection
aws ce create-anomaly-monitor \
  --anomaly-monitor '{
    "MonitorName": "EC2CostSpike",
    "MonitorType": "DIMENSIONAL",
    "MonitorDimension": "SERVICE"
  }'

aws ce create-anomaly-subscription \
  --anomaly-subscription '{
    "SubscriptionName": "CryptoMiningAlert",
    "MonitorArnList": ["arn:aws:ce::123456789012:anomalymonitor/monitor-id"],
    "Subscribers": [{"Address": "security@company.com", "Type": "EMAIL"}],
    "Threshold": 50.0,
    "Frequency": "IMMEDIATE"
  }'

# CloudWatch alarm for CPU utilization spike
aws cloudwatch put-metric-alarm \
  --alarm-name HighCPUUtilization \
  --namespace AWS/EC2 \
  --metric-name CPUUtilization \
  --statistic Average \
  --period 300 \
  --threshold 90 \
  --comparison-operator GreaterThanThreshold \
  --evaluation-periods 3 \
  --alarm-actions "arn:aws:sns:us-east-1:123456789012:security-alerts"
Step 2: Monitor GuardDuty CryptoCurrency Findings

Configure alerting for GuardDuty findings specific to cryptocurrency mining activity on EC2, ECS, and EKS workloads.

Key GuardDuty finding types for cryptomining:

  • CryptoCurrency:EC2/BitcoinTool.B - Network connections to crypto-related domains
  • CryptoCurrency:Runtime/BitcoinTool.B - Runtime detection of mining process execution
  • Impact:EC2/BitcoinTool.B - EC2 instance communicating with known Bitcoin mining pools
  • Impact:Runtime/CryptoMinerExecuted - Crypto mining binary execution detected by runtime agent
bash
# EventBridge rule for cryptocurrency findings
aws events put-rule \
  --name CryptoMiningDetection \
  --event-pattern '{
    "source": ["aws.guardduty"],
    "detail-type": ["GuardDuty Finding"],
    "detail": {
      "type": [
        {"prefix": "CryptoCurrency:"},
        {"prefix": "Impact:EC2/BitcoinTool"},
        {"prefix": "Impact:Runtime/CryptoMiner"}
      ]
    }
  }'

# Auto-remediation Lambda for crypto findings
aws events put-targets \
  --rule CryptoMiningDetection \
  --targets '[{
    "Id": "CryptoAutoRemediate",
    "Arn": "arn:aws:lambda:us-east-1:123456789012:function/crypto-remediate"
  }]'
Step 3: Analyze Network Traffic for Mining Pool Connections

Monitor VPC Flow Logs and DNS queries for connections to known cryptocurrency mining pools operating on common ports (3333, 4444, 5555, 8333, 9999, 14444).

kql
// Sentinel KQL query for mining pool connections
AzureNetworkAnalytics_CL
| where TimeGenerated > ago(24h)
| where DestPort_d in (3333, 4444, 5555, 8333, 9999, 14444, 14433, 45700)
| summarize ConnectionCount = count(), BytesSent = sum(BytesSent_d)
            by SrcIP_s, DestIP_s, DestPort_d, bin(TimeGenerated, 1h)
| where ConnectionCount > 10
| project TimeGenerated, SrcIP_s, DestIP_s, DestPort_d, ConnectionCount, BytesSent
bash
# AWS Athena query for VPC Flow Logs mining pool detection
cat << 'EOF' > mining-detection.sql
SELECT srcaddr, dstaddr, dstport, protocol,
       COUNT(*) as connection_count,
       SUM(bytes) as total_bytes
FROM vpc_flow_logs
WHERE dstport IN (3333, 4444, 5555, 8333, 9999, 14444)
  AND action = 'ACCEPT'
  AND start >= date_add('hour', -24, now())
GROUP BY srcaddr, dstaddr, dstport, protocol
HAVING COUNT(*) > 10
ORDER BY connection_count DESC
EOF
Step 4: Detect Mining in Container Environments

Monitor ECS task definitions and EKS pod deployments for known mining container images and suspicious process execution.

bash
# Check for recently registered ECS task definitions with suspicious images
aws ecs list-task-definitions --sort DESC --max-items 50 | \
  jq -r '.taskDefinitionArns[]' | while read arn; do
    aws ecs describe-task-definition --task-definition "$arn" \
      --query 'taskDefinition.containerDefinitions[*].[name,image]' --output text
  done

# Known malicious mining images to watch for:
# - Images with high pull counts from unknown registries
# - Images containing xmrig, cpuminer, minergate, or ccminer binaries
# - Images with entrypoint pointing to /tmp/.hidden or /dev/shm paths

# Monitor CloudTrail for suspicious ECS/EKS activity
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=EventName,AttributeValue=RegisterTaskDefinition \
  --start-time $(date -d '-24 hours' +%Y-%m-%dT%H:%M:%S) \
  --query 'Events[*].[EventName,Username,EventTime]'
Step 5: Respond and Contain Mining Activity

Execute immediate containment actions when mining is confirmed, preserving forensic evidence before terminating the malicious workloads.

python
# Auto-remediation Lambda for cryptomining incidents
import boto3
import json

def lambda_handler(event, context):
    finding = event['detail']
    resource_type = finding['resource']['resourceType']

    if resource_type == 'Instance':
        instance_id = finding['resource']['instanceDetails']['instanceId']
        ec2 = boto3.client('ec2')

        # Snapshot EBS volumes for forensics before isolation
        volumes = ec2.describe_instances(InstanceIds=[instance_id])
        for reservation in volumes['Reservations']:
            for instance in reservation['Instances']:
                for vol in instance['BlockDeviceMappings']:
                    volume_id = vol['Ebs']['VolumeId']
                    ec2.create_snapshot(
                        VolumeId=volume_id,
                        Description=f'Forensic snapshot - crypto mining - {instance_id}',
                        TagSpecifications=[{
                            'ResourceType': 'snapshot',
                            'Tags': [{'Key': 'Incident', 'Value': 'CryptoMining'},
                                     {'Key': 'SourceInstance', 'Value': instance_id}]
                        }]
                    )

        # Disable API termination protection if set by attacker
        ec2.modify_instance_attribute(
            InstanceId=instance_id,
            DisableApiTermination={'Value': False}
        )

        # Isolate instance with empty security group
        vpc_id = finding['resource']['instanceDetails']['networkInterfaces'][0]['vpcId']
        isolation_sg = ec2.create_security_group(
            GroupName=f'crypto-isolation-{instance_id}',
            Description='Cryptomining isolation - no traffic allowed',
            VpcId=vpc_id
        )
        # Revoke default egress rule
        ec2.revoke_security_group_egress(
            GroupId=isolation_sg['GroupId'],
            IpPermissions=[{'IpProtocol': '-1', 'IpRanges': [{'CidrIp': '0.0.0.0/0'}]}]
        )
        ec2.modify_instance_attribute(
            InstanceId=instance_id,
            Groups=[isolation_sg['GroupId']]
        )

        return {'status': 'contained', 'instance': instance_id}
Step 6: Trace Initial Access Vector

Investigate CloudTrail logs to determine how the attacker gained access to deploy mining workloads. Common vectors include compromised IAM credentials, exposed access keys, and supply chain attacks through container images.

bash
# Trace the initial access for the compromised identity
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=Username,AttributeValue=compromised-user \
  --start-time 2025-02-01T00:00:00Z \
  --query 'Events[?EventName==`ConsoleLogin` || EventName==`GetSessionToken`].[EventTime,SourceIPAddress,EventName]' \
  --output table

# Check for RunInstances calls in unusual regions
for region in $(aws ec2 describe-regions --query 'Regions[*].RegionName' --output text); do
  count=$(aws cloudtrail lookup-events \
    --region $region \
    --lookup-attributes AttributeKey=EventName,AttributeValue=RunInstances \
    --start-time $(date -d '-7 days' +%Y-%m-%dT%H:%M:%S) \
    --query 'Events | length(@)')
  if [ "$count" -gt 0 ]; then
    echo "Region: $region - RunInstances calls: $count"
  fi
done

Key Concepts

TermDefinition
CryptojackingUnauthorized use of cloud compute resources to mine cryptocurrency, typically Monero (XMR) due to its CPU-friendly algorithm
Stratum ProtocolMining pool communication protocol operating on TCP ports 3333, 4444, or custom ports, identifiable in network flow logs
XMRigOpen-source Monero mining software commonly found in cryptojacking attacks, often deployed as a hidden binary in containers
API Termination ProtectionEC2 attribute that attackers enable to prevent security teams from quickly terminating compromised mining instances
Cost Anomaly DetectionAWS service that uses machine learning to identify unusual spending patterns that may indicate unauthorized resource usage
Runtime MonitoringGuardDuty capability that deploys agents to detect process-level activity including crypto mining binary execution
Attack SequenceGuardDuty Extended Threat Detection finding correlating credential theft, infrastructure deployment, and mining execution into a single Critical event
Show full SKILL.md (239 more words)Show less

Tools & Systems

  • Amazon GuardDuty: Detects cryptocurrency mining through network traffic analysis, DNS queries, and runtime process monitoring
  • AWS Cost Anomaly Detection: Machine learning-based service identifying unexpected cost increases from mining instance deployment
  • VPC Flow Logs: Network traffic metadata showing connections to mining pool IP addresses and ports
  • Falco: Open-source runtime security tool for detecting crypto mining process execution in containers
  • Amazon Detective: Graph-based investigation tool for tracing the attack path from initial access to mining deployment

Common Scenarios

Scenario: Compromised IAM Credentials Used for Large-Scale EC2 Mining

Context: Exposed IAM credentials from a public GitHub repository are used to launch 200 GPU instances across 8 AWS regions within 10 minutes. The attacker enables API termination protection and disables CloudTrail in each region.

Approach:

  1. AWS Cost Anomaly Detection triggers an immediate alert for $15,000+ hourly EC2 spend
  2. GuardDuty generates Stealth:IAMUser/CloudTrailLoggingDisabled and CryptoCurrency:EC2/BitcoinTool.B findings
  3. Immediately deactivate the compromised IAM access key
  4. Re-enable CloudTrail in all affected regions to restore visibility
  5. Disable API termination protection on all 200 instances and terminate them
  6. Create forensic snapshots of representative instances before termination
  7. Review the GitHub commit history to identify and remove the exposed credentials
  8. Deploy AWS Config rules preventing CloudTrail disabling and enforcing IMDSv2

Pitfalls: Failing to check all AWS regions for mining instances leaves active miners running in overlooked regions. Not disabling API termination protection before attempting to stop instances wastes response time.

Output Format

Cryptomining Incident Response Report
=======================================
Incident ID: INC-2025-0223-CRYPTO
Detection Time: 2025-02-23T14:23:00Z
Containment Time: 2025-02-23T14:41:00Z (18 minutes)

INITIAL ACCESS:
  Vector: Exposed IAM access key in public GitHub repository
  Credential: AKIAIOSFODNN7EXAMPLE (user: ci-deploy)
  First Malicious Activity: 2025-02-23T14:12:00Z

IMPACT:
  Instances Launched: 200 (p3.2xlarge GPU instances)
  Regions Affected: 8 (us-east-1, us-west-2, eu-west-1, eu-central-1, ...)
  Estimated Cost: $4,200 (18 minutes at $15,400/hour)
  Mining Pool: stratum+tcp://pool.supportxmr.com:3333
  Cryptocurrency: Monero (XMR)

DETECTION SIGNALS:
  [14:15] GuardDuty: Stealth:IAMUser/CloudTrailLoggingDisabled (HIGH)
  [14:18] Cost Anomaly: EC2 spend 4,200% above baseline
  [14:23] GuardDuty: CryptoCurrency:EC2/BitcoinTool.B (HIGH) x 200

CONTAINMENT ACTIONS:
  [14:25] IAM access key AKIAIOSFODNN7EXAMPLE deactivated
  [14:30] CloudTrail re-enabled in all 8 regions
  [14:35] API termination protection disabled on 200 instances
  [14:41] All 200 instances terminated

REMEDIATION:
  - Compromised access key deleted
  - GitHub repository secret scanning enabled
  - AWS Config rule deployed: cloudtrail-enabled (auto-remediate)
  - SCP deployed: deny ec2:RunInstances for GPU instance types without approval

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/detecting-cryptomining-in-cloud of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Cryptomining In Cloud next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Cryptomining In Cloud compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Cryptomining In Cloud this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Oracle Flashloan Analysisquillai-network/quillshield_skills129—~2.8kAutomated safety check: PassMIT
Defi Amm Securityaffaan-m/ECC274k1 repos~1.3kAutomated safety check: PassMIT
Soroban Oracle Data Feed Auditsickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Technical Analysttradermonty/claude-trading-skills3k5 repos~4.6kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3601 repos~2kAutomated safety check: PassApache-2.0

Similar skills

  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    129 GitHub stars~2.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Defi Amm Security

    affaan-m/ECC

    Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.

    274k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Soroban Oracle Data Feed Audit

    sickn33/agentic-awesome-skills

    DeFi price oracle integration and safety audit register: heartbeat bounds, stale price threshold reversion, and TWAP medianizer validation.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 5 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    360 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    269 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Detecting Cryptomining In Cloud

What does Detecting Cryptomining In Cloud do?

This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. Detecting Cryptomining In Cloud is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments.

When should I use Detecting Cryptomining In Cloud?

Detecting Cryptomining In Cloud fits situations like: tasks that involve Crypto and DeFi analysis.

How do I install Detecting Cryptomining In Cloud in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a claude-code`. Or copy the skill folder (skills/detecting-cryptomining-in-cloud in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-cryptomining-in-cloud in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Cryptomining In Cloud in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a codex`. Or copy the skill folder (skills/detecting-cryptomining-in-cloud in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-cryptomining-in-cloud in your project. Codex loads it when a task matches its description.

Can I use Detecting Cryptomining In Cloud in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-cryptomining-in-cloud -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-cryptomining-in-cloud, .gemini/skills/detecting-cryptomining-in-cloud, .github/skills/detecting-cryptomining-in-cloud and .opencode/skills/detecting-cryptomining-in-cloud in your project.

What does Detecting Cryptomining In Cloud need to run?

Going by SKILL.md and its folder, Detecting Cryptomining In Cloud needs Python for the scripts in its folder and the command-line tools its instructions call (aws and jq). Our summary lists: Python 3.

Does Detecting Cryptomining In Cloud access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detecting Cryptomining In Cloud safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Cryptomining In Cloud use?

Detecting Cryptomining In Cloud is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Cryptomining In Cloud use?

About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 539 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Cryptomining In Cloud?

Skills that share tags, products or a category with Detecting Cryptomining In Cloud: Oracle Flashloan Analysis (quillai-network/quillshield_skills, 129 stars), Defi Amm Security (affaan-m/ECC, 274k stars), Soroban Oracle Data Feed Audit (sickn33/agentic-awesome-skills, 47k stars) and Technical Analyst (tradermonty/claude-trading-skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Cryptomining In Cloud?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.