Agent skill

Detecting Ransomware Precursors In Network

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance…

Apache-2.0Auto-check passedSecurity

Install Detecting Ransomware Precursors In Network

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-ransomware-precursors-in-network -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-ransomware-precursors-in-network --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-ransomware-precursors-in-network .claude/skills/detecting-ransomware-precursors-in-network && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-ransomware-precursors-in-network
GitHub stars
34k
Token cost
~3.7k tokens
SKILL.md length
802 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance…

  • Works in 5 steps: Identify Ransomware Kill Chain Phases in… → Deploy Network Detection Rules → Create SIEM Correlation Rules → …
  • Tasks that involve Security operations
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl and python3; reaches feodotracker.abuse.ch and urlhaus.abuse.ch

What it does

Detecting Ransomware Precursors In Network is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts. Activates for requests involving pre-ransomware…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Security operations, OSINT and Red teaming and adversary simulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security operations
  • Tasks that involve OSINT
  • Tasks that involve Red teaming and adversary simulation

Example prompts

  • “Use the detecting-ransomware-precursors-in-network skill to detect early-stage ransomware indicators in network traffic before encryption begins…”
  • “/detecting-ransomware-precursors-in-network”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify Ransomware Kill Chain Phases in Network Traffic
  2. Deploy Network Detection Rules
  3. Create SIEM Correlation Rules
  4. Integrate Threat Intelligence
  5. Establish Alert Triage and Escalation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • feodotracker.abuse.ch
    • urlhaus.abuse.ch
    • threatfox.abuse.ch
    • cisa.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Ransomware Precursors In Network loads about 3.7k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 802 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 802 words, ~3,723 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-ransomware-precursors-in-network/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
detecting-ransomware-precursors-in-network
description
Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior. Uses network detection tools (Zeek, Suricata, Arkime), SIEM correlation rules, and threat intelligence feeds to identify ransomware precursor patterns such as Cobalt Strike beacons, Mimikatz network signatures, and RDP brute-force attempts. Activates for requests involving pre-ransomware detection, network-based ransomware indicators, or early warning ransomware monitoring.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, detection, network-security, incident-response, defense
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1078, T1190, T1059, T1003, T1110
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, positioning, monetization

Detecting Ransomware Precursors in Network Traffic

When to Use

  • Building detection rules for pre-ransomware network activity (the average time from Cobalt Strike deployment to encryption is 17 minutes)
  • Monitoring for initial access broker (IAB) indicators that precede ransomware deployment
  • Creating SIEM correlation rules that chain multiple precursor events into high-confidence alerts
  • Tuning network detection systems to distinguish ransomware staging from normal administrative activity
  • Investigating suspicious network patterns that may indicate ransomware operators have established a foothold

Do not use for post-encryption response (see recovering-from-ransomware-attack). This skill focuses on the pre-encryption detection window where containment can prevent data loss.

Prerequisites

  • Network detection platform (Zeek/Bro, Suricata, or Arkime/Moloch) deployed on network TAP or SPAN ports
  • SIEM platform (Splunk, Elastic Security, Microsoft Sentinel, or QRadar) ingesting network logs
  • Threat intelligence feeds covering ransomware IOCs (CISA, abuse.ch, OTX, MISP)
  • Network flow data (NetFlow/IPFIX) from core routers and firewalls
  • DNS query logging from internal resolvers
  • Full packet capture capability for incident investigation

Workflow

Step 1: Identify Ransomware Kill Chain Phases in Network Traffic

Map network-observable indicators to each pre-encryption phase:

Kill Chain PhaseNetwork IndicatorsDetection Source
Initial AccessRDP brute force, VPN credential stuffing, phishing callbackFirewall logs, IDS, proxy logs
C2 EstablishmentCobalt Strike beacons (HTTPS/DNS), Sliver/Brute Ratel callbacksZeek SSL/HTTP logs, DNS logs
Credential HarvestingNTLM relay, Kerberoasting, DCSync trafficZeek Kerberos/NTLM logs, DC logs
ReconnaissanceInternal port scanning, AD enumeration (LDAP/SMB)Zeek conn.log, flow data
Lateral MovementPsExec/WMI/WinRM traffic, RDP pivoting, SMB file copiesZeek SMB/DCE-RPC logs
StagingData aggregation, archive creation, cloud upload prepProxy logs, DNS logs, DLP
Step 2: Deploy Network Detection Rules

Suricata rules for common ransomware precursors:

yaml
# Cobalt Strike default HTTPS beacon profile detection
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"RANSOMWARE PRECURSOR - Cobalt Strike Default TLS Certificate"; tls.cert_subject; content:"Major Cobalt Strike"; sid:3000001; rev:1;)

# Cobalt Strike DNS beacon
alert dns $HOME_NET any -> any 53 (msg:"RANSOMWARE PRECURSOR - Cobalt Strike DNS Beacon Pattern"; dns.query; pcre:"/^[a-z0-9]{3}\.[a-z]{4,8}\./"; threshold:type both, track by_src, count 50, seconds 60; sid:3000002; rev:1;)

# Mimikatz network signature (DCSync - DRS GetNCChanges)
alert tcp $HOME_NET any -> $HOME_NET 135 (msg:"RANSOMWARE PRECURSOR - Possible DCSync/Mimikatz"; content:"|05 00 0b|"; offset:0; depth:3; content:"|e3 51 4d 2b 4b 47 15 d2|"; sid:3000003; rev:1;)

# Internal network scanning (many connections, few bytes)
alert tcp $HOME_NET any -> $HOME_NET any (msg:"RANSOMWARE PRECURSOR - Internal Port Scan"; flags:S; threshold:type both, track by_src, count 100, seconds 10; sid:3000004; rev:1;)

# PsExec service installation over SMB
alert tcp $HOME_NET any -> $HOME_NET 445 (msg:"RANSOMWARE PRECURSOR - PsExec Service Install"; content:"|ff|SMB"; content:"PSEXESVC"; nocase; sid:3000005; rev:1;)

# RDP brute force from internal host (lateral movement)
alert tcp $HOME_NET any -> $HOME_NET 3389 (msg:"RANSOMWARE PRECURSOR - Internal RDP Brute Force"; flow:to_server,established; threshold:type both, track by_src, count 20, seconds 60; sid:3000006; rev:1;)

# Large SMB file transfer (data staging)
alert tcp $HOME_NET any -> $HOME_NET 445 (msg:"RANSOMWARE PRECURSOR - Large SMB Transfer Possible Staging"; flow:to_server,established; dsize:>60000; threshold:type both, track by_src, count 100, seconds 300; sid:3000007; rev:1;)

Zeek scripts for behavioral detection:

zeek
# detect_ransomware_precursors.zeek
# Detect high volume of failed SMB connections (credential testing)

@load base/protocols/smb

module RansomwarePrecursor;

export {
    redef enum Notice::Type += {
        SMB_Brute_Force,
        Suspicious_Internal_Scan,
        Excessive_DNS_Queries,
        SMB_Admin_Share_Access,
    };

    const smb_fail_threshold = 10 &redef;
    const scan_threshold = 50 &redef;
    const dns_query_threshold = 200 &redef;
}

global smb_fail_count: table[addr] of count &default=0 &create_expire=5min;
global conn_count: table[addr] of set[addr] &create_expire=1min;

event smb2_message(c: connection, hdr: SMB2::Header, is_orig: bool) {
    if (hdr$status != 0) {
        ++smb_fail_count[c$id$orig_h];
        if (smb_fail_count[c$id$orig_h] >= smb_fail_threshold) {
            NOTICE([$note=SMB_Brute_Force,
                    $msg=fmt("Host %s has %d failed SMB attempts", c$id$orig_h, smb_fail_count[c$id$orig_h]),
                    $src=c$id$orig_h,
                    $identifier=cat(c$id$orig_h)]);
        }
    }
}

event new_connection(c: connection) {
    if (c$id$orig_h in Site::local_nets && c$id$resp_h in Site::local_nets) {
        if (c$id$orig_h !in conn_count)
            conn_count[c$id$orig_h] = set();
        add conn_count[c$id$orig_h][c$id$resp_h];
        if (|conn_count[c$id$orig_h]| >= scan_threshold) {
            NOTICE([$note=Suspicious_Internal_Scan,
                    $msg=fmt("Host %s connected to %d internal hosts in 1 min", c$id$orig_h, |conn_count[c$id$orig_h]|),
                    $src=c$id$orig_h,
                    $identifier=cat(c$id$orig_h)]);
        }
    }
}
Step 3: Create SIEM Correlation Rules

Splunk correlation for ransomware precursor chain:

spl
| tstats count FROM datamodel=Network_Traffic
  WHERE earliest=-24h All_Traffic.dest_port IN (445, 135, 139, 3389, 5985, 5986)
    AND All_Traffic.src_ip IN 10.0.0.0/8
    AND All_Traffic.dest_ip IN 10.0.0.0/8
  BY All_Traffic.src_ip, All_Traffic.dest_port, _time span=1h
| stats dc(All_Traffic.dest_port) as port_count,
        values(All_Traffic.dest_port) as ports,
        count as total_conns
  BY All_Traffic.src_ip
| where port_count >= 3 AND total_conns > 50
| rename All_Traffic.src_ip as src_ip
| lookup threat_intel_ioc ip as src_ip OUTPUT threat_type
| eval risk_score = case(
    port_count >= 5 AND total_conns > 200, "CRITICAL",
    port_count >= 3 AND total_conns > 50, "HIGH",
    1=1, "MEDIUM")
| table src_ip, ports, port_count, total_conns, risk_score, threat_type

Microsoft Sentinel KQL - Ransomware precursor correlation:

kql
let timeframe = 24h;
let RDPBruteForce = SecurityEvent
| where TimeGenerated > ago(timeframe)
| where EventID == 4625
| where LogonType == 10
| summarize FailedRDP = count() by TargetAccount, IpAddress, bin(TimeGenerated, 1h)
| where FailedRDP > 10;
let SuspiciousSMB = SecurityEvent
| where TimeGenerated > ago(timeframe)
| where EventID == 5145
| where ShareName has "ADMIN$" or ShareName has "C$" or ShareName has "IPC$"
| summarize AdminShareAccess = count() by SubjectUserName, IpAddress, bin(TimeGenerated, 1h)
| where AdminShareAccess > 5;
let ServiceInstalls = SecurityEvent
| where TimeGenerated > ago(timeframe)
| where EventID == 7045
| where ServiceName has_any ("PSEXESVC", "meterpreter", "beacon");
RDPBruteForce
| join kind=inner SuspiciousSMB on IpAddress
| project TimeGenerated, IpAddress, TargetAccount, FailedRDP, SubjectUserName, AdminShareAccess
| extend AlertTitle = "Ransomware Precursor: RDP Brute Force + Admin Share Access"
Step 4: Integrate Threat Intelligence

Configure automated IOC feeds for known ransomware infrastructure:

bash
# Download and update ransomware C2 blocklists
# abuse.ch Feodo Tracker (Cobalt Strike, TrickBot, BazarLoader C2s)
curl -s https://feodotracker.abuse.ch/downloads/ipblocklist.csv | \
  grep -v "^#" | cut -d, -f2 > /opt/threat-intel/feodo_ips.txt

# abuse.ch URLhaus (malware distribution URLs)
curl -s https://urlhaus.abuse.ch/downloads/csv_recent/ | \
  grep -v "^#" | cut -d, -f3 > /opt/threat-intel/urlhaus_urls.txt

# abuse.ch ThreatFox (ransomware IOCs)
curl -s https://threatfox.abuse.ch/export/csv/recent/ | \
  grep -i "ransomware" | cut -d, -f3 > /opt/threat-intel/ransomware_iocs.txt

# CISA Known Exploited Vulnerabilities (initial access vectors)
curl -s https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json | \
  python3 -c "import json,sys; data=json.load(sys.stdin); [print(v['cveID'],v['vendorProject'],v['product']) for v in data['vulnerabilities'] if 'ransomware' in v.get('knownRansomwareCampaignUse','').lower()]"
Step 5: Establish Alert Triage and Escalation

Define triage procedures based on precursor confidence level:

Alert TypeConfidenceResponse TimeAction
Confirmed Cobalt Strike beaconHigh15 minutesIsolate host immediately, trigger IR
DCSync/Kerberoasting from non-DCHigh15 minutesDisable account, isolate host, trigger IR
Internal port scan + admin share accessMedium-High30 minutesInvestigate source host, check EDR telemetry
RDP brute force from internal hostMedium1 hourVerify if legitimate admin activity, check host
Unusual DNS query volumeLow-Medium4 hoursCheck for DNS tunneling, correlate with other alerts

Key Concepts

TermDefinition
Ransomware PrecursorNetwork activity that precedes ransomware encryption, including C2 communication, lateral movement, and data staging
Dwell TimeTime between initial compromise and ransomware deployment, averaging 21 days but sometimes as short as 17 minutes
Initial Access Broker (IAB)Threat actors who sell compromised network access to ransomware operators on dark web markets
BeaconingPeriodic C2 callbacks from implants (Cobalt Strike, Sliver) that can be detected by analyzing connection timing patterns
KerberoastingCredential harvesting technique requesting Kerberos service tickets for offline cracking, detectable via unusual TGS-REQ patterns
DCSyncTechnique using Directory Replication Service to extract password hashes from domain controllers, critical ransomware precursor
Show full SKILL.md (297 more words)Show less

Tools & Systems

  • Zeek (formerly Bro): Network analysis framework generating structured logs for SMB, Kerberos, DNS, HTTP, and TLS connections
  • Suricata: High-performance IDS/IPS with protocol analysis and multi-threading support for ransomware signature detection
  • Arkime (formerly Moloch): Full packet capture and search platform for deep forensic investigation of network events
  • RITA (Real Intelligence Threat Analytics): Open-source tool for detecting beaconing, DNS tunneling, and long connections in Zeek logs
  • AC-Hunter: Network threat hunting platform from Active Countermeasures for beacon detection and C2 identification

Common Scenarios

Scenario: Detecting LockBit Precursors in a Manufacturing Network

Context: A manufacturing company's SOC receives an alert for unusual SMB traffic from a workstation (10.1.5.42) in the engineering department. The workstation connected to 47 internal hosts on port 445 within 5 minutes at 2:00 AM.

Approach:

  1. Zeek conn.log analysis shows 10.1.5.42 initiated connections to 47 unique internal IPs on port 445, 135, and 3389 between 01:55-02:05
  2. Zeek ssl.log reveals an outbound HTTPS connection to 185.x.x.x every 60 seconds with consistent 48-byte payloads (Cobalt Strike beacon pattern)
  3. RITA beacon analysis confirms high beacon score (0.96) for the external IP with 60-second jitter
  4. Zeek kerberos.log shows TGS-REQ for multiple SPN accounts from 10.1.5.42 (Kerberoasting)
  5. SMB tree_connect events show access to ADMIN$ shares on 12 hosts (lateral movement staging)
  6. Containment: Host isolated, credentials for engineering user reset, blocking rule for C2 IP deployed
  7. Full IR initiated before ransomware deployment could begin

Pitfalls:

  • Dismissing internal port scans as vulnerability scanner activity without verifying the source is an authorized scanner
  • Not correlating individual low-severity alerts (DNS anomaly + SMB access + failed logins) into a high-severity chain
  • Setting detection thresholds too high to avoid false positives, missing low-and-slow reconnaissance
  • Ignoring encrypted traffic analysis (JA3/JA4 fingerprinting) that can identify Cobalt Strike even in TLS tunnels

Output Format

## Ransomware Precursor Detection Alert

**Alert ID**: [SIEM-generated ID]
**Detection Time**: [Timestamp]
**Source Host**: [IP / Hostname]
**Confidence**: [High / Medium / Low]
**Kill Chain Phase**: [Initial Access / C2 / Credential Harvest / Recon / Lateral Movement / Staging]

### Indicators Detected
| Indicator | Source | Detail | MITRE ATT&CK |
|-----------|--------|--------|--------------|
| [Type] | [Zeek/Suricata/SIEM] | [Description] | [T-ID] |

### Correlation Chain
1. [Timestamp] - [Event 1]
2. [Timestamp] - [Event 2]
3. [Timestamp] - [Event 3]

### Recommended Actions
- [ ] Isolate source host from network
- [ ] Check EDR telemetry for host-based indicators
- [ ] Reset credentials for affected user accounts
- [ ] Block identified C2 infrastructure
- [ ] Escalate to incident response team

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/detecting-ransomware-precursors-in-network of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Ransomware Precursors In Network next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Ransomware Precursors In Network compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Ransomware Precursors In Network this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Threat Intelligence OSINTzhaoxuya520/reverse-skill41k1 repos~1kAutomated safety check: PassMIT
Councilwarpdotdev/common-skills6101 repos~1.8kAutomated safety check: PassMIT
Enrich Iocdandye/ai-runbooks127—~702Automated safety check: PassApache-2.0
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    41k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Council

    warpdotdev/common-skills

    Run a model-diverse subagent council to investigate the same problem from multiple perspectives, compare findings, and produce a final recommendation.

    610 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Enrich Ioc

    dandye/ai-runbooks

    Enrich an IOC (IP, domain, hash, URL) with threat intelligence.

    127 GitHub stars~702 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

    8.6k GitHub stars~2.2k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Detecting Ransomware Precursors In Network

What does Detecting Ransomware Precursors In Network do?

Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance…. Detecting Ransomware Precursors In Network is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects early-stage ransomware indicators in network traffic before encryption begins, including initial access broker activity, command-and-control beaconing, credential harvesting, reconnaissance scanning, and staging behavior.

When should I use Detecting Ransomware Precursors In Network?

Detecting Ransomware Precursors In Network fits situations like: tasks that involve Security operations; tasks that involve OSINT; tasks that involve Red teaming and adversary simulation.

How do I install Detecting Ransomware Precursors In Network in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-ransomware-precursors-in-network -a claude-code`. Or copy the skill folder (skills/detecting-ransomware-precursors-in-network in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-ransomware-precursors-in-network in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Ransomware Precursors In Network in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-ransomware-precursors-in-network -a codex`. Or copy the skill folder (skills/detecting-ransomware-precursors-in-network in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-ransomware-precursors-in-network in your project. Codex loads it when a task matches its description.

Can I use Detecting Ransomware Precursors In Network in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-ransomware-precursors-in-network -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-ransomware-precursors-in-network, .gemini/skills/detecting-ransomware-precursors-in-network, .github/skills/detecting-ransomware-precursors-in-network and .opencode/skills/detecting-ransomware-precursors-in-network in your project.

What does Detecting Ransomware Precursors In Network need to run?

Going by SKILL.md and its folder, Detecting Ransomware Precursors In Network needs Python for the scripts in its folder and the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.

Does Detecting Ransomware Precursors In Network access the network?

SKILL.md names 4 domains. In commands or code: feodotracker.abuse.ch, urlhaus.abuse.ch, threatfox.abuse.ch and cisa.gov; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Detecting Ransomware Precursors In Network safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Ransomware Precursors In Network use?

Detecting Ransomware Precursors In Network is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Ransomware Precursors In Network use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Ransomware Precursors In Network?

Skills that share tags, products or a category with Detecting Ransomware Precursors In Network: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Threat Intelligence OSINT (zhaoxuya520/reverse-skill, 41k stars), Council (warpdotdev/common-skills, 610 stars) and Enrich Ioc (dandye/ai-runbooks, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Ransomware Precursors In Network?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.