Kubernetes Network Security Audit
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
Agent skill
Deploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricata --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .claude/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .claude/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricataType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricata --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .agents/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .agents/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricata --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .cursor/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .cursor/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-network-intrusion-prevention-with-suricata--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricata --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .gemini/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .gemini/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricataInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .github/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .github/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-intrusion-prevention-with-suricata --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-network-intrusion-prevention-with-suricata .opencode/skills/implementing-network-intrusion-prevention-with-suricata && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-network-intrusion-prevention-with-suricata" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-intrusion-prevention-with-suricata into .opencode/skills/implementing-network-intrusion-prevention-with-suricata/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-intrusion-prevention-with-suricata", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-network-intrusion-prevention-with-suricataDeploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and…
Implementing Network Intrusion Prevention With Suricata is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and logging integration. Use when deploying real-time inline traffic inspection to actively block malicious traffic, or when tuning Suricata rules and performance for production IDS/IPS deployment.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
apt-getjqFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.suricata.iorules.emergingthreats.netgithub.comsuricata-update.readthedocs.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Network Intrusion Prevention With Suricata loads about 3k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 453 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo add-apt-repository ppa:oisf/suricata-stablesudo apt-get updatesudo apt-get install -y suricata suricata-updatesudo iptables -I FORWARD -j NFQUEUE --queue-num 0 --queue-bypasssudo iptables -I FORWARD -j NFQUEUE --queue-balance 0:3 --queue-bypasssudo iptables-save > /etc/iptables/rules.v4sudo suricata-updatesudo suricata-update list-sourcessudo suricata-update enable-source et/pro secret-code=YOUR_OINKCODEsudo suricata-update enable-source oisf/trafficidAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 453 words, ~3,000 tokens.
.claude/skills/implementing-network-intrusion-prevention-with-suricata/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Suricata is a high-performance, open-source network threat detection engine developed by the Open Information Security Foundation (OISF). It functions as an IDS (Intrusion Detection System), IPS (Intrusion Prevention System), and network security monitoring tool. Suricata performs deep packet inspection using extensive rule sets, protocol analysis, and file extraction capabilities. In IPS mode, Suricata inspects packets inline and can actively block malicious traffic. This skill covers deploying Suricata in IPS mode, configuring rulesets, writing custom rules, performance tuning, and integration with logging infrastructure.
| Mode | Function | Network Position |
|---|---|---|
| IDS (AF_PACKET) | Passive monitoring, alert-only | TAP/SPAN mirror |
| IPS (NFQUEUE) | Inline blocking via netfilter | In traffic path |
| IPS (AF_PACKET) | Inline blocking via AF_PACKET | Bridge between interfaces |
| Offline (PCAP) | Analyze captured traffic files | N/A |
Suricata rules follow a structured format:
action protocol src_ip src_port -> dst_ip dst_port (rule_options;)alert, pass, drop, reject, rejectsrc, rejectdst, rejectbothtcp, udp, icmp, ip, http, tls, dns, smtp, ftp-> (unidirectional), <> (bidirectional)# Add Suricata PPA (Ubuntu)
sudo add-apt-repository ppa:oisf/suricata-stable
sudo apt-get update
sudo apt-get install -y suricata suricata-update
# Verify installation
suricata --build-info
suricata -VEdit /etc/suricata/suricata.yaml:
%YAML 1.1
---
vars:
address-groups:
HOME_NET: "[10.0.0.0/8,172.16.0.0/12,192.168.0.0/16]"
EXTERNAL_NET: "!$HOME_NET"
HTTP_SERVERS: "$HOME_NET"
DNS_SERVERS: "[10.0.1.10/32,10.0.1.11/32]"
SMTP_SERVERS: "$HOME_NET"
port-groups:
HTTP_PORTS: "80"
SHELLCODE_PORTS: "!80"
SSH_PORTS: "22"
DNS_PORTS: "53"
# IPS mode with NFQUEUE
nfq:
mode: accept
repeat-mark: 1
repeat-mask: 1
route-queue: 2
fail-open: yes
# Threading configuration
threading:
set-cpu-affinity: yes
cpu-affinity:
- management-cpu-set:
cpu: [0]
- receive-cpu-set:
cpu: [1,2]
- worker-cpu-set:
cpu: [3,4,5,6,7]
mode: exclusive
# Detection engine
detect-engine:
- profile: high
- custom-values:
toclient-groups: 50
toserver-groups: 50
- sgh-mpm-context: auto
- inspection-recursion-limit: 3000
# Stream engine
stream:
memcap: 512mb
checksum-validation: yes
inline: auto
reassembly:
memcap: 1gb
depth: 1mb
toserver-chunk-size: 2560
toclient-chunk-size: 2560
# Logging configuration
outputs:
- eve-log:
enabled: yes
filetype: regular
filename: /var/log/suricata/eve.json
types:
- alert:
payload: yes
payload-buffer-size: 4kb
payload-printable: yes
packet: yes
metadata: yes
tagged-packets: yes
- http:
extended: yes
- dns:
query: yes
answer: yes
- tls:
extended: yes
- files:
force-magic: yes
force-hash: [md5, sha256]
- flow
- netflow
- stats:
totals: yes
threads: no
deltas: yes
- fast:
enabled: yes
filename: /var/log/suricata/fast.log
- stats:
enabled: yes
filename: /var/log/suricata/stats.log
interval: 30
# Rule files
default-rule-path: /var/lib/suricata/rules
rule-files:
- suricata.rulesSet up iptables to redirect traffic through Suricata:
# Enable IP forwarding
echo 1 > /proc/sys/net/ipv4/ip_forward
# Redirect FORWARD chain to NFQUEUE
sudo iptables -I FORWARD -j NFQUEUE --queue-num 0 --queue-bypass
# For multi-queue (better performance)
sudo iptables -I FORWARD -j NFQUEUE --queue-balance 0:3 --queue-bypass
# Save iptables rules
sudo iptables-save > /etc/iptables/rules.v4Alternative: AF_PACKET inline mode between two interfaces:
# In suricata.yaml
af-packet:
- interface: eth0
cluster-id: 98
cluster-type: cluster_flow
defrag: yes
use-mmap: yes
copy-mode: ips
copy-iface: eth1
- interface: eth1
cluster-id: 97
cluster-type: cluster_flow
defrag: yes
use-mmap: yes
copy-mode: ips
copy-iface: eth0# Update rules from default sources (ET Open)
sudo suricata-update
# List available rule sources
sudo suricata-update list-sources
# Enable ET Pro (requires license key)
sudo suricata-update enable-source et/pro secret-code=YOUR_OINKCODE
# Enable additional sources
sudo suricata-update enable-source oisf/trafficid
sudo suricata-update enable-source ptresearch/attackdetection
sudo suricata-update enable-source sslbl/ssl-fp-blacklist
# Disable specific rules that generate false positives
echo "2100498" >> /etc/suricata/disable.conf
echo "group:emerging-policy.rules" >> /etc/suricata/disable.conf
# Modify rule actions (change alert to drop)
echo 're:ET MALWARE' >> /etc/suricata/modify.conf
# Apply updates
sudo suricata-update --reload-command="suricatasc -c reload-rules"Create /var/lib/suricata/rules/local.rules:
# Detect potential reverse shell over TCP
drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"LOCAL Potential Reverse Shell - /bin/bash in payload"; flow:to_server,established; content:"/bin/bash"; content:"-i"; within:20; classtype:trojan-activity; sid:1000001; rev:1;)
# Block known malicious user agent
drop http $HOME_NET any -> $EXTERNAL_NET any (msg:"LOCAL Malicious User-Agent - Cobalt Strike"; http.user_agent; content:"Mozilla/5.0 (compatible|3b| MSIE 9.0|3b| Windows NT 6.1|3b| WOW64|3b| Trident/5.0)"; classtype:trojan-activity; sid:1000002; rev:1;)
# Detect DNS query for known DGA domain pattern
alert dns $HOME_NET any -> any 53 (msg:"LOCAL Suspicious DGA Domain Query"; dns.query; content:".top"; pcre:"/^[a-z0-9]{12,30}\.(top|xyz|club|online|site)$/"; classtype:bad-unknown; sid:1000003; rev:1;)
# Detect large DNS TXT response (potential C2)
alert dns any 53 -> $HOME_NET any (msg:"LOCAL Large DNS TXT Response - Potential C2"; dns.opcode:0; content:"|00 10|"; byte_test:2,>,500,0,relative; classtype:bad-unknown; sid:1000004; rev:1;)
# Block outbound traffic to Tor exit nodes
drop tcp $HOME_NET any -> [100.2.18.10,104.244.76.13,109.70.100.1] any (msg:"LOCAL Outbound Connection to Known Tor Exit Node"; classtype:policy-violation; sid:1000005; rev:1;)
# Detect SMB lateral movement attempts
alert tcp $HOME_NET any -> $HOME_NET 445 (msg:"LOCAL Internal SMB Connection - Possible Lateral Movement"; flow:to_server,established; content:"|ff|SMB"; offset:4; depth:4; threshold:type both,track by_src,count 5,seconds 60; classtype:attempted-admin; sid:1000006; rev:1;)
# Detect PowerShell download cradle
drop http $HOME_NET any -> $EXTERNAL_NET any (msg:"LOCAL PowerShell Download Cradle Detected"; http.user_agent; content:"PowerShell"; nocase; http.method; content:"GET"; classtype:trojan-activity; sid:1000007; rev:1;)
# Detect ICMP tunneling (large ICMP packets)
alert icmp $HOME_NET any -> $EXTERNAL_NET any (msg:"LOCAL Oversized ICMP Packet - Possible Tunneling"; dsize:>800; threshold:type both,track by_src,count 10,seconds 60; classtype:bad-unknown; sid:1000008; rev:1;)# Test configuration
sudo suricata -T -c /etc/suricata/suricata.yaml
# Start in NFQUEUE IPS mode
sudo suricata -c /etc/suricata/suricata.yaml -q 0
# Start with AF_PACKET inline mode
sudo suricata -c /etc/suricata/suricata.yaml --af-packet
# Start as systemd service
sudo systemctl enable suricata
sudo systemctl start suricata
# Monitor performance stats
tail -f /var/log/suricata/stats.log
# Reload rules without restart
sudo suricatasc -c reload-rules# Check kernel drops
sudo suricatasc -c dump-counters | grep -E "capture.kernel_drops|decoder.pkts"
# Monitor EVE JSON alerts
tail -f /var/log/suricata/eve.json | jq 'select(.event_type=="alert")'
# Check rule loading
grep -c "rules loaded" /var/log/suricata/suricata.log
# Memory usage
sudo suricatasc -c dump-counters | grep memuse# Identify noisy rules
cat /var/log/suricata/eve.json | jq -r 'select(.event_type=="alert") | .alert.signature_id' | sort | uniq -c | sort -rn | head -20
# Suppress specific rules per source
echo "suppress gen_id 1, sig_id 2100498, track by_src, ip 10.0.5.0/24" >> /etc/suricata/threshold.config
# Rate-limit alerts
echo "rate_filter gen_id 1, sig_id 2100366, track by_src, count 10, seconds 60, new_action alert, timeout 300" >> /etc/suricata/threshold.configpass rules for known-good traffic to reduce processing loadsuricata-update daily via cron to keep signatures current© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-network-intrusion-prevention-with-suricata of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Network Intrusion Prevention With Suricata next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Network Intrusion Prevention With Suricata this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Google Cloud PAM Helpergoogle/skills | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit | 220 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Runtime Provisionernealbridges/VulnHunter | 678 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
AgentSecOps/SecOpsAgentKit
Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.
nealbridges/VulnHunter
VulnHunter sandbox-depth decision procedure. An agent skill from nealbridges/VulnHunter.
Sergei-thinker/vpn-setup
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Deploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and…. Implementing Network Intrusion Prevention With Suricata is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and logging integration.
Implementing Network Intrusion Prevention With Suricata fits situations like: deploying real-time inline traffic inspection to actively block malicious traffic; tuning Suricata rules and performance for production IDS/IPS deployment.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a claude-code`. Or copy the skill folder (skills/implementing-network-intrusion-prevention-with-suricata in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-network-intrusion-prevention-with-suricata in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a codex`. Or copy the skill folder (skills/implementing-network-intrusion-prevention-with-suricata in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-network-intrusion-prevention-with-suricata in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-intrusion-prevention-with-suricata -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-network-intrusion-prevention-with-suricata, .gemini/skills/implementing-network-intrusion-prevention-with-suricata, .github/skills/implementing-network-intrusion-prevention-with-suricata and .opencode/skills/implementing-network-intrusion-prevention-with-suricata in your project.
Going by SKILL.md and its folder, Implementing Network Intrusion Prevention With Suricata needs Python for the scripts in its folder and the command-line tools its instructions call (apt-get and jq). Our summary lists: Python 3.
SKILL.md names 4 domains. As links in the text: docs.suricata.io, rules.emergingthreats.net, github.com and suricata-update.readthedocs.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Network Intrusion Prevention With Suricata is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 743 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Network Intrusion Prevention With Suricata: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Google Cloud PAM Helper (google/skills, 21k stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.