Agent skill

Implementing Ransomware Backup Strategy

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules…

Apache-2.0Auto-check: notesDevOps & Cloud

Install Implementing Ransomware Backup Strategy

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-backup-strategy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ransomware-backup-strategy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-ransomware-backup-strategy .claude/skills/implementing-ransomware-backup-strategy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-ransomware-backup-strategy
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
859 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules…

  • Works in 5 steps: Classify Assets and Define Recovery… → Implement 3-2-1-1-0 Architecture → Isolate Backup Credentials → …
  • Planning ransomware backup resilience
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws and az

What it does

Implementing Ransomware Backup Strategy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules, isolating backup credentials, and automating restore testing. Use when planning ransomware backup resilience or air-gapped/immutable backup architecture.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in DevOps & Cloud, covering Backup and disaster recovery. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Planning ransomware backup resilience
  • Air-gapped/immutable backup architecture

Example prompts

  • “Use the implementing-ransomware-backup-strategy skill to design a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2…”
  • “/implementing-ransomware-backup-strategy”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Classify Assets and Define Recovery Objectives
  2. Implement 3-2-1-1-0 Architecture
  3. Isolate Backup Credentials
  4. Configure Immutable Storage
  5. Automate Restore Testing

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws and az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Ransomware Backup Strategy loads about 3.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 859 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:157
    sudo sed -i 's/PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config
  • NoteRuns commands with sudoSKILL.md:158
    sudo systemctl restart sshd
  • NoteRuns commands with sudoSKILL.md:161
    sudo chattr +i /mnt/backup/repository/*
  • NoteRuns commands with sudoSKILL.md:176
    sudo mkfs.xfs -b size=4096 -m reflink=1 /dev/sdb1
  • NoteRuns commands with sudoSKILL.md:177
    sudo mount /dev/sdb1 /mnt/veeam-repo
  • NoteRuns commands with sudoSKILL.md:180
    sudo useradd -m -s /bin/bash veeamuser
  • NoteRuns commands with sudoSKILL.md:181
    sudo mkdir -p /mnt/veeam-repo/backups
  • NoteRuns commands with sudoSKILL.md:182
    sudo chown veeamuser:veeamuser /mnt/veeam-repo/backups

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 859 words, ~3,119 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-ransomware-backup-strategy/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-ransomware-backup-strategy
description
Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules, isolating backup credentials, and automating restore testing. Use when planning ransomware backup resilience or air-gapped/immutable backup architecture.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, backup, incident-response, defense, recovery, immutable-storage
version
1.0.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4, MANAGE-3.1, MEASURE-3.1
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1078, T1190, T1059, T1003, T1110

Implementing Ransomware Backup Strategy

When to Use

  • Designing backup architecture that withstands ransomware encryption and deletion attempts
  • Migrating from traditional backup to ransomware-resilient backup with immutable storage
  • Establishing RPO/RTO targets for critical systems and validating them through restore testing
  • Isolating backup credentials and infrastructure from the production Active Directory domain
  • Meeting cyber insurance requirements for backup resilience and tested recovery capabilities

Do not use as a substitute for endpoint protection, network segmentation, or incident response planning. Backups are a last line of defense, not a primary prevention control.

Prerequisites

  • Inventory of critical systems, applications, and data classified by business impact (Tier 1/2/3)
  • Defined RPO (Recovery Point Objective) and RTO (Recovery Time Objective) per tier
  • Backup software supporting immutable repositories (Veeam 12+, Commvault, Rubrik, Cohesity)
  • Isolated backup network segment or air-gapped storage infrastructure
  • Separate backup admin credentials not joined to the production AD domain

Workflow

Step 1: Classify Assets and Define Recovery Objectives

Map all systems into recovery tiers based on business impact:

TierExamplesRPORTOBackup Frequency
Tier 1 (Critical)Domain controllers, ERP, databases1 hour4 hoursHourly incremental, daily full
Tier 2 (Important)File servers, email, web apps4 hours12 hoursEvery 4 hours incremental, daily full
Tier 3 (Standard)Dev environments, archives24 hours48 hoursDaily incremental, weekly full

Document dependencies between systems. Domain controllers and DNS must recover before application servers. Database servers before application tiers.

Step 2: Implement 3-2-1-1-0 Architecture

Configure backup storage following the extended 3-2-1-1-0 rule:

Copy 1 - Primary backup on local storage:

# Veeam backup job targeting local repository
# Fast restore for operational recovery
Backup Repository: Local NAS (CIFS/NFS) or SAN
Retention: 14 days of restore points
Encryption: AES-256 with password not stored in AD

Copy 2 - Secondary backup on different media:

# Replicate to secondary site or cloud
# Veeam Backup Copy Job or Scale-Out Backup Repository
Target: AWS S3 / Azure Blob / Wasabi / tape library
Retention: 30 days
Transfer: Encrypted TLS 1.2+ in transit

Copy 3 - Offsite copy:

# Geographically separated from primary and secondary
# Cloud object storage in different region or physical tape rotation
Target: Cross-region cloud storage or Iron Mountain tape vaulting
Retention: 90 days

+1 - Immutable or air-gapped copy:

# Cannot be modified or deleted for defined retention period
# Veeam Hardened Repository on Linux with immutable flag
# Or AWS S3 Object Lock in Compliance mode
# Or physical air-gapped tape

+0 - Zero errors on restore verification:

# Automated restore testing using Veeam SureBackup or equivalent
# Scheduled weekly for Tier 1, monthly for Tier 2/3
# Verify boot, network connectivity, and application health
Step 3: Isolate Backup Credentials

Ransomware operators target backup infrastructure by compromising backup admin credentials through Active Directory:

  1. Separate backup admin accounts from the production AD domain. Use local accounts on backup servers or a dedicated backup management domain.
  2. Dedicated backup network segment with firewall rules allowing only backup traffic (specific ports, specific source/destination IPs).
  3. MFA on backup console access using hardware tokens or authenticator apps, not SMS.
  4. Disable RDP on backup servers. Use out-of-band management (iLO/iDRAC/IPMI) for emergency access.
  5. Remove backup servers from domain or place in a dedicated OU with restricted GPO inheritance.
bash
# Linux Hardened Repository - disable SSH password auth
sudo sed -i 's/PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl restart sshd

# Set immutable flag on backup files (XFS filesystem)
sudo chattr +i /mnt/backup/repository/*

# Veeam Hardened Repository uses single-use credentials
# that are not stored on the Veeam server after initial setup
Step 4: Configure Immutable Storage

Veeam Hardened Linux Repository:

bash
# Minimal Ubuntu 22.04 LTS installation
# No GUI, no unnecessary services
# Veeam uses temporary SSH credentials during backup window only

# Configure XFS with reflink support
sudo mkfs.xfs -b size=4096 -m reflink=1 /dev/sdb1
sudo mount /dev/sdb1 /mnt/veeam-repo

# Create dedicated Veeam user with limited permissions
sudo useradd -m -s /bin/bash veeamuser
sudo mkdir -p /mnt/veeam-repo/backups
sudo chown veeamuser:veeamuser /mnt/veeam-repo/backups

AWS S3 Object Lock (Compliance Mode):

bash
# Create bucket with Object Lock enabled
aws s3api create-bucket \
  --bucket company-immutable-backups \
  --object-lock-enabled-for-bucket \
  --region us-east-1

# Set default retention - 30 days compliance mode
aws s3api put-object-lock-configuration \
  --bucket company-immutable-backups \
  --object-lock-configuration '{
    "ObjectLockEnabled": "Enabled",
    "Rule": {
      "DefaultRetention": {
        "Mode": "COMPLIANCE",
        "Days": 30
      }
    }
  }'

Azure Immutable Blob Storage:

bash
# Create storage account with immutable storage
az storage container immutability-policy create \
  --account-name backupaccount \
  --container-name immutable-backups \
  --period 30

# Lock the policy (irreversible)
az storage container immutability-policy lock \
  --account-name backupaccount \
  --container-name immutable-backups
Step 5: Automate Restore Testing

Configure automated restore verification on a recurring schedule:

powershell
# Veeam SureBackup verification job (PowerShell)
# Tests VM boot, network ping, and application health

Add-PSSnapin VeeamPSSnapin
$backupJob = Get-VBRJob -Name "Tier1-DailyBackup"
$sureBackupJob = Get-VSBJob -Name "Tier1-RestoreTest"

# Verify last restore test completed successfully
$lastSession = Get-VSBSession -Job $sureBackupJob -Last
if ($lastSession.Result -ne "Success") {
    Send-MailMessage -To "backup-team@company.com" `
        -Subject "ALERT: SureBackup verification failed" `
        -Body "Tier 1 restore test failed. Last result: $($lastSession.Result)" `
        -SmtpServer "smtp.company.com"
}

Document restore test results and maintain a recovery runbook with step-by-step procedures for each tier.

Key Concepts

TermDefinition
3-2-1-1-0Extended backup rule: 3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore verification errors
RPORecovery Point Objective: maximum acceptable data loss measured in time (e.g., 1 hour RPO means max 1 hour of data loss)
RTORecovery Time Objective: maximum acceptable downtime before system must be operational
Immutable BackupBackup copy that cannot be modified, encrypted, or deleted for a defined retention period, even by administrators
Air-Gapped BackupPhysically isolated backup with no network connectivity to production systems, providing strongest ransomware protection
Hardened RepositoryLinux-based backup storage with minimal attack surface, no persistent SSH, and immutable file flags
Show full SKILL.md (331 more words)Show less

Tools & Systems

  • Veeam Backup & Replication 12: Enterprise backup with Hardened Linux Repository, SureBackup verification, and immutable backup support
  • Rubrik Security Cloud: Zero-trust backup platform with immutable snapshots, anomaly detection, and air-gapped recovery
  • Commvault: Backup with Metallic air-gap protection, anomaly detection, and automated recovery orchestration
  • AWS S3 Object Lock: Cloud-native immutable storage in Compliance or Governance mode for backup copies
  • Cohesity DataProtect: Backup platform with DataLock immutability, anti-ransomware detection, and instant mass restore

Common Scenarios

Scenario: Financial Services Firm Implementing Ransomware-Resilient Backup

Context: A mid-size bank with 500 servers, 200TB of data, and regulatory requirements for 7-year retention must redesign backup after a peer institution was hit by ransomware. Current backups use a single Veeam repository on a Windows server joined to the production domain.

Approach:

  1. Classify all 500 servers into three tiers: 50 Tier 1 (core banking, AD, DNS), 200 Tier 2 (email, file shares, web), 250 Tier 3 (dev, test, archive)
  2. Deploy Veeam Hardened Linux Repository on dedicated Ubuntu 22.04 servers with XFS immutability for primary backup
  3. Configure S3 Object Lock in Compliance mode for 30-day immutable cloud copy with Veeam Scale-Out Repository capacity tier
  4. Establish quarterly tape rotation to Iron Mountain for 7-year regulatory retention
  5. Remove all backup servers from the production AD domain and create isolated backup admin accounts with hardware MFA tokens
  6. Deploy SureBackup jobs: weekly for Tier 1, monthly for Tier 2, quarterly for Tier 3
  7. Conduct annual full recovery drill restoring AD, DNS, core banking, and dependent applications to validate documented RTO

Pitfalls:

  • Leaving backup admin credentials in the production AD domain where ransomware operators can compromise them via Kerberoasting or DCSync
  • Configuring immutable retention periods shorter than the dwell time of typical ransomware (average 21 days), allowing attackers to wait for immutability to expire
  • Testing only individual VM restores without testing full application stack recovery including dependencies
  • Forgetting to back up backup server configuration (Veeam config database, encryption keys) separately from the backup infrastructure itself

Output Format

## Ransomware Backup Strategy Assessment

**Organization**: [Name]
**Assessment Date**: [Date]
**Assessor**: [Name]

### Current State
- Backup Solution: [Product/Version]
- Copies: [Number and locations]
- Immutable Copy: [Yes/No - Details]
- Air-Gapped Copy: [Yes/No - Details]
- Credential Isolation: [Yes/No - Details]
- Last Restore Test: [Date - Result]

### Gap Analysis
| Control | Current | Target | Gap | Priority |
|---------|---------|--------|-----|----------|
| Immutable backup | None | S3 Object Lock + Linux Hardened Repo | Missing | Critical |
| Credential isolation | Domain-joined | Standalone local accounts + MFA | Partial | Critical |
| Restore testing | Ad-hoc manual | Automated weekly SureBackup | Missing | High |

### Recommendations
1. [Priority] [Recommendation] - [Estimated effort]
2. ...

### Recovery Tier Summary
| Tier | Systems | RPO | RTO | Backup Schedule | Restore Test Frequency |
|------|---------|-----|-----|-----------------|----------------------|
| 1 | 50 | 1hr | 4hr | Hourly inc/Daily full | Weekly |
| 2 | 200 | 4hr | 12hr | 4hr inc/Daily full | Monthly |
| 3 | 250 | 24hr | 48hr | Daily inc/Weekly full | Quarterly |

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-ransomware-backup-strategy of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Ransomware Backup Strategy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Ransomware Backup Strategy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Ransomware Backup Strategy this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: NotesApache-2.0
OmniRoute Backup and Sync CLIdiegosouzapw/OmniRoute74k—~948Automated safety check: PassMIT
Pymobiledevice3 Device Operatordoronz88/pymobiledevice32.9k—~1.8kAutomated safety check: NotesGPL-3.0
Myclaw BackupLeoYeAI/openclaw-backup659—~1.8kAutomated safety check: PassMIT
OmniRoute Database Backupsdiegosouzapw/OmniRoute74k—~395Automated safety check: PassMIT
Tempsgotempsh/temps828—~2kAutomated safety check: PassApache-2.0

Similar skills

  • OmniRoute Backup and Sync CLI

    diegosouzapw/OmniRoute

    Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.

    74k GitHub stars~948 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pymobiledevice3 Device Operator

    doronz88/pymobiledevice3

    Operate iOS and iPadOS devices with pymobiledevice3, from a local checkout or straight from PyPI via uvx on a fresh workstation.

    2.9k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Myclaw Backup

    LeoYeAI/openclaw-backup

    Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data.

    659 GitHub stars~1.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • OmniRoute Database Backups

    diegosouzapw/OmniRoute

    Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.

    74k GitHub stars~395 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Temps

    gotempsh/temps

    Manage, deploy, operate, and instrument applications with Temps.

    828 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Hermes Offsite Backup

    OnlyTerp/hermes-optimization-guide

    Set up encrypted off-machine Hermes backups. An agent skill from OnlyTerp/hermes-optimization-guide.

    687 GitHub stars~772 tokensUpdated 15 days ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Ransomware Backup Strategy

What does Implementing Ransomware Backup Strategy do?

Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules…. Implementing Ransomware Backup Strategy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Designs a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules, isolating backup credentials, and automating restore testing.

When should I use Implementing Ransomware Backup Strategy?

Implementing Ransomware Backup Strategy fits situations like: planning ransomware backup resilience; air-gapped/immutable backup architecture.

How do I install Implementing Ransomware Backup Strategy in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-backup-strategy -a claude-code`. Or copy the skill folder (skills/implementing-ransomware-backup-strategy in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-ransomware-backup-strategy in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Ransomware Backup Strategy in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-backup-strategy -a codex`. Or copy the skill folder (skills/implementing-ransomware-backup-strategy in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-ransomware-backup-strategy in your project. Codex loads it when a task matches its description.

Can I use Implementing Ransomware Backup Strategy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-backup-strategy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-ransomware-backup-strategy, .gemini/skills/implementing-ransomware-backup-strategy, .github/skills/implementing-ransomware-backup-strategy and .opencode/skills/implementing-ransomware-backup-strategy in your project.

What does Implementing Ransomware Backup Strategy need to run?

Going by SKILL.md and its folder, Implementing Ransomware Backup Strategy needs Python for the scripts in its folder and the command-line tools its instructions call (aws and az). Our summary lists: Python 3.

Does Implementing Ransomware Backup Strategy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Ransomware Backup Strategy safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Ransomware Backup Strategy use?

Implementing Ransomware Backup Strategy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Ransomware Backup Strategy use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Ransomware Backup Strategy?

Skills that share tags, products or a category with Implementing Ransomware Backup Strategy: OmniRoute Backup and Sync CLI (diegosouzapw/OmniRoute, 74k stars), Pymobiledevice3 Device Operator (doronz88/pymobiledevice3, 2.9k stars), Myclaw Backup (LeoYeAI/openclaw-backup, 659 stars) and OmniRoute Database Backups (diegosouzapw/OmniRoute, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Ransomware Backup Strategy?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.