Agent skill

Implementing Ransomware Kill Switch Detection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.

Apache-2.0Auto-check passedDevOps & Cloud

Install Implementing Ransomware Kill Switch Detection

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-kill-switch-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ransomware-kill-switch-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-ransomware-kill-switch-detection .claude/skills/implementing-ransomware-kill-switch-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-ransomware-kill-switch-detection
GitHub stars
34k
Token cost
~2.4k tokens
SKILL.md length
530 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.

  • Works in 5 steps: Identify Kill Switch Mechanisms in… → Deploy Mutex Vaccination → Monitor for Mutex Creation Events → …
  • Analyzing a samples execution guards
  • SKILL.md covers When to Use, Prerequisites, Workflow and Verification, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Ransomware Kill Switch Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g. WannaCry-style), and registry termination checks, then implements mutex vaccination and kill switch domain monitoring to stop ransomware before it runs. Use when analyzing a sample's execution guards or deploying vaccination/monitoring as a defensive control.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Analyzing a samples execution guards
  • Deploying vaccination/monitoring as a defensive control

Example prompts

  • “Use the implementing-ransomware-kill-switch-detection skill to analyz ransomware kill switch mechanisms, including mutex-based execution guards…”
  • “/implementing-ransomware-kill-switch-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify Kill Switch Mechanisms in Ransomware
  2. Deploy Mutex Vaccination
  3. Monitor for Mutex Creation Events
  4. Monitor DNS for Kill Switch Domains
  5. Enumerate Active Mutexes for Incident Response

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Ransomware Kill Switch Detection loads about 2.4k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 530 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 530 words, ~2,379 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-ransomware-kill-switch-detection/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-ransomware-kill-switch-detection
description
Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g. WannaCry-style), and registry termination checks, then implements mutex vaccination and kill switch domain monitoring to stop ransomware before it runs. Use when analyzing a sample's execution guards or deploying vaccination/monitoring as a defensive control.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, kill-switch, mutex, detection, WannaCry, malware-analysis
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1078, T1190, T1059, T1486, T1490
mitre_f3.version
1.1
mitre_f3.tactics
positioning, monetization

Implementing Ransomware Kill Switch Detection

When to Use

  • Analyzing a ransomware sample to determine if it contains a kill switch mechanism (mutex, domain, registry)
  • Deploying proactive mutex vaccination across endpoints to prevent known ransomware families from executing
  • Monitoring DNS for kill switch domain lookups that indicate ransomware attempting to check before encrypting
  • During incident response to quickly determine if a ransomware variant can be stopped by activating its kill switch
  • Building detection signatures for ransomware mutex creation events using Sysmon or EDR telemetry

Do not use kill switch vaccination as a primary defense. Not all ransomware families implement kill switches, and those that do may remove them in newer versions. This is a supplementary detection and prevention layer.

Prerequisites

  • Python 3.8+ with ctypes (Windows) for mutex creation and enumeration
  • Sysmon installed with Event ID 1 (process creation) and Event ID 17/18 (pipe/mutex events) configured
  • Access to malware analysis sandbox for identifying kill switch mechanisms in samples
  • DNS monitoring capability for detecting kill switch domain resolution attempts
  • Familiarity with Windows internals: mutexes (mutants), kernel objects, named pipes
  • Reference database of known ransomware mutexes (github.com/albertzsigovits/malware-mutex)

Workflow

Step 1: Identify Kill Switch Mechanisms in Ransomware

Analyze samples for common kill switch patterns:

Kill Switch Types Found in Ransomware:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. MUTEX-BASED (most common):
   - Ransomware creates a named mutex at startup
   - If mutex already exists → another instance is running → exit
   - Defense: Pre-create the mutex to prevent execution
   - Examples:
     WannaCry:     Global\MsWinZonesCacheCounterMutexA
     Conti:        kasKDJSAFJauisiudUASIIQWUA82
     REvil:        Global\{GUID-based-on-machine}
     Ryuk:         Global\YOURPRODUCT_MUTEX

2. DOMAIN-BASED:
   - Ransomware resolves a hardcoded domain before executing
   - If domain resolves → security sandbox detected → exit
   - Defense: Register/sinkhole the domain to activate kill switch
   - Examples:
     WannaCry v1:  iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
     WannaCry v1:  fferfsodp9ifjaposdfjhgosurijfaewrwergwea.com

3. REGISTRY-BASED:
   - Check for specific registry key/value before executing
   - If key exists → exit (anti-analysis or kill switch)
   - Defense: Create the registry key proactively

4. FILE-BASED:
   - Check for existence of specific file or directory
   - If marker file exists → exit
   - Defense: Create the marker file on all endpoints

5. LANGUAGE-BASED:
   - Check system language/keyboard layout
   - Exit if Russian/CIS country keyboard detected
   - Common in Eastern European ransomware groups
Step 2: Deploy Mutex Vaccination

Pre-create known ransomware mutexes on endpoints to prevent execution:

python
# Windows mutex vaccination using ctypes
import ctypes
from ctypes import wintypes

kernel32 = ctypes.WinDLL('kernel32', use_last_error=True)

def create_mutex(name):
    """Create a named mutex to vaccinate against ransomware."""
    handle = kernel32.CreateMutexW(None, False, name)
    error = ctypes.get_last_error()
    if handle == 0:
        return False, f"Failed to create mutex: error {error}"
    if error == 183:  # ERROR_ALREADY_EXISTS
        return True, f"Mutex already exists (already vaccinated): {name}"
    return True, f"Mutex created successfully: {name}"

KNOWN_RANSOMWARE_MUTEXES = [
    "Global\\MsWinZonesCacheCounterMutexA",        # WannaCry
    "Global\\kasKDJSAFJauisiudUASIIQWUA82",        # Conti
    "Global\\YOURPRODUCT_MUTEX",                     # Ryuk variant
    "Global\\JhbGjhBsSQjz",                         # Maze
    "Global\\sdjfhksjdhfsd",                         # Generic ransomware
]
Step 3: Monitor for Mutex Creation Events

Use Sysmon to detect when ransomware creates its characteristic mutexes:

xml
<!-- Sysmon configuration for mutex monitoring -->
<Sysmon schemaversion="4.90">
  <EventFiltering>
    <!-- Event ID 1: Process creation with mutex indicators -->
    <ProcessCreate onmatch="include">
      <CommandLine condition="contains">mutex</CommandLine>
      <CommandLine condition="contains">CreateMutex</CommandLine>
    </ProcessCreate>
  </EventFiltering>
</Sysmon>
Detection via Event Logs:
━━━━━━━━━━━━━━━━━━━━━━━━
Windows Security Log:
  Event ID 4688: Process creation (enable command line logging)

Sysmon:
  Event ID 1:  Process create (includes command line and hashes)
  Event ID 17: Pipe created (named pipes, similar to mutexes)

PowerShell detection:
  Event ID 4104: Script block logging (detect mutex creation in scripts)

Velociraptor artifact:
  Windows.Detection.Mutants - Enumerates all named mutant objects
Step 4: Monitor DNS for Kill Switch Domains

Detect ransomware domain-based kill switch resolution attempts:

DNS Monitoring for Kill Switch Domains:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. Monitor DNS queries for known kill switch domains
2. High-entropy domain names (>4.0 entropy in domain label) may indicate
   ransomware kill switch domains or DGA-generated C2 domains
3. Queries to newly registered domains from endpoints that typically
   only access well-established domains

Indicators:
  - Domain with no prior resolution history
  - Domain registered in last 24-72 hours
  - High character entropy in domain name
  - Resolution attempt followed by either mass encryption (kill switch failed)
    or process termination (kill switch activated)
Step 5: Enumerate Active Mutexes for Incident Response

During an active incident, scan endpoints for ransomware-associated mutexes:

powershell
# PowerShell: List all named mutant objects using Sysinternals Handle
# handle.exe -a -p <PID> | findstr "Mutant"

# Velociraptor query for mutex hunting:
# SELECT * FROM glob(globs="\\BaseNamedObjects\\*") WHERE Name =~ "mutex_pattern"

# Python-based enumeration (requires pywin32):
# import win32event
# handle = win32event.OpenMutex(0x00100000, False, "Global\\MutexName")

Verification

  • Verify mutex vaccination by attempting to create the same mutex (should get ERROR_ALREADY_EXISTS)
  • Test that vaccinated mutexes survive system reboot (they do not; re-apply at startup via scheduled task)
  • Confirm DNS monitoring detects test queries for known kill switch domains
  • Validate Sysmon event generation for mutex creation by running a test script
  • Check that vaccination does not interfere with legitimate applications using similar mutex names
  • Test against actual ransomware samples in an isolated sandbox to confirm kill switch activation
Show full SKILL.md (188 more words)Show less

Key Concepts

TermDefinition
Mutex (Mutant)A Windows kernel synchronization object used to ensure only one instance of a program runs; ransomware uses named mutexes to prevent re-infection
Kill SwitchA mechanism in ransomware that causes it to terminate without encrypting if a specific condition is met (mutex exists, domain resolves, file present)
Mutex VaccinationProactively creating named mutexes on endpoints that match known ransomware mutex names, preventing the ransomware from executing
Domain SinkholeRegistering or redirecting a malicious domain to a controlled server; used to activate domain-based kill switches
DGA (Domain Generation Algorithm)Algorithm used by malware to generate pseudo-random domain names for C2 communication, sometimes incorporating kill switch checks

Tools & Systems

  • Sysmon: Microsoft system monitor providing Event ID 17/18 for named pipe and mutex creation monitoring
  • Velociraptor: Endpoint visibility tool with built-in artifacts for enumerating mutant (mutex) objects on Windows
  • Sysinternals Handle: Command-line tool for listing open handles including named mutexes per process
  • malware-mutex (GitHub): Community-maintained database of mutexes used by known malware families
  • ANY.RUN: Interactive malware sandbox that reports mutex creation during dynamic analysis
  • PassiveDNS: DNS monitoring infrastructure for detecting kill switch domain resolution attempts

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-ransomware-kill-switch-detection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Ransomware Kill Switch Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Ransomware Kill Switch Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Ransomware Kill Switch Detection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
KubeShark for KubernetesLukasNiessen/kubernetes-skill444—~1.2kAutomated safety check: PassMIT
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills1481 repos~2.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated 18 days ago
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    444 GitHub stars~1.2k tokensUpdated 25 days ago
    DevOps & CloudAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check: notes
  • Censorship Audit

    hedioum/Hedioum-Pool-Tunnel

    Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.

    139 GitHub stars~4.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Ransomware Kill Switch Detection

What does Implementing Ransomware Kill Switch Detection do?

Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g. Implementing Ransomware Kill Switch Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.g.

When should I use Implementing Ransomware Kill Switch Detection?

Implementing Ransomware Kill Switch Detection fits situations like: analyzing a samples execution guards; deploying vaccination/monitoring as a defensive control.

How do I install Implementing Ransomware Kill Switch Detection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-kill-switch-detection -a claude-code`. Or copy the skill folder (skills/implementing-ransomware-kill-switch-detection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-ransomware-kill-switch-detection in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Ransomware Kill Switch Detection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-kill-switch-detection -a codex`. Or copy the skill folder (skills/implementing-ransomware-kill-switch-detection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-ransomware-kill-switch-detection in your project. Codex loads it when a task matches its description.

Can I use Implementing Ransomware Kill Switch Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ransomware-kill-switch-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-ransomware-kill-switch-detection, .gemini/skills/implementing-ransomware-kill-switch-detection, .github/skills/implementing-ransomware-kill-switch-detection and .opencode/skills/implementing-ransomware-kill-switch-detection in your project.

What does Implementing Ransomware Kill Switch Detection need to run?

Going by SKILL.md and its folder, Implementing Ransomware Kill Switch Detection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Ransomware Kill Switch Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Ransomware Kill Switch Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Ransomware Kill Switch Detection use?

Implementing Ransomware Kill Switch Detection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Ransomware Kill Switch Detection use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 940 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Ransomware Kill Switch Detection?

Skills that share tags, products or a category with Implementing Ransomware Kill Switch Detection: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars) and KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 444 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Ransomware Kill Switch Detection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.