Agent skill

Implementing Usb Device Control Policy

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices.

Apache-2.0Auto-check passedSecurity

Install Implementing Usb Device Control Policy

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-usb-device-control-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-usb-device-control-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-usb-device-control-policy .claude/skills/implementing-usb-device-control-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-usb-device-control-policy
GitHub stars
34k
Token cost
~1.4k tokens
SKILL.md length
304 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices.

  • Works in 4 steps: Inventory Current USB Usage → Configure GPO Device Control → Deploy via Microsoft Defender for Endpoint → …
  • Deploying device control via Group Policy
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Usb Device Control Policy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security. It works with Microsoft Defender. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Deploying device control via Group Policy
  • EDR platforms to enforce USB restrictions

Example prompts

  • “Use the implementing-usb-device-control-policy skill to implement USB device control policies to restrict unauthorized removable media access on…”
  • “/implementing-usb-device-control-policy”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Inventory Current USB Usage
  2. Configure GPO Device Control
  3. Deploy via Microsoft Defender for Endpoint
  4. Audit and Monitor

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Usb Device Control Policy loads about 1.4k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 304 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 304 words, ~1,373 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-usb-device-control-policy/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-usb-device-control-policy
description
Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
domain
cybersecurity
subdomain
endpoint-security
tags
endpoint, USB-control, device-control, data-loss-prevention, removable-media
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, PR.PS-02, DE.CM-01, PR.IR-01
mitre_attack
T1055, T1547, T1059, T1036, T1048

Implementing USB Device Control Policy

When to Use

Use this skill when:

  • Restricting USB storage devices to prevent data exfiltration or malware introduction
  • Implementing device control policies via GPO, Intune, or EDR device control modules
  • Creating USB whitelists for authorized devices while blocking all others
  • Meeting compliance requirements for removable media control (PCI DSS, HIPAA)

Do not use for network-based DLP or cloud storage restrictions.

Prerequisites

  • Active Directory GPO or Microsoft Intune for policy deployment
  • Device Instance IDs of authorized USB devices
  • EDR with device control module (CrowdStrike, Microsoft Defender for Endpoint)
  • Understanding of USB device classes (mass storage, HID, printer, etc.)

Workflow

Step 1: Inventory Current USB Usage
powershell
# Enumerate currently connected USB devices
Get-PnpDevice -Class USB | Select-Object InstanceId, FriendlyName, Status

# Query USB storage history from registry
Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Enum\USBSTOR\*\*" |
  Select-Object FriendlyName, ContainerID, HardwareID

# Collect USB usage across fleet (via EDR or scripts)
# CrowdStrike: Investigate → USB Device Activity
# MDE: DeviceEvents | where ActionType == "UsbDriveMounted"
Step 2: Configure GPO Device Control
Computer Configuration → Administrative Templates → System → Removable Storage Access

- All Removable Storage classes: Deny all access → Enabled
  (Block read AND write for all removable storage)

OR for granular control:
- CD and DVD: Deny read access → Enabled
- Removable Disks: Deny write access → Enabled (read-only USB)
- Tape Drives: Deny all access → Enabled
- WPD Devices: Deny all access → Enabled

To allow specific approved USB devices:
Computer Configuration → Administrative Templates → System → Device Installation
  → Device Installation Restrictions

- Prevent installation of devices not described by other policy settings → Enabled
- Allow installation of devices that match any of these device IDs → Enabled
  Add approved Device IDs: USB\VID_0781&PID_5583 (example: SanDisk Cruzer)
Step 3: Deploy via Microsoft Defender for Endpoint
xml
<!-- MDE Device Control policy (XML format) -->
<PolicyGroups>
  <Group Id="{d9a81dc0-1234-5678-9abc-def012345678}"
    Type="Device" Name="Approved USB Devices">
    <MatchClause>
      <MatchType>VID_PID</MatchType>
      <MatchData>0781_5583</MatchData> <!-- SanDisk -->
    </MatchClause>
  </Group>
</PolicyGroups>

<PolicyRules>
  <Rule Id="{rule-guid}" Name="Block unapproved USB storage">
    <IncludedIdList>
      <PrimaryId>RemovableMediaDevices</PrimaryId>
    </IncludedIdList>
    <ExcludedIdList>
      <GroupId>{d9a81dc0-1234-5678-9abc-def012345678}</GroupId>
    </ExcludedIdList>
    <Entry>
      <Type>Deny</Type>
      <AccessMask>63</AccessMask> <!-- All access -->
      <Options>4</Options> <!-- Show notification -->
    </Entry>
  </Rule>
</PolicyRules>
Step 4: Audit and Monitor
# Monitor USB events in SIEM:
# Windows Event ID 6416 - New external device recognized
# Windows Event ID 4663 - File access on removable media
# MDE: DeviceEvents where ActionType contains "Usb"

# Generate USB activity reports monthly
# Track: blocked attempts, approved device usage, exception requests

Key Concepts

TermDefinition
VID/PIDVendor ID and Product ID that uniquely identify USB device models
Device Instance IDUnique identifier for a specific physical USB device
Device ControlEDR/endpoint feature restricting device access based on type, vendor, or serial number
USB ClassUSB device category (mass storage 08h, HID 03h, printer 07h)

Tools & Systems

  • Microsoft Defender Device Control: MDE module for USB restriction policies
  • CrowdStrike Falcon Device Control: EDR-based USB policy enforcement
  • Group Policy (Removable Storage Access): Built-in Windows USB restriction via GPO
  • Endpoint Protector: Third-party device control and DLP solution

Common Pitfalls

  • Blocking all USB without exception: Keyboards and mice are USB HID devices. Block only mass storage class, not all USB.
  • Not communicating policy to users: USB blocks without user notification generate helpdesk tickets. Display a notification explaining the policy.
  • Ignoring USB-C and Thunderbolt: Modern devices use USB-C for docking, charging, and storage. Policies must distinguish between USB storage and USB peripherals.
  • No approved device process: Users with legitimate USB needs (presentations, field data collection) require an exception process with approved, encrypted devices.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-usb-device-control-policy of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Usb Device Control Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Usb Device Control Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Usb Device Control Policy this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.0
Azure Network Security Designvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT
Cloud App Security Posturevinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Defender Easmvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Sentinelvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Threat Modellingvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT

Similar skills

  • Azure Network Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…

    175 GitHub stars~1.8k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Cloud App Security Posture

    vinayaklatthe/microsoft-security-skills

    Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Defender Easm

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Sentinel

    vinayaklatthe/microsoft-security-skills

    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Threat Modelling

    vinayaklatthe/microsoft-security-skills

    Guidance for threat modelling using STRIDE and the Microsoft Security Development Lifecycle (SDL).

    175 GitHub stars~1.8k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Incident Investigation

    SCStelz/security-investigator

    A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

    249 GitHub stars~13k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Usb Device Control Policy

What does Implementing Usb Device Control Policy do?

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Implementing Usb Device Control Policy is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices.

When should I use Implementing Usb Device Control Policy?

Implementing Usb Device Control Policy fits situations like: deploying device control via Group Policy; EDR platforms to enforce USB restrictions.

How do I install Implementing Usb Device Control Policy in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-usb-device-control-policy -a claude-code`. Or copy the skill folder (skills/implementing-usb-device-control-policy in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-usb-device-control-policy in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Usb Device Control Policy in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-usb-device-control-policy -a codex`. Or copy the skill folder (skills/implementing-usb-device-control-policy in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-usb-device-control-policy in your project. Codex loads it when a task matches its description.

Can I use Implementing Usb Device Control Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-usb-device-control-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-usb-device-control-policy, .gemini/skills/implementing-usb-device-control-policy, .github/skills/implementing-usb-device-control-policy and .opencode/skills/implementing-usb-device-control-policy in your project.

What does Implementing Usb Device Control Policy need to run?

Going by SKILL.md and its folder, Implementing Usb Device Control Policy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Usb Device Control Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Usb Device Control Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Usb Device Control Policy use?

Implementing Usb Device Control Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Usb Device Control Policy use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Usb Device Control Policy?

Skills that share tags, products or a category with Implementing Usb Device Control Policy: Azure Network Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Cloud App Security Posture (vinayaklatthe/microsoft-security-skills, 175 stars), Defender Easm (vinayaklatthe/microsoft-security-skills, 175 stars) and Sentinel (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Usb Device Control Policy?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.