Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Agent skill
Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifacts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .claude/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .claude/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifactsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifacts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .agents/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .agents/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifacts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .cursor/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .cursor/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/investigating-ransomware-attack-artifacts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifacts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .gemini/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .gemini/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifactsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .github/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .github/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-ransomware-attack-artifacts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/investigating-ransomware-attack-artifacts .opencode/skills/investigating-ransomware-attack-artifacts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "investigating-ransomware-attack-artifacts" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/investigating-ransomware-attack-artifacts into .opencode/skills/investigating-ransomware-attack-artifacts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-ransomware-attack-artifacts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
investigating-ransomware-attack-artifactsForensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to…
Investigating Ransomware Attack Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options. Use immediately after discovering ransomware encryption, when scoping the incident forensically, or when documenting evidence for law enforcement and insurance claims.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nomoreransom.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Investigating Ransomware Attack Artifacts loads about 4.1k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 497 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# Linux: sudo insmod lime.ko "path=/evidence/memory.lime format=lime"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 497 words, ~4,051 tokens.
.claude/skills/investigating-ransomware-attack-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.# CRITICAL: Do NOT restart systems. Preserve memory first if possible.
# Encryption keys may still be in memory.
# Capture memory from running systems
# Windows: DumpIt.exe (generates memory.raw)
# Linux: sudo insmod lime.ko "path=/evidence/memory.lime format=lime"
# Collect ransom note
cp /mnt/evidence/Users/*/Desktop/README*.txt /cases/case-2024-001/ransomware/ransom_notes/
cp /mnt/evidence/Users/*/Desktop/DECRYPT*.txt /cases/case-2024-001/ransomware/ransom_notes/
cp /mnt/evidence/Users/*/Desktop/HOW_TO*.txt /cases/case-2024-001/ransomware/ransom_notes/
find /mnt/evidence/ -name "*.hta" -o -name "*DECRYPT*" -o -name "*RANSOM*" -o -name "*README*" \
2>/dev/null | head -20 > /cases/case-2024-001/ransomware/note_locations.txt
# Collect sample encrypted files (for identification)
find /mnt/evidence/Users/ -name "*.encrypted" -o -name "*.locked" -o -name "*.crypted" \
-o -name "*.crypt" -o -name "*.enc" | head -10 > /cases/case-2024-001/ransomware/encrypted_samples.txt
# Copy sample encrypted files
mkdir -p /cases/case-2024-001/ransomware/samples/
head -5 /cases/case-2024-001/ransomware/encrypted_samples.txt | while read f; do
cp "$f" /cases/case-2024-001/ransomware/samples/
done
# Identify ransomware variant using file extension and ransom note
python3 << 'PYEOF'
import os, hashlib, json
ransomware_indicators = {
'.lockbit': 'LockBit',
'.blackcat': 'BlackCat/ALPHV',
'.royal': 'Royal',
'.akira': 'Akira',
'.clop': 'Cl0p',
'.conti': 'Conti',
'.ryuk': 'Ryuk',
'.revil': 'REvil/Sodinokibi',
'.maze': 'Maze',
'.phobos': 'Phobos',
'.dharma': 'Dharma/CrySIS',
'.stop': 'STOP/Djvu',
'.hive': 'Hive',
'.blackbasta': 'Black Basta',
'.play': 'Play',
}
# Check encrypted file extensions
samples_dir = '/cases/case-2024-001/ransomware/samples/'
for f in os.listdir(samples_dir):
ext = os.path.splitext(f)[1].lower()
variant = ransomware_indicators.get(ext, 'Unknown')
sha256 = hashlib.sha256(open(os.path.join(samples_dir, f), 'rb').read()).hexdigest()
print(f"File: {f}")
print(f" Extension: {ext}")
print(f" Suspected Variant: {variant}")
print(f" SHA-256: {sha256}")
print()
# Parse ransom note for IoCs
note_dir = '/cases/case-2024-001/ransomware/ransom_notes/'
for note in os.listdir(note_dir):
with open(os.path.join(note_dir, note), 'r', errors='ignore') as f:
content = f.read()
print(f"\n=== Ransom Note: {note} ===")
# Extract bitcoin addresses
import re
btc = re.findall(r'[13][a-km-zA-HJ-NP-Z1-9]{25,34}|bc1[a-zA-HJ-NP-Z0-9]{25,39}', content)
tor = re.findall(r'[a-z2-7]{56}\.onion', content)
emails = re.findall(r'[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}', content)
if btc: print(f" Bitcoin addresses: {btc}")
if tor: print(f" Tor addresses: {tor}")
if emails: print(f" Contact emails: {emails}")
PYEOF# Find the earliest encrypted file (encryption start time)
find /mnt/evidence/ -name "*.encrypted" -printf '%T+ %p\n' 2>/dev/null | sort | head -5 \
> /cases/case-2024-001/ransomware/encryption_start.txt
# Find the latest encrypted file (encryption end time)
find /mnt/evidence/ -name "*.encrypted" -printf '%T+ %p\n' 2>/dev/null | sort -r | head -5 \
> /cases/case-2024-001/ransomware/encryption_end.txt
# Analyze Prefetch for ransomware executable
ls /mnt/evidence/Windows/Prefetch/ | grep -iE "(encrypt|ransom|lock|crypt)" \
> /cases/case-2024-001/ransomware/prefetch_hits.txt
# Check Windows Event Logs for key events
python3 << 'PYEOF'
import json
from evtx import PyEvtxParser
# Security log - authentication and access events
parser = PyEvtxParser("/cases/case-2024-001/evtx/Security.evtx")
attack_events = []
for record in parser.records_json():
data = json.loads(record['data'])
event_id = str(data['Event']['System']['EventID'])
timestamp = data['Event']['System']['TimeCreated']['#attributes']['SystemTime']
# Key events for ransomware investigation
if event_id in ('4624', '4625', '4648', '4672', '4697', '4698', '4688', '1102'):
event_data = data['Event'].get('EventData', {})
attack_events.append({
'time': timestamp,
'event_id': event_id,
'data': json.dumps(event_data, default=str)[:200]
})
# Sort and display timeline
attack_events.sort(key=lambda x: x['time'])
print("=== RANSOMWARE ATTACK TIMELINE ===\n")
for event in attack_events[-50:]:
print(f" [{event['time']}] EventID {event['event_id']}: {event['data'][:150]}")
PYEOF
# Check for Volume Shadow Copy deletion (common ransomware behavior)
# Look for vssadmin.exe or wmic shadowcopy in event logs and Prefetch
grep -l "vssadmin" /cases/case-2024-001/evtx/*.evtx 2>/dev/null
ls /mnt/evidence/Windows/Prefetch/ | grep -i "vssadmin\|wmic\|bcdedit\|wbadmin"# Check for common ransomware initial access vectors
# RDP brute force
python3 << 'PYEOF'
import json
from evtx import PyEvtxParser
from collections import defaultdict
parser = PyEvtxParser("/cases/case-2024-001/evtx/Security.evtx")
failed_rdp = defaultdict(int)
successful_rdp = []
for record in parser.records_json():
data = json.loads(record['data'])
event_id = str(data['Event']['System']['EventID'])
event_data = data['Event'].get('EventData', {})
timestamp = data['Event']['System']['TimeCreated']['#attributes']['SystemTime']
if event_id == '4625': # Failed logon
logon_type = str(event_data.get('LogonType', ''))
if logon_type == '10': # RDP
source_ip = event_data.get('IpAddress', 'Unknown')
failed_rdp[source_ip] += 1
if event_id == '4624': # Successful logon
logon_type = str(event_data.get('LogonType', ''))
if logon_type in ('10', '3'): # RDP or Network
source_ip = event_data.get('IpAddress', 'Unknown')
username = event_data.get('TargetUserName', 'Unknown')
successful_rdp.append({'time': timestamp, 'user': username, 'ip': source_ip, 'type': logon_type})
print("=== FAILED RDP ATTEMPTS ===")
for ip, count in sorted(failed_rdp.items(), key=lambda x: x[1], reverse=True)[:10]:
print(f" {ip}: {count} failed attempts")
print(f"\n=== SUCCESSFUL NETWORK/RDP LOGONS ===")
for logon in successful_rdp[-20:]:
type_name = 'RDP' if logon['type'] == '10' else 'Network'
print(f" [{logon['time']}] {logon['user']} from {logon['ip']} ({type_name})")
PYEOF
# Check for phishing-related artifacts
# Browser downloads, email attachments, Office macros
find /mnt/evidence/Users/*/Downloads/ -name "*.exe" -o -name "*.dll" -o -name "*.js" \
-o -name "*.vbs" -o -name "*.hta" -o -name "*.ps1" 2>/dev/null \
> /cases/case-2024-001/ransomware/suspicious_downloads.txt
# Check PowerShell execution
ls /mnt/evidence/Windows/Prefetch/ | grep -i powershell# Count encrypted files by directory
find /mnt/evidence/ -name "*.encrypted" 2>/dev/null | \
awk -F/ '{OFS="/"; NF--; print}' | sort | uniq -c | sort -rn | head -20 \
> /cases/case-2024-001/ransomware/encryption_scope.txt
# Check if Volume Shadow Copies survived
vssadmin list shadows 2>/dev/null > /cases/case-2024-001/ransomware/vss_status.txt
# Check for backup integrity
find /mnt/evidence/ -name "*.bak" -o -name "*.backup" 2>/dev/null | head -20
# Check No More Ransom project for available decryptors
# https://www.nomoreransom.org/en/decryption-tools.html
echo "Check https://www.nomoreransom.org/ for decryption tools" \
> /cases/case-2024-001/ransomware/decryption_options.txt
# Attempt to recover encryption keys from memory dump
if [ -f /cases/case-2024-001/memory/memory.raw ]; then
# Search for AES key schedules in memory
vol -f /cases/case-2024-001/memory/memory.raw yarascan \
--yara-rules 'rule AES_Key { strings: $aes = { 63 7C 77 7B F2 6B 6F C5 30 01 67 2B FE D7 AB 76 } condition: $aes }' \
> /cases/case-2024-001/ransomware/aes_key_search.txt
# Search for RSA key material
vol -f /cases/case-2024-001/memory/memory.raw yarascan \
--yara-rules 'rule RSA_Key { strings: $rsa = "RSA PRIVATE KEY" condition: $rsa }' \
> /cases/case-2024-001/ransomware/rsa_key_search.txt
fi# Generate comprehensive ransomware investigation report
cat << 'REPORT' > /cases/case-2024-001/ransomware/investigation_report.txt
RANSOMWARE INCIDENT INVESTIGATION REPORT
==========================================
Case Number: 2024-001
Date: $(date -u)
Analyst: [Examiner Name]
1. INCIDENT OVERVIEW
- Ransomware Variant: [Identified variant]
- First Encryption: [Timestamp from earliest encrypted file]
- Last Encryption: [Timestamp from latest encrypted file]
- Systems Affected: [Count]
- Data Encrypted: [Volume estimate]
2. INITIAL ACCESS VECTOR
- Method: [RDP brute force / Phishing / Exploit / etc.]
- Entry Point: [System and IP]
- Timestamp: [First unauthorized access]
- Credentials Used: [Account names]
3. ATTACK CHAIN
a. Initial Access: [Details]
b. Execution: [Ransomware binary details]
c. Persistence: [Services, scheduled tasks]
d. Privilege Escalation: [Method used]
e. Lateral Movement: [Systems accessed, methods]
f. Collection/Staging: [Data staging before encryption]
g. Impact: [Encryption execution]
4. INDICATORS OF COMPROMISE
- Ransomware Binary SHA-256: [Hash]
- C2 Servers: [IPs/Domains]
- Bitcoin Wallet: [Address]
- Tor Site: [.onion address]
- Attacker IPs: [Source IPs]
5. RECOVERY ASSESSMENT
- Decryptor Available: [Yes/No]
- Shadow Copies: [Survived/Deleted]
- Backups: [Status and integrity]
- Memory Key Recovery: [Attempted/Results]
6. RECOMMENDATIONS
- [Remediation steps]
- [Prevention measures]
- [Monitoring improvements]
REPORT| Concept | Description |
|---|---|
| Ransomware variant identification | Determining the specific ransomware family from extensions, notes, and behavior |
| Double extortion | Attack combining encryption with data theft and threatened public release |
| Volume Shadow Copies | Windows backup mechanism often deleted by ransomware to prevent recovery |
| Encryption scope | Assessment of which files, directories, and systems were encrypted |
| Dwell time | Period between initial access and ransomware deployment (often days to weeks) |
| Ransom note IoCs | Bitcoin addresses, Tor sites, and email addresses in ransom demands |
| Key recovery | Attempting to extract encryption keys from memory before shutdown |
| No More Ransom | Law enforcement initiative providing free decryption tools for some variants |
| Tool | Purpose |
|---|---|
| ID Ransomware | Online service identifying ransomware variant from samples |
| No More Ransom | Free decryption tools from law enforcement partnerships |
| Volatility | Memory forensics for encryption key and malware artifact recovery |
| Chainsaw/Hayabusa | Windows Event Log analysis for attack timeline reconstruction |
| PECmd | Prefetch analysis confirming ransomware executable execution |
| YARA | Pattern matching for ransomware variant identification |
| Any.Run/Joe Sandbox | Online malware sandboxes for ransomware behavior analysis |
| Capa | Mandiant tool identifying malware capabilities from static analysis |
Scenario 1: LockBit Attack via RDP Trace initial access through RDP brute force in event logs, identify attacker IP and compromised account, follow lateral movement through network logons, find LockBit deployment via PsExec or GPO, document encryption timeline from file timestamps, check for data exfiltration before encryption.
Scenario 2: Phishing-Initiated Ransomware Trace phishing email through browser history and email artifacts, identify malicious attachment execution in Prefetch, follow Cobalt Strike beacon communication in network logs, trace privilege escalation and domain compromise, document ransomware deployment across the network.
Scenario 3: Supply Chain Ransomware Attack Identify the compromised software update mechanism, trace the malicious update distribution in application logs, analyze the ransomware payload delivered via the trusted channel, assess which systems received the update, determine if the vendor was notified.
Scenario 4: Recovery from Partial Encryption Determine which systems and files were encrypted before containment, check for surviving volume shadow copies, verify backup integrity and restoration capability, attempt memory-based key recovery, contact law enforcement for potential decryptor availability.
Ransomware Investigation Summary:
Variant: LockBit 3.0
First Seen: 2024-01-18 02:00:00 UTC
Encryption Duration: 4 hours 23 minutes
Systems Encrypted: 45 out of 200 (containment stopped spread)
Attack Timeline:
2024-01-10 14:32 - RDP brute force from 203.0.113.45 (1,234 attempts)
2024-01-10 15:00 - Successful RDP login as admin_backup
2024-01-12 02:00 - Mimikatz executed (credential dump)
2024-01-12 02:30 - Domain Admin credentials obtained
2024-01-15 03:00 - Data exfiltration (45 GB to 185.x.x.x)
2024-01-18 02:00 - LockBit deployed via PsExec to 45 systems
2024-01-18 06:23 - Encryption completed on affected systems
Recovery Options:
Decryptor: Not available (LockBit 3.0)
Shadow Copies: Deleted on all systems
Backups: Last clean backup 2024-01-09 (9 days of data loss)
Memory Keys: Not recovered (systems rebooted)
IOCs:
Ransomware Hash: a1b2c3d4e5f6...
C2 IP: 185.x.x.x
Bitcoin: bc1q...
Tor: http://lockbit...onion© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/investigating-ransomware-attack-artifacts of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Investigating Ransomware Attack Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Investigating Ransomware Attack Artifacts this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to…. Investigating Ransomware Attack Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options.
Investigating Ransomware Attack Artifacts fits situations like: security work in your project.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a claude-code`. Or copy the skill folder (skills/investigating-ransomware-attack-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/investigating-ransomware-attack-artifacts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a codex`. Or copy the skill folder (skills/investigating-ransomware-attack-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/investigating-ransomware-attack-artifacts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-ransomware-attack-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-ransomware-attack-artifacts, .gemini/skills/investigating-ransomware-attack-artifacts, .github/skills/investigating-ransomware-attack-artifacts and .opencode/skills/investigating-ransomware-attack-artifacts in your project.
Going by SKILL.md and its folder, Investigating Ransomware Attack Artifacts needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: nomoreransom.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Investigating Ransomware Attack Artifacts is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 547 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Investigating Ransomware Attack Artifacts: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.