TimesFM Forecasting
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
Agent skill
Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomalies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .claude/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .claude/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomaliesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomalies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .agents/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .agents/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomalies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .cursor/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .cursor/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/monitoring-scada-modbus-traffic-anomalies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomalies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .gemini/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .gemini/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomaliesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .github/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .github/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills monitoring-scada-modbus-traffic-anomalies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/monitoring-scada-modbus-traffic-anomalies .opencode/skills/monitoring-scada-modbus-traffic-anomalies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "monitoring-scada-modbus-traffic-anomalies" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/monitoring-scada-modbus-traffic-anomalies into .opencode/skills/monitoring-scada-modbus-traffic-anomalies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "monitoring-scada-modbus-traffic-anomalies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
monitoring-scada-modbus-traffic-anomaliesMonitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns.
Monitoring Scada Modbus Traffic Anomalies is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic…
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Data & Analytics, covering Anomaly detection. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Monitoring Scada Modbus Traffic Anomalies loads about 6.2k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 167 tokens; SKILL.md has 2,333 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 2,333 words, ~6,164 tokens.
.claude/skills/monitoring-scada-modbus-traffic-anomalies/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use on networks without authorization from the asset owner, for active injection or fuzzing against production SCADA systems, or as a replacement for safety-instrumented systems (SIS) that provide physical process protection.
Establish passive monitoring on the OT network segment and begin capturing Modbus TCP frames:
tcpdump -i eth0 port 502 -c 100 -w modbus_capture.pcap.from scapy.all import rdpcap, TCP
from scapy.contrib.modbus import ModbusADURequest, ModbusADUResponse
packets = rdpcap("modbus_capture.pcap")
for pkt in packets:
if pkt.haslayer(ModbusADURequest):
adu = pkt[ModbusADURequest]
print(f"Src: {pkt['IP'].src} -> Dst: {pkt['IP'].dst} "
f"Unit: {adu.unitId} FuncCode: {adu.funcCode}")@load policy/protocols/modbus/known-masters-slaves to generate modbus.log entries containing timestamp, source/destination IPs, function code, and exception responses. This provides continuous passive logging without custom scripting.Build a behavioral profile of legitimate Modbus traffic to distinguish normal operations from anomalies:
Normal baseline example (72-hour period):
HMI (10.1.1.10) -> PLC (10.1.1.50):
FC 03 (Read Holding Registers): 432,180 packets (97.2%)
FC 04 (Read Input Registers): 10,540 packets (2.4%)
FC 06 (Write Single Register): 1,780 packets (0.4%)
FC 16 (Write Multiple Registers): 0 packets (0.0%)
FC 43 (Read Device ID): 0 packets (0.0%)Apply rule-based and statistical detection to identify suspicious function code usage:
WRITE_FUNCTION_CODES = {5, 6, 15, 16}
AUTHORIZED_WRITERS = {"10.1.1.10", "10.1.1.11"} # HMI and engineering WS
def check_unauthorized_write(src_ip, function_code):
if function_code in WRITE_FUNCTION_CODES and src_ip not in AUTHORIZED_WRITERS:
return {
"alert": "UNAUTHORIZED_MODBUS_WRITE",
"severity": "CRITICAL",
"src_ip": src_ip,
"function_code": function_code,
"description": f"Write FC {function_code} from unauthorized source {src_ip}"
}
return NoneException response correlation:
- Isolated exception (1-2 per hour): Normal operational error
- Burst (>10 per minute): Active scanning or fuzzing attempt
- Continuous (>100 per hour): Denial-of-service or tool malfunctionDetect attempts to manipulate physical process parameters through register value analysis:
REGISTER_LIMITS = {
40001: {"name": "Reactor Temperature Setpoint", "min": 50, "max": 200, "unit": "C",
"max_rate": 5}, # Max 5 degrees per write cycle
40010: {"name": "Pump Speed", "min": 0, "max": 3600, "unit": "RPM",
"max_rate": 200}, # Max 200 RPM change per cycle
40020: {"name": "Valve Position", "min": 0, "max": 100, "unit": "%",
"max_rate": 10}, # Max 10% per cycle
}
def check_register_value(register_addr, new_value, previous_value):
if register_addr not in REGISTER_LIMITS:
return None
limits = REGISTER_LIMITS[register_addr]
alerts = []
if new_value < limits["min"] or new_value > limits["max"]:
alerts.append({
"alert": "REGISTER_VALUE_OUT_OF_RANGE",
"severity": "CRITICAL",
"register": register_addr,
"name": limits["name"],
"value": new_value,
"range": f"{limits['min']}-{limits['max']} {limits['unit']}"
})
if previous_value is not None:
rate = abs(new_value - previous_value)
if rate > limits["max_rate"]:
alerts.append({
"alert": "REGISTER_VALUE_EXCESSIVE_RATE",
"severity": "HIGH",
"register": register_addr,
"name": limits["name"],
"change": rate,
"max_allowed": limits["max_rate"]
})
return alerts if alerts else NoneIdentify anomalies in communication patterns that may indicate man-in-the-middle, replay, or denial-of-service attacks:
AUTHORIZED_MASTERS = {"10.1.1.10", "10.1.1.11"}
def detect_rogue_master(src_ip, dst_ip, dst_port):
if dst_port == 502 and src_ip not in AUTHORIZED_MASTERS:
return {
"alert": "ROGUE_MODBUS_MASTER",
"severity": "CRITICAL",
"src_ip": src_ip,
"target_slave": dst_ip,
"description": "Unauthorized device initiating Modbus connection"
}
return Noneimport numpy as np
from collections import defaultdict
class TimingAnomalyDetector:
def __init__(self, window_size=1000, threshold_sigma=3.0):
self.windows = defaultdict(list)
self.window_size = window_size
self.threshold_sigma = threshold_sigma
def check(self, src_ip, dst_ip, timestamp):
key = (src_ip, dst_ip)
window = self.windows[key]
if len(window) > 0:
interval = timestamp - window[-1]
if len(window) >= 100:
mean = np.mean(np.diff(window[-100:]))
std = np.std(np.diff(window[-100:]))
if std > 0 and abs(interval - mean) > self.threshold_sigma * std:
return {
"alert": "TIMING_ANOMALY",
"severity": "MEDIUM",
"pair": f"{src_ip}->{dst_ip}",
"interval": interval,
"expected_mean": mean,
"deviation_sigma": abs(interval - mean) / std
}
window.append(timestamp)
if len(window) > self.window_size:
window.pop(0)
return None| Term | Definition |
|---|---|
| Modbus TCP | An application-layer protocol encapsulating Modbus frames in TCP/IP, communicating on port 502. It uses a 7-byte MBAP header (transaction ID, protocol ID, length, unit ID) followed by the Modbus PDU containing the function code and data. |
| Function Code | A single-byte identifier in the Modbus PDU specifying the operation: read coils (01), read discrete inputs (02), read holding registers (03), read input registers (04), write single coil (05), write single register (06), write multiple coils (15), write multiple registers (16), diagnostics (08), and device identification (43). |
| MBAP Header | Modbus Application Protocol header used in Modbus TCP. Contains Transaction ID for request-response matching, Protocol ID (always 0x0000 for Modbus), Length of remaining bytes, and Unit Identifier for addressing slaves behind gateways. |
| Holding Register | A 16-bit read/write register in a Modbus slave addressed at range 40001-49999 (protocol address 0-9998). Used for setpoints, configuration, and control values that can be written by the master. Primary target for process manipulation attacks. |
| Coil | A single-bit read/write data element in a Modbus slave addressed at range 00001-09999. Controls discrete outputs (valves, pumps, breakers). Write operations (FC 05/15) to coils can directly affect physical equipment state. |
| Deep Packet Inspection | Analysis beyond TCP/IP headers into the Modbus application-layer payload to extract function codes, register addresses, and values. Required because standard firewalls only inspect IP/port, missing protocol-level attacks that use legitimate Modbus framing. |
| Rogue Master | An unauthorized device sending Modbus requests to slave devices. In OT environments, only designated HMI servers and engineering workstations should act as Modbus masters. A rogue master can read process data or write dangerous values to PLCs. |
| Register Value Baseline | The statistical profile (min, max, mean, standard deviation) of values observed in specific registers during normal operations. Deviations beyond physical process bounds indicate sensor failure or malicious manipulation. |
modbus.func_code == 6), and exporting specific fields for analysis.Context: A water treatment facility uses Modbus TCP to communicate between the SCADA server (10.1.1.10) and six PLCs controlling chemical dosing pumps, filtration valves, and flow meters. The security team deploys passive Modbus traffic monitoring after an industry advisory about attacks targeting water utilities.
Approach:
Pitfalls:
Context: A manufacturing plant's SOC observes unusual network activity from an engineering workstation (10.1.2.20) that is authorized for PLC programming. The OT security team uses Modbus traffic monitoring to determine if the workstation is being used for reconnaissance.
Approach:
Pitfalls:
## Modbus Traffic Anomaly Report
**Monitoring Period**: 2026-03-15 00:00:00 UTC to 2026-03-15 23:59:59 UTC
**Network Segment**: OT VLAN 10 (10.1.1.0/24)
**Packets Analyzed**: 2,847,320
**Anomalies Detected**: 4
---
### Alert 1: Unauthorized Write Operation
**Timestamp**: 2026-03-15 14:23:17 UTC
**Severity**: CRITICAL
**Source**: 10.1.2.20 (Engineering Workstation)
**Destination**: 10.1.1.52 (PLC-3 Chemical Dosing)
**Function Code**: 16 (Write Multiple Registers)
**Registers**: 40050-40055
**Values Written**: [250, 100, 0, 1, 3600, 1]
**Baseline**: FC 16 never observed for this source-destination pair
**Context**: Register 40050 (Chlorine Dosing Rate) changed from 25 to 250
(safe range: 10-40). Register 40054 (Dosing Timer) changed from 1800 to 3600.
Combined effect would double chlorine concentration over extended period.
**Recommended Action**: Immediately verify physical process state. Isolate
source device. Check register values against expected setpoints with
plant operator.
---
### Alert 2: Device Enumeration Detected
**Timestamp**: 2026-03-15 14:20:05 to 14:20:47 UTC
**Severity**: HIGH
**Source**: 10.1.2.20
**Targets**: 10.1.1.50, 10.1.1.51, 10.1.1.52, 10.1.1.53, 10.1.1.54 (+10 more)
**Function Code**: 43 (Read Device Identification)
**Baseline**: FC 43 never observed from this source
**Context**: Sequential scanning of 15 devices in 42 seconds. Device
identification responses reveal PLC vendor, model, and firmware versions
for all scanned devices.
**Recommended Action**: Investigate source workstation for compromise
indicators. Block FC 43 from non-engineering subnets at OT firewall.© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/monitoring-scada-modbus-traffic-anomalies of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Monitoring Scada Modbus Traffic Anomalies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Monitoring Scada Modbus Traffic Anomalies this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | |
| TimesFM Forecastinggoogle-research/timesfm | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Adding A Modelopen-edge-platform/anomalib | 6.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Tiled Ensembleopen-edge-platform/anomalib | 6.2k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Kqlmicrosoft/fabric-rti-mcp | 131 | — | ~6.2k | Automated safety check: Pass | MIT | |
| Time Series Analytics Useropen-edge-platform/edge-ai-libraries | 171 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
open-edge-platform/anomalib
Adds a new anomaly-detection model to anomalib under src/anomalib/models/.
open-edge-platform/anomalib
Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.
microsoft/fabric-rti-mcp
KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.
open-edge-platform/edge-ai-libraries
Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…
Dynatrace/dynatrace-for-ai
Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. Monitoring Scada Modbus Traffic Anomalies is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns.
Monitoring Scada Modbus Traffic Anomalies fits situations like: tasks that involve Anomaly detection.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a claude-code`. Or copy the skill folder (skills/monitoring-scada-modbus-traffic-anomalies in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/monitoring-scada-modbus-traffic-anomalies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a codex`. Or copy the skill folder (skills/monitoring-scada-modbus-traffic-anomalies in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/monitoring-scada-modbus-traffic-anomalies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill monitoring-scada-modbus-traffic-anomalies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/monitoring-scada-modbus-traffic-anomalies, .gemini/skills/monitoring-scada-modbus-traffic-anomalies, .github/skills/monitoring-scada-modbus-traffic-anomalies and .opencode/skills/monitoring-scada-modbus-traffic-anomalies in your project.
Going by SKILL.md and its folder, Monitoring Scada Modbus Traffic Anomalies needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Monitoring Scada Modbus Traffic Anomalies is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Monitoring Scada Modbus Traffic Anomalies: TimesFM Forecasting (google-research/timesfm, 34k stars), Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars), Anomalib Tiled Ensemble (open-edge-platform/anomalib, 6.2k stars) and Kql (microsoft/fabric-rti-mcp, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.