Detecting Credential Dumping Techniques
mukul975/Anthropic-Cybersecurity-Skills
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.
Выгрузка конфигурации 1С в CF-файл. An agent skill from Nikolay-Shirokov/cc-1c-skills.
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/db-dump-cf .claude/skills/db-dump-cf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .claude/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cfType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/db-dump-cf .agents/skills/db-dump-cf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .agents/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/db-dump-cf .cursor/skills/db-dump-cf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .cursor/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Nikolay-Shirokov/cc-1c-skills.git --path .claude/skills/db-dump-cf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/db-dump-cf .gemini/skills/db-dump-cf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .gemini/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cfInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/db-dump-cf .github/skills/db-dump-cf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .github/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Nikolay-Shirokov/cc-1c-skills db-dump-cf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nikolay-Shirokov/cc-1c-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/db-dump-cf .opencode/skills/db-dump-cf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "db-dump-cf" agent skill from https://github.com/Nikolay-Shirokov/cc-1c-skills/tree/main/.claude/skills/db-dump-cf into .opencode/skills/db-dump-cf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-dump-cf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
db-dump-cfВыгрузка конфигурации 1С в CF-файл. An agent skill from Nikolay-Shirokov/cc-1c-skills.
DB Dump Cf is an agent skill from Nikolay-Shirokov/cc-1c-skills. Выгрузка конфигурации 1С в CF-файл. Используй когда нужно выгрузить конфигурацию в CF, сохранить конфигурацию, сделать бэкап CF
Its SKILL.md is about 710 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/db-dump-cf.py`).
The repository describes itself as: Набор навыков для AI(ИИ)-агентов (Claude Code, Cursor, Codex и др.), помогающий охватить полный цикл разработки на платформе 1С:Предприятие 8.3. Даёт модели абстракции над… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1fa205b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGlobAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (PowerShell and Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
DB Dump Cf loads about 713 tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 189 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Glob, AskUserQuestionAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Nikolay-Shirokov/cc-1c-skills at commit 1fa205b, republished under its MIT licence (© Nikolay-Shirokov). 189 words, ~713 tokens.
.claude/skills/db-dump-cf/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Выгружает конфигурацию информационной базы в бинарный CF-файл.
/db-dump-cf [database] [output.cf]
/db-dump-cf dev config.cf
/db-dump-cf — база по умолчанию, файл config.cfПрочитай .v8-project.json из корня проекта и разреши базу:
.v8-project.jsondatabases[].branchesdefault
Платформа — v8path найденной записи базы, иначе корневой v8path. Не задан ни там, ни там — -V8Path не передавай.
Если файла нет — предложи /db-list add.
Если использованная база не зарегистрирована — после выполнения предложи добавить через /db-list add.powershell.exe -NoProfile -File "${CLAUDE_SKILL_DIR}/scripts/db-dump-cf.ps1" <параметры>| Параметр | Обязательный | Описание |
|---|---|---|
-V8Path <путь> | нет | Каталог bin платформы, или полный путь к 1cv8.exe / ibcmd.exe |
-InfoBasePath <путь> | * | Файловая база |
-InfoBaseServer <сервер> | * | Сервер 1С (для серверной базы) |
-InfoBaseRef <имя> | * | Имя базы на сервере |
-UserName <имя> | нет | Имя пользователя |
-Password <пароль> | нет | Пароль |
-OutputFile <путь> | да | Путь к выходному CF-файлу |
-Extension <имя> | нет | Выгрузить расширение |
-AllExtensions | нет | Выгрузить все расширения |
-AdditionalV8Arguments <список> | нет | Доп. аргументы запуска 1cv8.exe через запятую, напр. /UseHwLicenses+ |
-AdditionalIbcmdArguments <список> | нет | Доп. аргументы ibcmd через запятую, в форме --ключ=значение |
*— нужен либо-InfoBasePath, либо пара-InfoBaseServer+-InfoBaseRef
# Выгрузка конфигурации (файловая база)
powershell.exe -NoProfile -File "${CLAUDE_SKILL_DIR}/scripts/db-dump-cf.ps1" -InfoBasePath "C:\Bases\MyDB" -UserName "Admin" -OutputFile "C:\backup\config.cf"
# Серверная база
powershell.exe -NoProfile -File "${CLAUDE_SKILL_DIR}/scripts/db-dump-cf.ps1" -InfoBaseServer "srv01" -InfoBaseRef "MyApp_Dev" -UserName "Admin" -Password "secret" -OutputFile "config.cf"
# Выгрузка расширения
powershell.exe -NoProfile -File "${CLAUDE_SKILL_DIR}/scripts/db-dump-cf.ps1" -InfoBasePath "C:\Bases\MyDB" -UserName "Admin" -OutputFile "ext.cfe" -Extension "МоёРасширение"© Nikolay-Shirokov, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in .claude/skills/db-dump-cf of Nikolay-Shirokov/cc-1c-skills.
Open the folder on GitHubat commit 1fa205b
DB Dump Cf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| DB Dump Cf this skillNikolay-Shirokov/cc-1c-skills | 671 | — | ~713 | Automated safety check: Notes | MIT | |
| Detecting Credential Dumping Techniquesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~849 | Automated safety check: Pass | Apache-2.0 | |
| Extracting Credentials From Memory Dumpmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Memory Dumps With Volatilitymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| .NET Crash Dump Collectiondotnet/skills | 5.6k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Detecting T1003 Credential Dumping With Edrmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
mukul975/Anthropic-Cybersecurity-Skills
Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g.
mukul975/Anthropic-Cybersecurity-Skills
Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz.
mukul975/Anthropic-Cybersecurity-Skills
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
dotnet/skills
Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.
mukul975/Anthropic-Cybersecurity-Skills
Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security…
macro-inc/macro
Dump clean Postgres schema to a file and copy path to clipboard.
Nikolay-Shirokov/cc-1c-skills
Работа с хранилищем конфигурации 1С. An agent skill from Nikolay-Shirokov/cc-1c-skills.
Nikolay-Shirokov/cc-1c-skills
Компиляция управляемой формы 1С из JSON-определения или из метаданных объекта.
Nikolay-Shirokov/cc-1c-skills
Точечное редактирование конфигурации 1С. An agent skill from Nikolay-Shirokov/cc-1c-skills.
Nikolay-Shirokov/cc-1c-skills
Правка существующей управляемой формы 1С — элементы, реквизиты, команды и свойства самой формы.
Nikolay-Shirokov/cc-1c-skills
Создать пустую конфигурацию 1С (scaffold XML-исходников). An agent skill from Nikolay-Shirokov/cc-1c-skills.
Nikolay-Shirokov/cc-1c-skills
Создать расширение конфигурации 1С (CFE) — scaffold XML-исходников.
Выгрузка конфигурации 1С в CF-файл. An agent skill from Nikolay-Shirokov/cc-1c-skills. DB Dump Cf is an agent skill from Nikolay-Shirokov/cc-1c-skills. Выгрузка конфигурации 1С в CF-файл.
Run `npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a claude-code`. Or copy the skill folder (.claude/skills/db-dump-cf in Nikolay-Shirokov/cc-1c-skills) into .claude/skills/db-dump-cf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a codex`. Or copy the skill folder (.claude/skills/db-dump-cf in Nikolay-Shirokov/cc-1c-skills) into .agents/skills/db-dump-cf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Nikolay-Shirokov/cc-1c-skills --skill db-dump-cf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/db-dump-cf, .gemini/skills/db-dump-cf, .github/skills/db-dump-cf and .opencode/skills/db-dump-cf in your project.
Going by SKILL.md and its folder, DB Dump Cf needs PowerShell and Python for the scripts in its folder. Our summary lists: Python 3; PowerShell. Its frontmatter pre-approves these tools: Bash, Read, Glob, AskUserQuestion.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
DB Dump Cf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 713 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with DB Dump Cf: Detecting Credential Dumping Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Extracting Credentials From Memory Dump (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Memory Dumps With Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and .NET Crash Dump Collection (dotnet/skills, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Nikolay-Shirokov (a GitHub user) maintains it in Nikolay-Shirokov/cc-1c-skills, which has 671 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 5, 2026.
Source: Nikolay-Shirokov/cc-1c-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.