Skills by mukul975
Every agent skill we found in mukul975's public GitHub repositories. 132 of 150 scan clean (A or B).
- Aabusing-dpapi-for-credential-accessmukul975/Anthropic-Cybersecurity-Skills · 34k
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
- Aabusing-shadow-credentials-for-privescmukul975/Anthropic-Cybersecurity-Skills · 34k
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
- Aachieving-cmmc-level-2-compliancemukul975/Anthropic-Cybersecurity-Skills · 34k
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
- Aacquiring-disk-image-with-dd-and-dcflddmukul975/Anthropic-Cybersecurity-Skills · 34k
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
- Aanalyzing-active-directory-acl-abusemukul975/Anthropic-Cybersecurity-Skills · 34k
Detect dangerous ACL misconfigurations in Active Directory using ldap3
- Aanalyzing-android-malware-with-apktoolmukul975/Anthropic-Cybersecurity-Skills · 34k
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
- Danalyzing-api-gateway-access-logsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
- Aanalyzing-apt-group-with-mitre-navigatormukul975/Anthropic-Cybersecurity-Skills · 34k
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.
- Aanalyzing-azure-activity-logs-for-threatsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
- Aanalyzing-bootkit-and-rootkit-samplesmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes bootkit and advanced rootkit malware infecting the Master
- Aanalyzing-browser-forensics-with-hindsightmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.
- Aanalyzing-campaign-attribution-evidencemukul975/Anthropic-Cybersecurity-Skills · 34k
Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.
- Aanalyzing-certificate-transparency-for-phishingmukul975/Anthropic-Cybersecurity-Skills · 34k
Monitor Certificate Transparency logs using crt.sh and Certstream to
- Aanalyzing-cloud-storage-access-patternsmukul975/Anthropic-Cybersecurity-Skills · 34k
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
- Aanalyzing-cobalt-strike-beacon-configurationmukul975/Anthropic-Cybersecurity-Skills · 34k
Extract and analyze Cobalt Strike beacon configuration from PE files
- Aanalyzing-cobaltstrike-malleable-c2-profilesmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
- Aanalyzing-command-and-control-communicationmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
- Aanalyzing-cyber-kill-chainmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
- Aanalyzing-disk-image-with-autopsymukul975/Anthropic-Cybersecurity-Skills · 34k
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.
- Aanalyzing-dns-logs-for-exfiltrationmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
- Fanalyzing-docker-container-forensicsmukul975/Anthropic-Cybersecurity-Skills · 34k
Investigate compromised Docker containers by analyzing images, layers,
- Aanalyzing-email-headers-for-phishing-investigationmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse and analyze email headers (Received chain, Return-Path, Message-ID)
- Aanalyzing-ethereum-smart-contract-vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 34k
Perform static and symbolic analysis of Solidity smart contracts using
- Aanalyzing-golang-malware-with-ghidramukul975/Anthropic-Cybersecurity-Skills · 34k
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo
- Aanalyzing-heap-spray-exploitationmukul975/Anthropic-Cybersecurity-Skills · 34k
Detect and analyze heap spray attacks in memory dumps using Volatility3
- Aanalyzing-indicators-of-compromisemukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
- Aanalyzing-ios-app-security-with-objectionmukul975/Anthropic-Cybersecurity-Skills · 34k
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
- Aanalyzing-kubernetes-audit-logsmukul975/Anthropic-Cybersecurity-Skills · 34k
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco.
- Fanalyzing-linux-audit-logs-for-intrusionmukul975/Anthropic-Cybersecurity-Skills · 34k
'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
- Canalyzing-linux-elf-malwaremukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,
- Aanalyzing-linux-kernel-rootkitsmukul975/Anthropic-Cybersecurity-Skills · 34k
Detect kernel-level rootkits in Linux memory dumps using Volatility3
- Fanalyzing-linux-system-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Examine Linux system artifacts (auth logs, cron/systemd persistence,
- Aanalyzing-lnk-file-and-jump-list-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd,
- Canalyzing-macro-malware-in-office-documentsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes malicious VBA macros embedded in Microsoft Office documents
- Aanalyzing-malicious-pdf-with-peepdfmukul975/Anthropic-Cybersecurity-Skills · 34k
Perform static analysis of malicious PDF documents using peepdf, pdfid,
- Aanalyzing-malicious-url-with-urlscanmukul975/Anthropic-Cybersecurity-Skills · 34k
URLScan.io is a free service for scanning and analyzing suspicious URLs.
- Aanalyzing-malware-behavior-with-cuckoo-sandboxmukul975/Anthropic-Cybersecurity-Skills · 34k
'Detonate malware samples in Cuckoo Sandbox to observe runtime behavior
- Aanalyzing-malware-family-relationships-with-malpediamukul975/Anthropic-Cybersecurity-Skills · 34k
Query the Malpedia API to look up malware family aliases and naming
- Aanalyzing-malware-persistence-with-autorunsmukul975/Anthropic-Cybersecurity-Skills · 34k
Use Sysinternals Autoruns to systematically enumerate and analyze malware
- Aanalyzing-malware-sandbox-evasion-techniquesmukul975/Anthropic-Cybersecurity-Skills · 34k
Detect sandbox and VM evasion techniques in malware samples by analyzing
- Aanalyzing-memory-dumps-with-volatilitymukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
- Aanalyzing-memory-forensics-with-lime-and-volatilitymukul975/Anthropic-Cybersecurity-Skills · 34k
'Performs Linux memory acquisition using LiME (Linux Memory Extractor)
- Aanalyzing-mft-for-deleted-file-recoverymukul975/Anthropic-Cybersecurity-Skills · 34k
Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,
- Aanalyzing-network-covert-channels-in-malwaremukul975/Anthropic-Cybersecurity-Skills · 34k
Detect and analyze covert communication channels used by malware, including
- Aanalyzing-network-flow-data-with-netflowmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
- Aanalyzing-network-packets-with-scapymukul975/Anthropic-Cybersecurity-Skills · 34k
Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.
- Aanalyzing-network-traffic-for-incidentsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
- Aanalyzing-network-traffic-of-malwaremukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes network traffic generated by malware during sandbox execution
- Aanalyzing-network-traffic-with-wiresharkmukul975/Anthropic-Cybersecurity-Skills · 34k
'Captures and analyzes network packet data using Wireshark and tshark
- Aanalyzing-office365-audit-logs-for-compromisemukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
- Aanalyzing-outlook-pst-for-email-forensicsmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.
- Aanalyzing-packed-malware-with-upx-unpackermukul975/Anthropic-Cybersecurity-Skills · 34k
'Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or when preparing a packed binary for disassembly in Ghidra or IDA.
- Aanalyzing-pdf-malware-with-pdfidmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
- Fanalyzing-persistence-mechanisms-in-linuxmukul975/Anthropic-Cybersecurity-Skills · 34k
Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.
- Aanalyzing-powershell-empire-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
- Aanalyzing-powershell-script-block-loggingmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
- Aanalyzing-prefetch-files-for-execution-historymukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.
- Aanalyzing-ransomware-encryption-mechanismsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes encryption algorithms, key management, and file encryption
- Aanalyzing-ransomware-leak-site-intelligencemukul975/Anthropic-Cybersecurity-Skills · 34k
Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or building proactive defense reporting from double-extortion leak-site activity.
- Aanalyzing-ransomware-network-indicatorsmukul975/Anthropic-Cybersecurity-Skills · 34k
Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
- Aanalyzing-ransomware-payment-walletsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.
- Canalyzing-sbom-for-supply-chain-vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 34k
'Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
- Aanalyzing-security-logs-with-splunkmukul975/Anthropic-Cybersecurity-Skills · 34k
'Leverages Splunk Enterprise Security and SPL (Search Processing Language)
- Aanalyzing-slack-space-and-file-system-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.
- Canalyzing-supply-chain-malware-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Investigate supply chain attack artifacts including trojanized software
- Aanalyzing-threat-actor-ttps-with-mitre-attackmukul975/Anthropic-Cybersecurity-Skills · 34k
Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.
- Aanalyzing-threat-actor-ttps-with-mitre-navigatormukul975/Anthropic-Cybersecurity-Skills · 34k
'Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group''s techniques, building Navigator coverage heatmaps, or assessing technique coverage gaps against a specific threat actor.
- Aanalyzing-threat-intelligence-feedsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes structured and unstructured threat intelligence feeds to extract
- Aanalyzing-threat-landscape-with-mispmukul975/Anthropic-Cybersecurity-Skills · 34k
Query a MISP (Malware Information Sharing Platform) instance via PyMISP
- Aanalyzing-tls-certificate-transparency-logsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
- Aanalyzing-typosquatting-domains-with-dnstwistmukul975/Anthropic-Cybersecurity-Skills · 34k
Generate domain permutations with dnstwist and check DNS resolution
- Aanalyzing-uefi-bootkit-persistencemukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications,
- Aanalyzing-usb-device-connection-historymukul975/Anthropic-Cybersecurity-Skills · 34k
Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs,
- Canalyzing-web-server-logs-for-intrusionmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Apache and Nginx access logs to detect SQL injection attempts,
- Aanalyzing-windows-amcache-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Parses the Windows Amcache.hve registry hive with Eric Zimmerman''s
- Aanalyzing-windows-event-logs-in-splunkmukul975/Anthropic-Cybersecurity-Skills · 34k
'Analyzes Windows Security, System, and Sysmon event logs in Splunk to
- Aanalyzing-windows-lnk-files-for-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Windows LNK shortcut files to extract target paths, MAC timestamps,
- Aanalyzing-windows-prefetch-with-pythonmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse Windows Prefetch (.pf) files with the windowsprefetch Python
- Aanalyzing-windows-registry-for-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Extract and analyze Windows Registry hives with tools like RegRipper
- Aanalyzing-windows-shellbag-artifactsmukul975/Anthropic-Cybersecurity-Skills · 34k
Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and
- Aassessing-vector-and-embedding-weaknessesmukul975/Anthropic-Cybersecurity-Skills · 34k
Test RAG vector stores (Pinecone, Qdrant, Weaviate, Chroma, pgvector,
- Aattacking-entra-id-with-roadtoolsmukul975/Anthropic-Cybersecurity-Skills · 34k
Enumerate Microsoft Entra ID (Azure AD) tenants with ROADrecon and
- Aattacking-oauth-with-device-code-phishingmukul975/Anthropic-Cybersecurity-Skills · 34k
Run OAuth 2.0 device-code and illicit-consent phishing attacks against
- Aauditing-aws-s3-bucket-permissionsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Systematically audit AWS S3 bucket permissions to identify publicly
- Aauditing-azure-active-directory-configurationmukul975/Anthropic-Cybersecurity-Skills · 34k
'Auditing Microsoft Entra ID (Azure Active Directory) configuration to
- Aauditing-cloud-with-cis-benchmarksmukul975/Anthropic-Cybersecurity-Skills · 34k
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking remediation for continuous compliance. Use when conducting a cloud security audit, validating CIS benchmark compliance (CIS v5 AWS, v4 Azure, v4 GCP), or setting up continuous cloud compliance monitoring.
- Aauditing-entra-id-with-aadinternalsmukul975/Anthropic-Cybersecurity-Skills · 34k
Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use during an authorized Entra ID/Microsoft 365 red-team assessment to map external attack surface or verify AD FS signing certs resist Golden SAML.
- Cauditing-foundry-smart-contract-securitymukul975/Anthropic-Cybersecurity-Skills · 34k
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based testing (forge fuzz + invariant tests with handlers) to catch reentrancy, access-control, oracle/price manipulation, and arithmetic bugs BEFORE deploying to an EVM chain. Also enforces key hygiene (no plaintext private keys, encrypted cast keystore) and a secure deploy workflow. Use when writing, reviewing, testing, or deploying Solidity/Foundry contracts, building a dApp, or working with forge/cast/anvil, MetaMask, or Web3/DeFi code.
- Aauditing-gcp-iam-permissionsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Auditing Google Cloud Platform IAM permissions to identify overly permissive
- Dauditing-kubernetes-cluster-rbacmukul975/Anthropic-Cybersecurity-Skills · 34k
'Auditing Kubernetes cluster RBAC configurations to identify overly permissive
- Cauditing-kubernetes-rbac-privilege-escalationmukul975/Anthropic-Cybersecurity-Skills · 34k
Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can escalate toward cluster-admin. Use when reviewing who can escalate privileges in a cluster, hunting exploitable RoleBindings during an authorized review, or validating least privilege after an RBAC change. Keywords: RBAC, ClusterRoleBinding, service account token, auth can-i, rbac-police, escalate, bind, impersonate. Do not use for designing and applying hardened RBAC - use implementing-rbac-hardening-for-kubernetes.
- Fauditing-mcp-servers-for-tool-poisoningmukul975/Anthropic-Cybersecurity-Skills · 34k
Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and description pinning. Use before adding a new MCP server to an agent stack, when reviewing an internal MCP server, detecting rug pulls, or investigating an agent's unexpected tool-driven behavior.
- Aauditing-terraform-infrastructure-for-securitymukul975/Anthropic-Cybersecurity-Skills · 34k
'Auditing Terraform infrastructure-as-code for security misconfigurations
- Dauditing-tls-certificate-transparency-logsmukul975/Anthropic-Cybersecurity-Skills · 34k
'Monitors Certificate Transparency (CT) logs to detect unauthorized certificate
- Aauditing-uefi-firmware-with-chipsecmukul975/Anthropic-Cybersecurity-Skills · 34k
Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.
- Aautomating-ioc-enrichmentmukul975/Anthropic-Cybersecurity-Skills · 34k
'Automates the enrichment of raw indicators of compromise with multi-source
- Abenchmarking-kubernetes-with-kube-benchmukul975/Anthropic-Cybersecurity-Skills · 34k
Installs and runs the kube-bench tool against a Kubernetes cluster as a Job, DaemonSet, or standalone binary, selecting the correct benchmark version and targets (control plane, etcd, kubelet, worker nodes) and emitting JSON or JUnit output for pipelines. Use when setting kube-bench up for the first time, choosing which benchmark version and node targets to run, wiring it into CI, or troubleshooting skipped or misdetected checks. Keywords: kube-bench, DaemonSet, --benchmark, --targets, JSON output, JUnit, CI integration. Do not use for interpreting the findings or producing an audit report - use performing-kubernetes-cis-benchmark-with-kube-bench.
- Abuilding-adversary-infrastructure-tracking-systemmukul975/Anthropic-Cybersecurity-Skills · 34k
Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP enrichment to map threat-actor C2 networks and flag newly registered domains matching known patterns. Use when pivoting from known indicators to discover related C2 infrastructure or maintaining a continuously updated map of a threat actor's network.
- Abuilding-attack-pattern-library-from-cti-reportsmukul975/Anthropic-Cybersecurity-Skills · 34k
Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs, and build a searchable STIX 2.1 attack-pattern library with detection templates. Use when cataloging attack patterns from CTI reports for threat-informed detection engineering, or generating Sigma/YARA templates from documented behaviors.
- Abuilding-automated-malware-submission-pipelinemukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds an automated malware submission and analysis pipeline that collects
- Cbuilding-c2-infrastructure-with-sliver-frameworkmukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulation framework) with multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard), redirectors, domain fronting, and multi-operator support for authorized red-team operations. Use when standing up resilient C2 for a red-team engagement or generating beacon/session implants that must survive blue-team detection.
- Abuilding-c2-redirector-infrastructuremukul975/Anthropic-Cybersecurity-Skills · 34k
Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC controls like domain fronting and UA/geo filtering. Use when standing up red-team C2 that must survive blue-team triage or ensuring only profile-matching implant traffic reaches the hidden team server.
- Abuilding-cloud-siem-with-sentinelmukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps response playbooks. Use when establishing a centralized SOC for multi-cloud environments, migrating from a legacy SIEM, or performing petabyte-scale threat hunting; not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs.
- Dbuilding-detection-rule-with-splunk-splmukul975/Anthropic-Cybersecurity-Skills · 34k
Build effective detection rules using Splunk Search Processing Language
- Abuilding-detection-rules-with-sigmamukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds vendor-agnostic detection rules using the Sigma rule format for
- Abuilding-devsecops-pipeline-with-gitlab-cimukul975/Anthropic-Cybersecurity-Skills · 34k
Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security templates. Use when building a shift-left DevSecOps pipeline in GitLab, adding automated vulnerability scanning stages to .gitlab-ci.yml, or triaging scanner findings with GitLab Duo AI before deployment.
- Abuilding-identity-federation-with-saml-azure-admukul975/Anthropic-Cybersecurity-Skills · 34k
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID.
- Abuilding-identity-governance-lifecycle-processmukul975/Anthropic-Cybersecurity-Skills · 34k
Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance.
- Abuilding-incident-response-dashboardmukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds real-time incident response dashboards in Splunk, Elastic, or
- Abuilding-incident-response-playbookmukul975/Anthropic-Cybersecurity-Skills · 34k
Designs and documents structured incident response playbooks with step-by-step
- Abuilding-incident-timeline-with-timesketchmukul975/Anthropic-Cybersecurity-Skills · 34k
Build collaborative forensic incident timelines using Timesketch to ingest,
- Abuilding-ioc-defanging-and-sharing-pipelinemukul975/Anthropic-Cybersecurity-Skills · 34k
Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains,
- Abuilding-ioc-enrichment-pipeline-with-openctimukul975/Anthropic-Cybersecurity-Skills · 34k
Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native
- Abuilding-malware-incident-communication-templatemukul975/Anthropic-Cybersecurity-Skills · 34k
Build structured communication templates for malware incidents (ransomware,
- Abuilding-patch-tuesday-response-processmukul975/Anthropic-Cybersecurity-Skills · 34k
Establish a repeatable operational process for triaging, testing, and
- Abuilding-phishing-reporting-button-workflowmukul975/Anthropic-Cybersecurity-Skills · 34k
Implement a phishing report button (Microsoft 365 built-in Report button
- Abuilding-ransomware-playbook-with-cisa-frameworkmukul975/Anthropic-Cybersecurity-Skills · 34k
Builds a structured ransomware incident response playbook aligned with
- Abuilding-red-team-c2-infrastructure-with-havocmukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB
- Abuilding-role-mining-for-rbac-optimizationmukul975/Anthropic-Cybersecurity-Skills · 34k
Apply bottom-up and top-down role mining techniques, including clustering
- Cbuilding-soc-escalation-matrixmukul975/Anthropic-Cybersecurity-Skills · 34k
Build a structured SOC escalation matrix defining severity tiers, response
- Abuilding-soc-metrics-and-kpi-trackingmukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds SOC performance metrics and KPI tracking dashboards measuring
- Abuilding-soc-playbook-for-ransomwaremukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds a structured SOC incident response playbook for ransomware attacks
- Abuilding-super-timelines-with-plasomukul975/Anthropic-Cybersecurity-Skills · 34k
Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py,
- Abuilding-threat-actor-profile-from-osintmukul975/Anthropic-Cybersecurity-Skills · 34k
Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools like Maltego and SpiderFoot, and producing structured dossiers of motivations, capabilities, infrastructure, and TTPs. Use when performing attribution or building an adversary dossier from open-source intelligence.
- Abuilding-threat-feed-aggregation-with-mispmukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms. Use when standing up centralized IOC management or wiring multi-source threat feeds into a SIEM.
- Abuilding-threat-hunt-hypothesis-frameworkmukul975/Anthropic-Cybersecurity-Skills · 34k
Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma) and documents findings in a standardized hunt report. Use when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.
- Abuilding-threat-intelligence-enrichment-in-splunkmukul975/Anthropic-Cybersecurity-Skills · 34k
Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.
- Abuilding-threat-intelligence-feed-integrationmukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds automated threat intelligence feed integration pipelines connecting
- Abuilding-threat-intelligence-platformmukul975/Anthropic-Cybersecurity-Skills · 34k
Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment workflows, STIX/TAXII interoperability, and analyst dashboards. Use when architecting or standing up a centralized CTI platform to collect, analyze, and disseminate threat intelligence across a security team.
- Abuilding-vulnerability-aging-and-sla-trackingmukul975/Anthropic-Cybersecurity-Skills · 34k
Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g. 14 days critical, 30 days high, 60 days medium, 90 days low), with automated escalations and compliance metrics reporting. Use when designing SLA policies, building aging/remediation dashboards, or proving compliance with remediation timelines.
- Abuilding-vulnerability-dashboard-with-defectdojomukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD, Jira ticketing, and Slack notifications via its REST API. Use when consolidating scanner output into one dashboard or automating vulnerability ticketing and executive reporting.
- Abuilding-vulnerability-exception-tracking-systemmukul975/Anthropic-Cybersecurity-Skills · 34k
Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA remediation timelines. Use when standing up a governance process for risk acceptance and exception approvals to support PCI DSS, SOC 2, or NIST CSF compliance.
- Abuilding-vulnerability-scanning-workflowmukul975/Anthropic-Cybersecurity-Skills · 34k
'Builds a structured vulnerability scanning workflow using tools like
- Abypassing-authentication-with-forced-browsingmukul975/Anthropic-Cybersecurity-Skills · 34k
Discovering and accessing unprotected pages, APIs, and administrative
- Acoercing-authentication-with-coercer-petitpotammukul975/Anthropic-Cybersecurity-Skills · 34k
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes, feeding the coerced NTLM auth into a relay against AD CS Web Enrollment (ESC8), LDAP (RBCD), or SMB. Use in authorized engagements to complete a coercion-relay chain against a Domain Controller, or to validate coercion detections and signing/EPA mitigations.
- Acollecting-indicators-of-compromisemukul975/Anthropic-Cybersecurity-Skills · 34k
'Systematically collects, categorizes, and distributes indicators of
- Acollecting-open-source-intelligencemukul975/Anthropic-Cybersecurity-Skills · 34k
'Collects and synthesizes open-source intelligence (OSINT) about threat
- Acollecting-threat-intelligence-with-mispmukul975/Anthropic-Cybersecurity-Skills · 34k
Deploy MISP, configure threat feeds (MISP community, freetext, TAXII, CSV), and use the PyMISP API to programmatically fetch, add, and search events and IOCs, building automated collection pipelines that aggregate indicators from community and commercial sources. Use when gathering, storing, or correlating IOCs and threat intelligence, or when scripting MISP ingestion via PyMISP.
- Acollecting-volatile-evidence-from-compromised-hostmukul975/Anthropic-Cybersecurity-Skills · 34k
Collect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and system state with documented chain of custody before they are lost. Use before isolating, shutting down, or remediating a compromised host, especially when fileless or memory-resident malware is suspected, root cause analysis is needed, or the evidence must hold up in legal proceedings.
- Aconducting-api-security-testingmukul975/Anthropic-Cybersecurity-Skills · 34k
'Conducts security testing of REST, GraphQL, and gRPC APIs to identify
- Aconducting-cloud-incident-responsemukul975/Anthropic-Cybersecurity-Skills · 34k
Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Use when CSPM alerts or audit logs show compromised cloud credentials, unauthorized IAM changes, or a breach spanning cloud services.
- Aconducting-cloud-penetration-testingmukul975/Anthropic-Cybersecurity-Skills · 34k
'This skill outlines methodologies for performing authorized penetration
- Aconducting-cyber-risk-assessment-with-nist-800-30mukul975/Anthropic-Cybersecurity-Skills · 34k
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis, threat sources, vulnerabilities, risk determination, qualitative risk, risk matrix, residual risk, risk treatment.
- Aconducting-domain-persistence-with-dcsyncmukul975/Anthropic-Cybersecurity-Skills · 34k
Perform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extract KRBTGT, Domain Admin, and service account hashes for Golden Ticket forging, typically with Mimikatz. Use in authorized engagements after finding principals with replication rights, to establish long-term domain persistence, or to validate detections for replication abuse.
- Aconducting-external-reconnaissance-with-osintmukul975/Anthropic-Cybersecurity-Skills · 34k
Conduct external recon using OSINT techniques to map an organization's external attack surface without touching target systems, gathering DNS records, certificate transparency logs, search results, social media, code repositories, and breach databases into a target profile. Use for the passive info-gathering phase of a pentest, external footprinting, or collecting employee/email intel for a social engineering campaign.
- Aconducting-full-scope-red-team-engagementmukul975/Anthropic-Cybersecurity-Skills · 34k
Plan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to evaluate an organization's detection, prevention, and response against APT-style behavior. Use when scoping or running a full-scope, objective-based engagement, or purple-teaming against a specific threat actor's TTPs.
- Aconducting-gdpr-compliance-assessmentmukul975/Anthropic-Cybersecurity-Skills · 34k
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
- Aconducting-internal-network-penetration-testmukul975/Anthropic-Cybersecurity-Skills · 34k
Execute an internal network penetration test simulating an insider threat
- Aconducting-internal-reconnaissance-with-bloodhound-cemukul975/Anthropic-Cybersecurity-Skills · 34k
Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold to Domain Admin. Use after an initial AD foothold to identify privilege escalation chains, or to validate that AD hardening closed known attack paths.
- Aconducting-malware-incident-responsemukul975/Anthropic-Cybersecurity-Skills · 34k
Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing containment, analysis, eradication, and recovery procedures aligned to MITRE ATT&CK. Use when responding to a confirmed or suspected malware infection, including trojan/worm/ransomware outbreaks, malware triage, or infected endpoint remediation.