Wardn HubTrusted MCP server directory.

Registry

  • MCP Servers
  • Skills
  • Categories

Resources

  • API docs
  • Score method

Contribute

  • Submit server
  • Advertise
© 2026 Wardn Hub
Wardn Hub
MCP ServersSkillsCategoriesAPI docsSubmit server
Submit server
skills/mukul975/Anthropic-Cybersecurity-Skills
Source

mukul975/Anthropic-Cybersecurity-Skills

Skills
500
#SkillSourceInstalls
1securing-github-actions-workflowsS · 100This skill covers hardening GitHub Actions workflows against supplymukul975/Anthropic-Cybersecurity-Skills · 3 installsmukul975/Anthropic-Cybersecurity-Skills32implementing-rbac-hardening-for-kubernetesA · 79Harden Kubernetes Role-Based Access Control by implementing least-privilegemukul975/Anthropic-Cybersecurity-Skills · 1 installsmukul975/Anthropic-Cybersecurity-Skills13Abuse of Public-Facing API: Mobile API AbuseC+ · 13Detects and analyzes malicious behavior in mobile applications throughmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills04Access with Stolen Session CookieC+ · 21Establish SAML 2.0 identity federation between on-premises Active Directorymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills05Access with Stolen Session CookieB · 41Implements passwordless authentication using Microsoft Entra ID withmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills06Access with Stolen Session CookieC+ · 13A cryptographic audit systematically reviews an application's use ofmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills07Access with Stolen Session CookieC · 0Executes authorized phishing simulation campaigns to assess an organization''smukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills08Account Access RemovalA+ · 96Auditing Kubernetes cluster RBAC configurations to identify overly permissivemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills09Account ManipulationB · 41Implements Delinea Secret Server for privileged access management (PAM)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills010Account ManipulationS · 100Implements comprehensive Google Workspace security hardening includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills011Account ManipulationS · 100Detecting compromised cloud credentials across AWS, Azure, and GCP bymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills012Account Manipulation: Account LinkingS · 100Detect unusual API call patterns in AWS CloudTrail logs using boto3,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills013Account Manipulation: Add Authorized UserC · 0Configure Microsoft Entra Privileged Identity Management to enforce just-in-timemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills014Account Manipulation: Change Account DetailsB · 41This skill guides practitioners through hardening AWS Identity and Accessmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills015Account Manipulation: Change of Payment DetailsC · 0Deploy and configure Proofpoint Email Protection as a secure email gatewaymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills016Account Manipulation: Enable Account FeaturesB · 42Configure and execute access recertification campaigns in Saviynt Enterprisemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills017Account Manipulation: Enable Account FeaturesB · 49Performs entitlement review and access certification campaigns usingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills018Account TakeoverB · 49Deploy SailPoint IdentityNow or IdentityIQ for identity governance andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills019Account TakeoverB · 49Configure SAML 2.0 single sign-on for Google Workspace with a third-partymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills020Account TakeoverB · 45Perform authorized initial access using EvilGinx3 adversary-in-the-middlemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills021Account TakeoverC · 0Builds comprehensive identity governance and lifecycle management processesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills022Account TakeoverC+ · 16Extract stored credentials from compromised endpoints using the LaZagnemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills023Account TakeoverB- · 30Executes a structured ransomware incident response from initial detectionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills024Account TakeoverS · 100Detects credential stuffing attacks by analyzing authentication logsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills025Account TakeoverA- · 72Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacksmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills026Account Takeover: Exposed API KeyC · 6Extract cached credentials, password hashes, Kerberos tickets, and authenticationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills027Account Takeover: Exposed Login CredentialB · 41Automate GoPhish phishing simulation campaigns using the Python gophishmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills028Account Takeover: Exposed Login CredentialC · 0Responds to phishing incidents by analyzing reported emails, extractingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills029Account Takeover: Exposed Login CredentialA · 79Detect and prevent QR code phishing (quishing) attacks that bypass traditionalmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills030Account Takeover: Exposed Login CredentialB- · 32Spearphishing simulation is a targeted social engineering attack vectormukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills031Account Takeover: Exposed Login CredentialC · 0Investigates phishing email incidents from initial user report throughmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills032Account Takeover: Exposed Login CredentialC · 0Performs firmware image extraction and analysis using binwalk to identifymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills033Account Takeover: Exposed Login CredentialC · 0Deploy CyberArk Privileged Access Management to discover, vault, rotate,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills034Account Takeover: Exposed Login CredentialC+ · 24Detect OS credential dumping techniques targeting LSASS memory, SAM database,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills035Account Takeover: Exposed Login CredentialB · 49Deploy privileged access management for database systems including Oracle,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills036Account Takeover: Exposed Login CredentialC · 0Implement automated user provisioning and deprovisioning using SCIM 2.0mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills037Account Takeover: Password ResetB · 40Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Providermukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills038Adversary-in-the-Browser: Malicious JavaScript InjectionB · 49Deploys remote browser isolation (RBI) as a core component of a Zeromukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills039Adversary-in-the-MiddleS · 100Harden LDAP directory services against common attacks including credentialmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills040Browser Session HijackingA · 76Detects and responds to OAuth token theft and replay attacks in cloudmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills041Brute Force: Credential StuffingC · 0Monitors dark web forums, marketplaces, paste sites, and ransomwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills042Brute Force: Password CrackingS · 100Detect LSASS credential dumping, SAM database extraction, and NTDS.ditmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills043Conversion to Physical Monetary Instruments: CashC · 0Validate backup integrity through cryptographic hash verification, automatedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills044Conversion to Physical Monetary Instruments: CashA · 76Test and validate ransomware recovery procedures including backup restoremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills045Conversion to Physical Monetary Instruments: CashC · 0Designs and implements a ransomware-resilient backup strategy followingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills046Conversion to Physical Monetary Instruments: CashC · 0Identify, collect, and analyze ransomware attack artifacts to determinemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills047Conversion to Physical Monetary Instruments: CashS · 99Plans and facilitates tabletop exercises simulating ransomware incidentsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills048Convert to CryptocurrencyB- · 36Detects early-stage ransomware indicators in network traffic beforemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills049Convert to CryptocurrencyS · 100Configures Windows Group Policy Objects (GPO) to prevent ransomwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills050Convert to CryptocurrencyS · 100This skill teaches security teams how to detect and respond to unauthorizedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills051Create Fake Materials: Fake WebsiteC · 0Design and execute a social engineering penetration test including phishing,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills052Create Fake Materials: Fake WebsiteS · 100Configure Google Workspace advanced phishing and malware protection settingsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills053Create Fake Materials: Fake WebsiteC · 0Implement a phishing report button in email clients with automated triagemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills054Create Fake Materials: Fake WebsiteC · 0Analyzes indicators of compromise (IOCs) including IP addresses, domains,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills055Create Fake Materials: Fake WebsiteC · 0Parse and analyze email headers to trace the origin of phishing emails,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills056Create Fake Materials: Fake WebsiteA · 79Spearphishing targets specific individuals using personalized, researchedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills057Create Fake Materials: Fake WebsiteS · 100Hunt for spearphishing campaign indicators across email logs, endpointmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills058Create Fake Materials: Fake WebsiteB · 49Deploy Mimecast Targeted Threat Protection including URL Protect, Attachmentmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills059Delete Relevant EmailsS · 100Business Email Compromise (BEC) is a sophisticated fraud scheme wheremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills060Device Fingerprint SpoofingC · 0Automate credential rotation for service accounts across Active Directory,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills061Device Fingerprint SpoofingA- · 66Performs OAuth 2.0 scope minimization review to identify over-permissionedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills062Electronic Funds Transfer: Wire TransferA- · 73Monitor and analyze ransomware group data leak sites (DLS) to track victimmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills063Electronic Funds Transfer: Wire TransferC+ · 24Deploys and monitors ransomware canary files across critical directoriesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills064Electronic Funds Transfer: Wire TransferA- · 72Deploy AI and NLP-powered detection systems to identify business emailmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills065Electronic Funds Transfer: Wire TransferS · 99Detects AI-generated deepfake audio used in voice phishing (vishing)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills066Email SpoofingC · 0Monitor for brand impersonation attacks across domains, social media,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills067Gather Customer InformationA- · 73Monitor paste sites like Pastebin and GitHub Gists for leaked credentials,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills068Impersonate Account HolderC · 0GoPhish is an open-source phishing simulation framework used by securitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills069Impersonate Account HolderS · 100Security awareness training is the human layer of phishing defense. Anmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills070Impersonate OfficialC · 0Automate phishing incident response using Splunk SOAR REST API to createmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills071Indicator RemovalA- · 66Implements Sigstore-based software signing and verification using Cosignmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills072Indicator RemovalB · 49Deploys canary files (honeytokens) across file systems to detect ransomwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills073Indicator RemovalA- · 72Detects ransomware encryption activity in real time using entropy analysis,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills074Insider Access AbuseA · 79Deploys canary files, honeypot shares, and decoy systems to detect ransomwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills075Insider Access AbuseB · 49Implements HashiCorp Vault dynamic secrets engines for database credentials,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills076Insider Access AbuseB · 49Implement HashiCorp Boundary for identity-aware zero trust infrastructuremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills077PhishingB+ · 57Monitor Certificate Transparency logs using crt.sh and Certstream tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills078PhishingB+ · 61Detect typosquatting, homograph phishing, and brand impersonation domainsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills079PhishingB- · 31Queries Certificate Transparency logs via crt.sh and pycrtsh to detectmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills080Phishing for InformationA · 79Implement continuous identity verification for zero trust using phishing-resistantmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills081Phone Number Spoofing: Official Phone Number SpoofingC · 0Plan and execute authorized vishing (voice phishing) pretext calls tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills082Remote Access ToolsS · 100Reverse engineer ransomware encryption routines to identify cryptographicmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills083Remote Access ToolsB · 49Executes structured recovery from a ransomware incident following NISTmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills084Remote Access ToolsS · 100Analyzes encryption algorithms, key management, and file encryptionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills085Stage Capabilities: SEO PoisoningA- · 67Threat actor infrastructure tracking involves monitoring and mappingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills086Steal Web Session CookieB- · 28Configure secure OAuth 2.0 authorization flows including Authorizationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills087Steal Web Session CookieA+ · 95Detects anomalous authentication patterns using UEBA analytics, statisticalmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills088Steal Web Session CookieA · 76Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-requestmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills089StructuringA- · 73Traces ransomware cryptocurrency payment flows using blockchain analysismukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills090Transfer of fundsC · 6Detects and exploits ransomware kill switch mechanisms including mutex-basedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills091Transfer of fundsB- · 35Builds a structured SOC incident response playbook for ransomware attacksmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills092Transfer of fundsA+ · 96Builds a structured ransomware incident response playbook aligned withmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills093Transfer of fundsC+ · 24Analyzes malicious Linux ELF (Executable and Linkable Format) binariesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills094Transfer of fundsC+ · 13Identify ransomware network indicators including C2 beaconing patterns,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills095Use Alternate Authentication Material: Application Access TokenA · 76This skill covers implementing Okta as a centralized identity providermukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills096Use Alternate Authentication Material: Application Access TokenC · 0Detecting exposed AWS credentials in source code repositories, CI/CDmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills097abusing-dpapi-for-credential-accessC · 0Extract DPAPI-protected secrets such as credentials and browser data offline and online.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills098abusing-shadow-credentials-for-privescC+ · 18Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills099achieving-cmmc-level-2-complianceS · 100>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0100acquiring-disk-image-with-dd-and-dcflddS · 100Create forensically sound bit-for-bit disk images using dd and dcflddmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0101analyzing-active-directory-acl-abuseB · 49Detect dangerous ACL misconfigurations in Active Directory using ldap3mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0102analyzing-android-malware-with-apktoolA · 79Perform static analysis of Android APK malware samples using apktoolmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0103analyzing-api-gateway-access-logsS · 100Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detectmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0104analyzing-apt-group-with-mitre-navigatorA · 76Analyze advanced persistent threat (APT) group techniques using MITREmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0105analyzing-azure-activity-logs-for-threatsA · 79Queries Azure Monitor activity logs and sign-in logs via azure-monitor-querymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0106analyzing-bootkit-and-rootkit-samplesC · 0Analyzes bootkit and advanced rootkit malware that infects the Mastermukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0107analyzing-browser-forensics-with-hindsightB · 45Analyze Chromium-based browser artifacts using Hindsight to extract browsingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0108analyzing-campaign-attribution-evidenceA · 79Campaign attribution analysis involves systematically evaluating evidencemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0109analyzing-cloud-storage-access-patternsA · 79Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storagemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0110analyzing-cobalt-strike-beacon-configurationB- · 37Extract and analyze Cobalt Strike beacon configuration from PE filesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0111analyzing-cobaltstrike-malleable-c2-profilesA · 79Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrikemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0112analyzing-command-and-control-communicationA- · 64Analyzes malware command-and-control (C2) communication protocols tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0113analyzing-cyber-kill-chainS · 100Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chainmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0114analyzing-disk-image-with-autopsyB · 49Perform comprehensive forensic analysis of disk images using Autopsymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0115analyzing-dns-logs-for-exfiltrationS · 100Analyzes DNS query logs to detect data exfiltration via DNS tunneling,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0116analyzing-docker-container-forensicsC · 0Investigate compromised Docker containers by analyzing images, layers,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0117analyzing-ethereum-smart-contract-vulnerabilitiesA+ · 96Perform static and symbolic analysis of Solidity smart contracts usingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0118analyzing-golang-malware-with-ghidraA · 79Reverse engineer Go-compiled malware using Ghidra with specialized scriptsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0119analyzing-heap-spray-exploitationS · 100Detect and analyze heap spray attacks in memory dumps using Volatility3mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0120analyzing-ios-app-security-with-objectionB · 49>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0121analyzing-kubernetes-audit-logsS · 100Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0122analyzing-linux-audit-logs-for-intrusionS · 100Uses the Linux Audit framework (auditd) with ausearch and aureport utilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0123analyzing-linux-kernel-rootkitsB- · 37Detect kernel-level rootkits in Linux memory dumps using Volatility3mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0124analyzing-linux-system-artifactsC · 8Examine Linux system artifacts including auth logs, cron jobs, shellmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0125analyzing-lnk-file-and-jump-list-artifactsS · 100Analyze Windows LNK shortcut files and Jump List artifacts to establishmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0126analyzing-macro-malware-in-office-documentsA · 79Analyzes malicious VBA macros embedded in Microsoft Office documentsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0127analyzing-malicious-pdf-with-peepdfA · 79Perform static analysis of malicious PDF documents using peepdf, pdfid,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0128analyzing-malicious-url-with-urlscanC · 0URLScan.io is a free service for scanning and analyzing suspicious URLs.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0129analyzing-malware-behavior-with-cuckoo-sandboxB- · 25Executes malware samples in Cuckoo Sandbox to observe runtime behaviormukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0130analyzing-malware-family-relationships-with-malpediaA · 76Use the Malpedia platform and API to research malware family relationships,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0131analyzing-malware-persistence-with-autorunsB · 38Use Sysinternals Autoruns to systematically identify and analyze malwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0132analyzing-malware-sandbox-evasion-techniquesS · 100Detect sandbox evasion techniques in malware samples by analyzing timingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0133analyzing-memory-dumps-with-volatilityA- · 72Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0134analyzing-memory-forensics-with-lime-and-volatilityS · 100Performs Linux memory acquisition using LiME (Linux Memory Extractor)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0135analyzing-mft-for-deleted-file-recoveryS · 100Analyze the NTFS Master File Table ($MFT) to recover metadata and contentmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0136analyzing-network-covert-channels-in-malwareS · 100Detect and analyze covert communication channels used by malware includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0137analyzing-network-flow-data-with-netflowS · 100Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, portmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0138analyzing-network-packets-with-scapyA · 79Craft, send, sniff, and dissect network packets using Scapy for protocolmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0139analyzing-network-traffic-for-incidentsB- · 25Analyzes network traffic captures and flow data to identify adversary activity during security incidents, includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0140analyzing-network-traffic-of-malwareA- · 68Analyzes network traffic generated by malware during sandbox executionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0141analyzing-network-traffic-with-wiresharkC+ · 24Captures and analyzes network packet data using Wireshark and tsharkmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0142analyzing-office365-audit-logs-for-compromiseA- · 73Parse Office 365 Unified Audit Logs via Microsoft Graph API to detectmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0143analyzing-outlook-pst-for-email-forensicsS · 100Analyze Microsoft Outlook PST and OST files for email forensic evidencemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0144analyzing-packed-malware-with-upx-unpackerA- · 72Identifies and unpacks UPX-packed and other packed malware samples tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0145analyzing-pdf-malware-with-pdfidC+ · 24Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0146analyzing-persistence-mechanisms-in-linuxC · 1Detect and analyze Linux persistence mechanisms including crontab entries,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0147analyzing-powershell-empire-artifactsS · 100Detect PowerShell Empire framework artifacts in Windows event logs bymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0148analyzing-powershell-script-block-loggingA+ · 96Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTXmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0149analyzing-prefetch-files-for-execution-historyA · 76Parse Windows Prefetch files to determine program execution history includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0150analyzing-sbom-for-supply-chain-vulnerabilitiesC · 0Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSONmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0151analyzing-security-logs-with-splunkA · 76Leverages Splunk Enterprise Security and SPL (Search Processing Language)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0152analyzing-slack-space-and-file-system-artifactsB · 49Examine file system slack space, MFT entries, USN journal, and alternatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0153analyzing-supply-chain-malware-artifactsB · 38Investigate supply chain attack artifacts including trojanized softwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0154analyzing-threat-actor-ttps-with-mitre-attackA- · 63MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0155analyzing-threat-actor-ttps-with-mitre-navigatorA- · 72Map advanced persistent threat (APT) group tactics, techniques, andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0156analyzing-threat-intelligence-feedsA · 79Analyzes structured and unstructured threat intelligence feeds to extractmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0157analyzing-threat-landscape-with-mispA · 79Analyze the threat landscape using MISP (Malware Information Sharingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0158analyzing-uefi-bootkit-persistenceC · 0Analyzes UEFI bootkit persistence mechanisms including firmware implantsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0159analyzing-usb-device-connection-historyB- · 37Investigate USB device connection history from Windows registry, eventmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0160analyzing-web-server-logs-for-intrusionC · 0Parse Apache and Nginx access logs to detect SQL injection attempts,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0161analyzing-windows-amcache-artifactsA- · 72Parses and analyzes the Windows Amcache.hve registry hive to extractmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0162analyzing-windows-event-logs-in-splunkB · 49Analyzes Windows Security, System, and Sysmon event logs in Splunk tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0163analyzing-windows-lnk-files-for-artifactsA · 79Parse Windows LNK shortcut files to extract target paths, timestamps,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0164analyzing-windows-prefetch-with-pythonA · 79Parse Windows Prefetch files using the windowsprefetch Python librarymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0165analyzing-windows-registry-for-artifactsS · 100Extract and analyze Windows Registry hives to uncover user activity,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0166analyzing-windows-shellbag-artifactsS · 100Analyze Windows Shellbag registry artifacts to reconstruct folder browsingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0167assessing-vector-and-embedding-weaknessesA+ · 96Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0168attacking-entra-id-with-roadtoolsC · 5Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0169attacking-oauth-with-device-code-phishingC · 2Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0170auditing-aws-s3-bucket-permissionsA · 76Systematically audit AWS S3 bucket permissions to identify publiclymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0171auditing-azure-active-directory-configurationC · 7Auditing Microsoft Entra ID (Azure Active Directory) configuration tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0172auditing-cloud-with-cis-benchmarksS · 100This skill details how to conduct cloud security audits using Centermukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0173auditing-entra-id-with-aadinternalsB- · 26Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0174auditing-foundry-smart-contract-securityB · 49>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0175auditing-gcp-iam-permissionsA · 79Auditing Google Cloud Platform IAM permissions to identify overly permissivemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0176auditing-kubernetes-rbac-privilege-escalationB · 49Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0177auditing-mcp-servers-for-tool-poisoningB- · 37Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0178auditing-terraform-infrastructure-for-securityB- · 37Auditing Terraform infrastructure-as-code for security misconfigurationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0179auditing-tls-certificate-transparency-logsC · 0Monitors Certificate Transparency (CT) logs to detect unauthorized certificatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0180auditing-uefi-firmware-with-chipsecA · 79Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0181automating-ioc-enrichmentC · 0Automates the enrichment of raw indicators of compromise with multi-sourcemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0182benchmarking-kubernetes-with-kube-benchB- · 29Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0183building-adversary-infrastructure-tracking-systemA- · 63Build an automated system to track adversary infrastructure using passivemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0184building-attack-pattern-library-from-cti-reportsS · 100Extract and catalog attack patterns from cyber threat intelligence reportsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0185building-automated-malware-submission-pipelineC · 0Builds an automated malware submission and analysis pipeline that collectsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0186building-c2-infrastructure-with-sliver-frameworkC · 0Build and configure a resilient command-and-control infrastructure usingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0187building-c2-redirector-infrastructureB- · 26Architect redirectors with nginx and Apache, malleable profiles, and OPSECmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0188building-cloud-siem-with-sentinelA · 79This skill covers deploying Microsoft Sentinel as a cloud-native SIEMmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0189building-detection-rule-with-splunk-splB · 49Build effective detection rules using Splunk Search Processing Languagemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0190building-detection-rules-with-sigmaA · 79Builds vendor-agnostic detection rules using the Sigma rule format formukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0191building-devsecops-pipeline-with-gitlab-ciC · 0Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CDmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0192building-incident-response-dashboardC+ · 20Builds real-time incident response dashboards in Splunk, Elastic, ormukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0193building-incident-response-playbookC · 0Designs and documents structured incident response playbooks that definemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0194building-incident-timeline-with-timesketchA · 76Build collaborative forensic incident timelines using Timesketch to ingest,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0195building-ioc-defanging-and-sharing-pipelineC · 0Build an automated pipeline to defang indicators of compromise (URLs,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0196building-ioc-enrichment-pipeline-with-openctiC · 0OpenCTI is an open-source platform for managing cyber threat intelligencemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0197building-malware-incident-communication-templateA- · 72Build structured communication templates for malware incidents includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0198building-patch-tuesday-response-processA- · 69Establish a structured operational process to triage, test, and deploymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0199building-red-team-c2-infrastructure-with-havocC · 0Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0200building-role-mining-for-rbac-optimizationA- · 72Apply bottom-up and top-down role mining techniques to discover optimalmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0201building-soc-escalation-matrixS · 100Build a structured SOC escalation matrix defining severity tiers, responsemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0202building-soc-metrics-and-kpi-trackingC · 0Builds SOC performance metrics and KPI tracking dashboards measuringmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0203building-super-timelines-with-plasoA · 79Generate log2timeline and Plaso super-timelines and triage them in Timesketch.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0204building-threat-actor-profile-from-osintB+ · 61Build comprehensive threat actor profiles using open-source intelligencemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0205building-threat-feed-aggregation-with-mispB+ · 58Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0206building-threat-hunt-hypothesis-frameworkA- · 64Build a systematic threat hunt hypothesis framework that transforms threatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0207building-threat-intelligence-enrichment-in-splunkA · 76Build automated threat intelligence enrichment pipelines in Splunk Enterprisemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0208building-threat-intelligence-feed-integrationC+ · 14Builds automated threat intelligence feed integration pipelines connectingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0209building-threat-intelligence-platformC · 0Building a Threat Intelligence Platform (TIP) involves deploying andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0210building-vulnerability-aging-and-sla-trackingS · 100Implement a vulnerability aging dashboard and SLA tracking system tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0211building-vulnerability-dashboard-with-defectdojoC · 0Deploy DefectDojo as a centralized vulnerability management dashboardmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0212building-vulnerability-exception-tracking-systemC · 0Build a vulnerability exception and risk acceptance tracking system withmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0213building-vulnerability-scanning-workflowB+ · 61Builds a structured vulnerability scanning workflow using tools likemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0214bypassing-authentication-with-forced-browsingB+ · 57Discovering and accessing unprotected pages, APIs, and administrativemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0215coercing-authentication-with-coercer-petitpotamC · 0Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer across MS-RPRN, MS-DFSNM, and MS-FSRVP to feed NTLM relay into AD CS Web Enrollment (ESC8) and other relay targets.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0216collecting-indicators-of-compromiseB+ · 58Systematically collects, categorizes, and distributes indicators ofmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0217collecting-open-source-intelligenceA- · 67Collects and synthesizes open-source intelligence (OSINT) about threatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0218collecting-threat-intelligence-with-mispC · 2MISP (Malware Information Sharing Platform) is an open-source threatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0219collecting-volatile-evidence-from-compromised-hostC · 0Collect volatile forensic evidence from a compromised system followingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0220conducting-api-security-testingB · 40Conducts security testing of REST, GraphQL, and gRPC APIs to identifymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0221conducting-cloud-incident-responseB · 41Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0222conducting-cloud-penetration-testingB · 49This skill outlines methodologies for performing authorized penetrationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0223conducting-cyber-risk-assessment-with-nist-800-30S · 100>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0224conducting-domain-persistence-with-dcsyncC+ · 24Perform DCSync attacks to replicate Active Directory credentials andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0225conducting-external-reconnaissance-with-osintC · 0Conducts external reconnaissance using Open Source Intelligence (OSINT)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0226conducting-full-scope-red-team-engagementC+ · 17Plan and execute a comprehensive red team engagement covering reconnaissancemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0227conducting-internal-network-penetration-testB · 49Execute an internal network penetration test simulating an insider threatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0228conducting-internal-reconnaissance-with-bloodhound-ceA · 84Conduct internal Active Directory reconnaissance using BloodHound Communitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0229conducting-malware-incident-responseB- · 26Responds to malware infections across enterprise endpoints by identifying the malware family, determining infectionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0230conducting-man-in-the-middle-attack-simulationB · 47Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercapmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0231conducting-memory-forensics-with-volatilityA · 79Performs memory forensics analysis using Volatility 3 to extract evidencemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0232conducting-mobile-app-penetration-testC · 0Conducts penetration testing of iOS and Android mobile applicationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0233conducting-network-penetration-testB · 49Conducts comprehensive network penetration tests against authorizedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0234conducting-pass-the-ticket-attackC · 0Pass-the-Ticket (PtT) is a lateral movement technique that uses stolenmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0235conducting-post-incident-lessons-learnedS · 100Facilitate structured post-incident reviews to identify root causes,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0236conducting-wireless-network-penetration-testC · 6Conducts authorized wireless network penetration tests to assess themukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0237configuring-active-directory-tiered-modelB · 49Implement Microsoft's Enhanced Security Admin Environment (ESAE) tieredmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0238configuring-aws-verified-access-for-ztnaB · 41Configure AWS Verified Access to provide VPN-less zero trust networkmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0239configuring-certificate-authority-with-opensslA+ · 95A Certificate Authority (CA) is the trust anchor in a PKI hierarchy,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0240configuring-host-based-intrusion-detectionB · 44Configures host-based intrusion detection systems (HIDS) to monitormukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0241configuring-hsm-for-key-storageB · 41Hardware Security Modules (HSMs) are tamper-resistant physical devicesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0242configuring-microsegmentation-for-zero-trustB · 49Configure microsegmentation policies to enforce least-privilege workload-to-workloadmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0243configuring-multi-factor-authentication-with-duoC · 0Deploy Cisco Duo multi-factor authentication across enterprise applications,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0244configuring-network-segmentation-with-vlansA · 79Designs and implements VLAN-based network segmentation on managed switchesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0245configuring-pfsense-firewall-rulesB · 49Configures pfSense firewall rules, NAT policies, VPN tunnels, and trafficmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0246configuring-snort-ids-for-intrusion-detectionB- · 25Installs, configures, and tunes Snort 3 intrusion detection system tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0247configuring-suricata-for-network-monitoringS · 100Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0248configuring-tls-1-3-for-secure-communicationsC · 0TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Securitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0249configuring-windows-defender-advanced-settingsS · 100Configures Microsoft Defender for Endpoint (MDE) advanced protectionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0250configuring-windows-event-logging-for-detectionA- · 72Configures Windows Event Logging with advanced audit policies to generatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0251configuring-zscaler-private-access-for-ztnaB- · 37Configuring Zscaler Private Access (ZPA) to replace traditional VPNmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0252containing-active-breachC · 2Executes containment strategies to stop active adversary operationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0253continuous-llm-red-teaming-with-promptfooB- · 37Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0254correlating-security-events-in-qradarA- · 65Correlates security events in IBM QRadar SIEM using AQL (Ariel Querymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0255correlating-threat-campaignsB · 47Correlates disparate security incidents, IOCs, and adversary behaviorsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0256defending-llms-with-guardrailsB · 46Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0257deobfuscating-javascript-malwareA- · 70Deobfuscates malicious JavaScript code used in web-based attacks, phishingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0258deobfuscating-powershell-obfuscated-malwareB · 49Systematically deobfuscate multi-layer PowerShell malware using AST analysis,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0259deploying-active-directory-honeytokensA · 79Deploys deception-based honeytokens in Active Directory including fakemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0260deploying-cloud-deception-with-decoy-resourcesS · 100>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0261deploying-cloudflare-access-for-zero-trustA- · 66Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trustmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0262deploying-edr-agent-with-crowdstrikeC+ · 13Deploys and configures CrowdStrike Falcon EDR agents across enterprisemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0263deploying-honeytokens-and-canarytokensC · 0Plant canarytokens and honey credentials and alert on breach.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0264deploying-osquery-for-endpoint-monitoringC · 0Deploys and configures osquery for real-time endpoint monitoring usingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0265deploying-palo-alto-prisma-access-zero-trustB- · 35Deploying Palo Alto Networks Prisma Access for SASE-based zero trustmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0266deploying-software-defined-perimeterC+ · 20Deploy a Software-Defined Perimeter using the CSA v2.0 specificationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0267deploying-tailscale-for-zero-trust-vpnC · 0Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPNmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0268designing-adversary-engagement-with-mitre-engageS · 100>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0269detecting-ai-model-prompt-injection-attacksB · 49Detects prompt injection attacks targeting LLM-based applications usingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0270detecting-anomalies-in-industrial-control-systemsC · 0This skill covers deploying anomaly detection systems for industrialmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0271detecting-api-enumeration-attacksB- · 34Detect and prevent API enumeration attacks including BOLA and IDOR exploitationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0272detecting-arp-poisoning-in-network-trafficB+ · 56Detect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0273detecting-attacks-on-historian-serversA- · 63Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0274detecting-attacks-on-scada-systemsB · 49This skill covers detecting cyber attacks targeting Supervisory Controlmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0275detecting-aws-guardduty-findings-automationA+ · 96Automate AWS GuardDuty threat detection findings processing using EventBridgemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0276detecting-aws-iam-privilege-escalationS · 100Detect AWS IAM privilege escalation paths using boto3 and Cloudsplainingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0277detecting-azure-lateral-movementB · 44Detect lateral movement in Azure AD/Entra ID environments using Microsoftmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0278detecting-azure-service-principal-abuseC · 0Detect and investigate Azure service principal abuse including privilegemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0279detecting-azure-storage-account-misconfigurationsA · 79Audit Azure Blob and ADLS storage accounts for public access exposure,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0280detecting-beaconing-patterns-with-zeekA- · 72Performs statistical analysis of Zeek conn.log connection intervalsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0281detecting-bluetooth-low-energy-attacksC · 5Detects and analyzes Bluetooth Low Energy (BLE) security attacks includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0282detecting-broken-object-property-level-authorizationB+ · 50Detect and test for OWASP API3:2023 Broken Object Property Level Authorizationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0283detecting-cloud-threats-with-guarddutyA · 79This skill teaches security teams how to deploy and operationalize Amazonmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0284detecting-command-and-control-over-dnsA+ · 90Detects command-and-control (C2) communications tunneled through DNSmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0285detecting-container-drift-at-runtimeA- · 72Detect unauthorized modifications to running containers by monitoringmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0286detecting-container-escape-attemptsC · 6Container escape is a critical attack technique where an adversary breaksmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0287detecting-container-escape-with-falco-rulesS · 100Detect container escape attempts in real-time using Falco runtime securitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0288detecting-container-runtime-threats-with-falcoS · 100Write and deploy Falco rules with the modern eBPF driver to detect container escape, namespace abuse, privileged mounts, and anomalous syscalls at runtime in Kubernetes and Docker.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0289detecting-data-and-model-poisoningB · 49Identify poisoned training data and backdoored models across the ML pipeline.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0290detecting-dcsync-attack-in-active-directoryS · 100Detect DCSync attacks where adversaries abuse Active Directory replicationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0291detecting-dependency-confusionB- · 32Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0292detecting-dll-sideloading-attacksS · 100Detect DLL side-loading attacks where adversaries place malicious DLLsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0293detecting-dnp3-protocol-anomaliesA- · 72Detect anomalies in DNP3 (Distributed Network Protocol 3) communicationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0294detecting-dns-exfiltration-with-dns-query-analysisA- · 72Detect data exfiltration through DNS tunneling by analyzing query entropy,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0295detecting-email-account-compromiseS · 100Detect compromised O365 and Google Workspace email accounts by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0296detecting-email-forwarding-rules-attackC · 0Detect malicious email forwarding rules created by adversaries to maintainmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0297detecting-entra-offensive-tools-in-graph-logsA- · 70Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0298detecting-evasion-techniques-in-endpoint-logsB- · 37Detects defense evasion techniques used by adversaries in endpoint logsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0299detecting-exfiltration-over-dns-with-zeekA · 79Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0300detecting-fileless-attacks-on-endpointsS · 100Detects fileless malware and in-memory attacks that execute entirelymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0301detecting-fileless-malware-techniquesA · 79Detects and analyzes fileless malware that operates entirely in memorymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0302detecting-golden-ticket-attacks-in-kerberos-logsA- · 72Detect Golden Ticket attacks in Active Directory by analyzing Kerberosmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0303detecting-golden-ticket-forgeryS · 100Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0304detecting-indirect-prompt-injectionA · 79Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0305detecting-insider-data-exfiltration-via-dlpS · 100Detects insider data exfiltration by analyzing DLP policy violations,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0306detecting-insider-threat-behaviorsS · 100Detect insider threat behavioral indicators including unusual data access,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0307detecting-insider-threat-with-uebaA · 79Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearchmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0308detecting-kerberoasting-attacksS · 100Detect Kerberoasting attacks by monitoring for anomalous Kerberos TGSmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0309detecting-lateral-movement-in-networkA · 79Identifies lateral movement techniques in enterprise networks by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0310detecting-lateral-movement-with-splunkA- · 72Detect adversary lateral movement across networks using Splunk SPL queriesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0311detecting-lateral-movement-with-zeekS · 99Detect lateral movement in network traffic using Zeek (formerly Bro)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0312detecting-living-off-the-land-attacksS · 99Detect abuse of legitimate Windows binaries (LOLBins) used for livingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0313detecting-living-off-the-land-with-lolbasA+ · 96Detect Living Off the Land Binaries (LOLBins/LOLBAS) abuse includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0314detecting-malicious-npm-packagesB- · 34Triage npm packages for install-script malware, exfiltration, and worming behavior.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0315detecting-malicious-scheduled-tasks-with-sysmonS · 100Detect malicious scheduled task creation and modification using Sysmonmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0316detecting-mimikatz-execution-patternsS · 100Detect Mimikatz execution through command-line patterns, LSASS accessmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0317detecting-misconfigured-azure-storageA · 79Detecting misconfigured Azure Storage accounts including publicly accessiblemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0318detecting-modbus-command-injection-attacksA+ · 96Detect command injection attacks against Modbus TCP/RTU protocol inmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0319detecting-modbus-protocol-anomaliesA · 79This skill covers detecting anomalies in Modbus/TCP and Modbus RTU communicationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0320detecting-model-extraction-attacksA+ · 96Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0321detecting-network-anomalies-with-zeekB+ · 60Deploys and configures Zeek (formerly Bro) network security monitormukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0322detecting-network-scanning-with-ids-signaturesA- · 72Detect network reconnaissance and port scanning using Suricata and Snortmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0323detecting-ntlm-relay-with-event-correlationA · 79Detect NTLM relay attacks through Windows Security Event correlationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0324detecting-pass-the-hash-attacksS · 100Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0325detecting-pass-the-ticket-attacksA · 79Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Eventmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0326detecting-port-scanning-with-fail2banB · 49Configures Fail2ban with custom filters and actions to detect port scanningmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0327detecting-privilege-escalation-attemptsS · 100Detect privilege escalation attempts including token manipulation, UACmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0328detecting-privilege-escalation-in-kubernetes-podsS · 100Detect and prevent privilege escalation in Kubernetes pods by monitoringmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0329detecting-process-hollowing-techniqueS · 100Detect process hollowing (T1055.012) by analyzing memory-mapped sections,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0330detecting-process-injection-techniquesA · 79Detects and analyzes process injection techniques used by malware includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0331detecting-rdp-brute-force-attacksS · 100Detect RDP brute force attacks by analyzing Windows Security Event Logsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0332detecting-rootkit-activityC+ · 24Detects rootkit presence on compromised systems by identifying hiddenmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0333detecting-s3-data-exfiltration-attemptsS · 100Detecting data exfiltration attempts from AWS S3 buckets by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0334detecting-secure-boot-bypassS · 100Detect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0335detecting-serverless-function-injectionC · 0Detects and prevents code injection attacks targeting serverless functionsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0336detecting-service-account-abuseS · 100Detect abuse of service accounts through anomalous interactive logons,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0337detecting-shadow-api-endpointsA- · 72Discover and inventory shadow API endpoints that operate outside documentedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0338detecting-shadow-it-cloud-usageS · 100Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0339detecting-sql-injection-via-waf-logsC+ · 24Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injectionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0340detecting-stuxnet-style-attacksB- · 37This skill covers detecting sophisticated cyber-physical attacks thatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0341detecting-supply-chain-attacks-in-ci-cdA · 76Scans GitHub Actions workflows and CI/CD pipeline configurations formukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0342detecting-suspicious-oauth-application-consentA · 76Detect risky OAuth application consent grants in Azure AD / Microsoftmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0343detecting-suspicious-powershell-executionS · 100Detect suspicious PowerShell execution patterns including encoded commands,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0344detecting-t1055-process-injection-with-sysmonS · 100Detect process injection techniques (T1055) including classic DLL injection,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0345detecting-t1548-abuse-elevation-control-mechanismB- · 25Detect abuse of elevation control mechanisms including UAC bypass, sudomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0346detecting-typosquatting-packagesB+ · 57Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0347detecting-typosquatting-packages-in-npm-pypiB+ · 59Detects typosquatting attacks in npm and PyPI package registries bymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0348detecting-wmi-persistenceS · 100Detect WMI event subscription persistence by analyzing Sysmon Event IDsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0349emulating-cloud-attacks-with-stratus-red-teamC · 6Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0350enumerating-cloud-with-cloudfoxS · 100Map AWS and Azure attack paths and find exploitable misconfigurations withmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0351eradicating-malware-from-infected-systemsC · 0Systematically remove malware, backdoors, and attacker persistence mechanismsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0352escaping-containers-to-hostC · 0Exploit privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during authorized container-security assessments.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0353evaluating-threat-intelligence-platformsB+ · 61Evaluates and selects Threat Intelligence Platform (TIP) products basedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0354executing-active-directory-attack-simulationC · 6Executes authorized attack simulations against Active Directory environmentsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0355executing-nist-rmf-authorization-to-operateA · 75>-mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0356executing-red-team-engagement-planningS · 99Red team engagement planning is the foundational phase that defines scope,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0357executing-red-team-exerciseC · 6Executes comprehensive red team exercises that simulate real-world adversarymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0358exploiting-active-directory-certificate-services-esc1B · 49Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0359exploiting-active-directory-with-bloodhoundB · 49BloodHound is a graph-based Active Directory reconnaissance tool thatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0360exploiting-adcs-with-certipyB- · 30Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0361exploiting-api-injection-vulnerabilitiesC · 0Tests APIs for injection vulnerabilities including SQL injection, NoSQLmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0362exploiting-aws-with-pacuC · 0Use Pacu modules for AWS privilege escalation, persistence, and backdooring.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0363exploiting-bgp-hijacking-vulnerabilitiesC · 0Analyzes and simulates BGP hijacking scenarios in authorized lab environmentsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0364exploiting-broken-function-level-authorizationB · 41Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0365exploiting-broken-link-hijackingB · 41Discover and exploit broken link hijacking vulnerabilities by identifyingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0366exploiting-constrained-delegation-abuseB · 49Exploit Kerberos Constrained Delegation misconfigurations in Active Directorymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0367exploiting-deeplink-vulnerabilitiesS · 100Tests and exploits deep link (URL scheme and App Link) vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0368exploiting-excessive-data-exposure-in-apiC · 0Tests APIs for excessive data exposure where endpoints return more datamukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0369exploiting-http-request-smugglingA · 76Detecting and exploiting HTTP request smuggling vulnerabilities causedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0370exploiting-idor-vulnerabilitiesB · 38Identifying and exploiting Insecure Direct Object Reference vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0371exploiting-insecure-data-storage-in-mobileC · 2Identifies and exploits insecure local data storage vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0372exploiting-insecure-deserializationC · 3Identifying and exploiting insecure deserialization vulnerabilities inmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0373exploiting-ipv6-vulnerabilitiesC+ · 18Identifies and exploits IPv6-specific vulnerabilities including SLAACmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0374exploiting-jwt-algorithm-confusion-attackB · 49Exploits JWT algorithm confusion vulnerabilities where the server''smukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0375exploiting-kerberoasting-with-impacketA · 83Perform Kerberoasting attacks using Impacket's GetUserSPNs to extractmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0376exploiting-mass-assignment-in-rest-apisC · 0Discover and exploit mass assignment vulnerabilities in REST APIs tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0377exploiting-ms17-010-eternalblue-vulnerabilityB · 49MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0378exploiting-nopac-cve-2021-42278-42287C · 5Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountNamemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0379exploiting-nosql-injection-vulnerabilitiesC · 0Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0380exploiting-oauth-misconfigurationC · 0Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0381exploiting-prototype-pollution-in-javascriptC · 3Detect and exploit JavaScript prototype pollution vulnerabilities onmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0382exploiting-race-condition-vulnerabilitiesC+ · 17Detect and exploit race condition vulnerabilities in web applicationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0383exploiting-server-side-request-forgeryC · 10Identifying and exploiting SSRF vulnerabilities to access internal services,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0384exploiting-smb-vulnerabilities-with-metasploitC · 6Identifies and exploits SMB protocol vulnerabilities using Metasploitmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0385exploiting-sql-injection-vulnerabilitiesC · 0Identifies and exploits SQL injection vulnerabilities in web applicationsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0386exploiting-sql-injection-with-sqlmapC · 0Detecting and exploiting SQL injection vulnerabilities using sqlmap tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0387exploiting-template-injection-vulnerabilitiesC · 11Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0388exploiting-type-juggling-vulnerabilitiesB- · 32Exploit PHP type juggling vulnerabilities caused by loose comparisonmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0389exploiting-vulnerabilities-with-metasploit-frameworkC · 10The Metasploit Framework is the world's most widely used penetrationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0390exploiting-websocket-vulnerabilitiesC · 0Testing WebSocket implementations for authentication bypass, cross-sitemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0391exploiting-zerologon-vulnerability-cve-2020-1472B · 49Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remotemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0392extracting-browser-history-artifactsC+ · 13Extract and analyze browser history, cookies, cache, downloads, and bookmarksmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0393extracting-config-from-agent-tesla-ratS · 100Extract embedded configuration from Agent Tesla RAT samples includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0394extracting-iocs-from-malware-samplesB- · 31Extracts indicators of compromise (IOCs) from malware samples includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0395extracting-memory-artifacts-with-rekallB · 49Uses Rekall memory forensics framework to analyze memory dumps for processmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0396extracting-windows-event-logs-artifactsB · 49Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0397fleet-hunting-with-velociraptorC+ · 24Deploy a Velociraptor server and agents and write VQL hunts across a fleet.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0398generating-and-analyzing-sbomsB · 49Produce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0399generating-forensic-timelines-with-hayabusaB · 49Produce Sigma-based EVTX timelines and summaries with Hayabusa.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0400generating-threat-intelligence-reportsC · 5Generates structured cyber threat intelligence reports at strategic,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0401hardening-docker-containers-for-productionS · 99Hardening Docker containers for production involves applying securitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0402hardening-docker-daemon-configurationC · 4Harden the Docker daemon by configuring daemon.json with user namespacemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0403hardening-linux-endpoint-with-cis-benchmarkS · 100Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0404hardening-windows-endpoint-with-cis-benchmarkA · 79Hardens Windows endpoints using CIS (Center for Internet Security) Benchmarkmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0405hunting-advanced-persistent-threatsA · 79Proactively hunts for Advanced Persistent Threat (APT) activity withinmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0406hunting-bootkits-in-efi-system-partitionA- · 72Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0407hunting-evtx-with-chainsawB · 49Perform rapid Sigma and keyword hunting across Windows event logs withmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0408hunting-for-anomalous-powershell-executionA- · 72Hunt for malicious PowerShell activity by analyzing Script Block Loggingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0409hunting-for-beaconing-with-frequency-analysisA · 76Identify command-and-control beaconing patterns in network traffic bymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0410hunting-for-cobalt-strike-beaconsS · 100Detect Cobalt Strike beacon network activity using default TLS certificatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0411hunting-for-command-and-control-beaconingS · 100Detect C2 beaconing patterns in network traffic using frequency analysis,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0412hunting-for-data-exfiltration-indicatorsS · 100Hunt for data exfiltration through network traffic analysis, detectingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0413hunting-for-data-staging-before-exfiltrationS · 100Detect data staging activity before exfiltration by monitoring for archivemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0414hunting-for-dcom-lateral-movementA+ · 98Hunt for DCOM-based lateral movement by detecting abuse of MMC20.Application,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0415hunting-for-dcsync-attacksB- · 37Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorizedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0416hunting-for-defense-evasion-via-timestompingS · 100Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATIONmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0417hunting-for-dns-based-persistenceA- · 73Hunt for DNS-based persistence mechanisms including DNS hijacking, danglingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0418hunting-for-dns-tunneling-with-zeekA · 79Detect DNS tunneling and data exfiltration by analyzing Zeek dns.logmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0419hunting-for-domain-fronting-c2-trafficA · 79Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host headermukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0420hunting-for-lateral-movement-via-wmiA- · 72Detect WMI-based lateral movement by analyzing Windows Event ID 4688mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0421hunting-for-living-off-the-cloud-techniquesS · 100Hunt for adversary abuse of legitimate cloud services for C2, data staging,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0422hunting-for-living-off-the-land-binariesS · 99Proactively hunt for adversary abuse of legitimate system binaries (LOLBins)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0423hunting-for-lolbins-execution-in-endpoint-logsA+ · 96Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) bymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0424hunting-for-ntlm-relay-attacksC+ · 24Detect NTLM relay attacks by analyzing Windows Event 4624 logon typemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0425hunting-for-persistence-mechanisms-in-windowsS · 100Systematically hunt for adversary persistence mechanisms across Windowsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0426hunting-for-persistence-via-wmi-subscriptionsS · 100Hunt for adversary persistence through Windows Management Instrumentationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0427hunting-for-process-injection-techniquesA- · 72Detect process injection techniques (T1055) including CreateRemoteThread,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0428hunting-for-registry-persistence-mechanismsB- · 37Hunt for registry-based persistence mechanisms including Run keys, Winlogonmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0429hunting-for-registry-run-key-persistenceS · 100Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0430hunting-for-scheduled-task-persistenceB- · 37Hunt for adversary persistence via Windows Scheduled Tasks by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0431hunting-for-shadow-copy-deletionS · 100Hunt for Volume Shadow Copy deletion activity that indicates ransomwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0432hunting-for-startup-folder-persistenceS · 100Detect T1547.001 startup folder persistence by monitoring Windows startupmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0433hunting-for-supply-chain-compromiseA · 76Hunt for supply chain compromise indicators including trojanized softwaremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0434hunting-for-suspicious-scheduled-tasksS · 100Hunt for adversary persistence and execution via Windows scheduled tasksmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0435hunting-for-t1098-account-manipulationS · 100Hunt for MITRE ATT&CK T1098 account manipulation including shadow adminmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0436hunting-for-unusual-network-connectionsS · 100Hunt for unusual network connections by analyzing outbound traffic patterns,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0437hunting-for-unusual-service-installationsS · 100Detect suspicious Windows service installations (MITRE ATT&CK T1543.003)mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0438hunting-for-webshell-activityA- · 72Hunt for web shell deployments on internet-facing servers by analyzingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0439hunting-saas-sso-token-abuseC · 0Detect SSO and OAuth token replay and SaaS lateral movement.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0440implementing-aes-encryption-for-data-at-restB · 41AES (Advanced Encryption Standard) is a symmetric block cipher standardizedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0441implementing-alert-fatigue-reductionC · 0Implements strategies to reduce SOC alert fatigue by tuning detectionmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0442implementing-api-abuse-detection-with-rate-limitingB · 49Implement API abuse detection using token bucket, sliding window, andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0443implementing-api-gateway-security-controlsB · 38Implements security controls at the API gateway layer including authenticationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0444implementing-api-key-security-controlsS · 100Implements secure API key generation, storage, rotation, and revocationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0445implementing-api-rate-limiting-and-throttlingC+ · 22Implements API rate limiting and throttling controls using token bucket,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0446implementing-api-schema-validation-securityA+ · 92Implement API schema validation using OpenAPI specifications and JSONmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0447implementing-api-security-posture-managementS · 100Implement API Security Posture Management to continuously discover, classify,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0448implementing-api-security-testing-with-42crunchS · 100Implement comprehensive API security testing using the 42Crunch platformmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0449implementing-api-threat-protection-with-apigeeS · 100Implement API threat protection using Google Apigee policies includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0450implementing-application-whitelisting-with-applockerS · 100Implements application whitelisting using Windows AppLocker to restrictmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0451implementing-aqua-security-for-container-scanningB- · 37Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0452implementing-attack-path-analysis-with-xm-cyberA · 79Deploy XM Cyber's continuous exposure management platform to map attackmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0453implementing-attack-surface-managementS · 99Implements external attack surface management (EASM) using Shodan, Censys,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0454implementing-aws-config-rules-for-complianceB- · 37Implementing AWS Config rules for continuous compliance monitoring ofmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0455implementing-aws-iam-permission-boundariesA+ · 95Configure IAM permission boundaries in AWS to delegate role creationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0456implementing-aws-macie-for-data-classificationA+ · 96Implement Amazon Macie to automatically discover, classify, and protectmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0457implementing-aws-nitro-enclave-securityA+ · 98Implements AWS Nitro Enclave-based confidential computing environmentsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0458implementing-aws-security-hubS · 100This skill covers deploying AWS Security Hub as a centralized cloudmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0459implementing-aws-security-hub-complianceS · 100Implementing AWS Security Hub to aggregate security findings acrossmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0460implementing-azure-defender-for-cloudB · 40Implementing Microsoft Defender for Cloud to enable cloud security posturemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0461implementing-beyondcorp-zero-trust-access-modelC · 0Implementing Google''s BeyondCorp zero trust access model to eliminatemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0462implementing-bgp-security-with-rpkiB- · 25Implement BGP route origin validation using RPKI with Route Origin Authorizations,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0463implementing-canary-tokens-for-network-intrusionC · 0Deploys DNS, HTTP, and AWS API key canary tokens across network infrastructuremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0464implementing-cisa-zero-trust-maturity-modelS · 99Implement the CISA Zero Trust Maturity Model v2.0 across the five pillarsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0465implementing-cloud-dlp-for-data-protectionA+ · 96Implementing Cloud Data Loss Prevention (DLP) using Amazon Macie, Azuremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0466implementing-cloud-security-posture-managementA · 79Implementing Cloud Security Posture Management (CSPM) to continuouslymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0467implementing-cloud-trail-log-analysisA- · 72Implementing AWS CloudTrail log analysis for security monitoring, threatmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0468implementing-cloud-vulnerability-posture-managementB- · 34Implement Cloud Security Posture Management using AWS Security Hub, Azuremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0469implementing-cloud-waf-rulesA- · 72This skill covers deploying and tuning Web Application Firewall rulesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0470implementing-cloud-workload-protectionS · 100Implements cloud workload protection using boto3 and google-cloud APIsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0471implementing-code-signing-for-artifactsB · 49This skill covers implementing code signing for build artifacts to ensuremukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0472implementing-conditional-access-policies-azure-adB · 44Configure Microsoft Entra ID (Azure AD) Conditional Access policies formukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0473implementing-conduit-security-for-ot-remote-accessS · 100Implement secure conduit architecture for OT remote access followingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0474implementing-container-image-minimal-base-with-distrolessA+ · 96Reduce container attack surface by building application images on Googlemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0475implementing-container-network-policies-with-calicoB · 41Enforce Kubernetes network segmentation using Calico CNI network policiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0476implementing-continuous-security-validation-with-basB · 47Deploy Breach and Attack Simulation tools to continuously validate securitymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0477implementing-data-loss-prevention-with-microsoft-purviewC+ · 13Implements data loss prevention policies using Microsoft Purview tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0478implementing-ddos-mitigation-with-cloudflareA · 76Configure Cloudflare DDoS protection with managed rulesets, rate limiting,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0479implementing-deception-based-detection-with-canarytokenB · 39Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-basedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0480implementing-device-posture-assessment-in-zero-trustC+ · 23Implementing device posture assessment as a zero trust access controlmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0481implementing-devsecops-security-scanningA · 79Integrates Static Application Security Testing (SAST), Dynamic Applicationmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0482implementing-diamond-model-analysisA · 75The Diamond Model of Intrusion Analysis provides a structured frameworkmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0483implementing-digital-signatures-with-ed25519A · 79Ed25519 is a high-performance digital signature algorithm using the Edwardsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0484implementing-disk-encryption-with-bitlockerS · 100Implements full disk encryption using Microsoft BitLocker on Windowsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0485implementing-dmarc-dkim-spf-email-securityA · 75SPF, DKIM, and DMARC form the three pillars of email authentication.mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0486implementing-dragos-platform-for-ot-monitoringB · 49Deploy and configure the Dragos Platform for OT network monitoring,mukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0487implementing-ebpf-security-monitoringC · 0Implements eBPF-based security monitoring using Cilium Tetragon formukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0488implementing-email-sandboxing-with-proofpointC · 0Email sandboxing detonates suspicious attachments and URLs in isolatedmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0489implementing-end-to-end-encryption-for-messagingA- · 72End-to-end encryption (E2EE) ensures that only the communicating partiesmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0490implementing-endpoint-detection-with-wazuhA- · 70Deploy and configure Wazuh SIEM/XDR for endpoint detection includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0491implementing-endpoint-dlp-controlsS · 100Implements endpoint Data Loss Prevention (DLP) controls to detect andmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0492implementing-envelope-encryption-with-aws-kmsS · 100Envelope encryption is a strategy where data is encrypted with a datamukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0493implementing-epss-score-for-vulnerability-prioritizationB- · 29Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritizemukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0494implementing-file-integrity-monitoring-with-aideB · 49Configure AIDE (Advanced Intrusion Detection Environment) for file integritymukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0495implementing-fuzz-testing-in-cicd-with-aflplusplusC · 8Integrate AFL++ coverage-guided fuzz testing into CI/CD pipelines tomukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0496implementing-gcp-binary-authorizationB · 49Implement GCP Binary Authorization to enforce deploy-time security controlsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0497implementing-gcp-organization-policy-constraintsS · 100Implement GCP Organization Policy constraints to enforce security guardrailsmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0498implementing-gcp-vpc-firewall-rulesS · 100Implementing and auditing GCP VPC firewall rules to enforce networkmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0499implementing-gdpr-data-protection-controlsS · 99The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU'smukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0500implementing-gdpr-data-subject-access-requestC+ · 24Automates GDPR Data Subject Access Request (DSAR) workflows includingmukul975/Anthropic-Cybersecurity-Skills · 0 installsmukul975/Anthropic-Cybersecurity-Skills0
Source repository