github.com/mukul975/Anthropic-Cybersecurity-Skills
| Skill | Added | Review |
|---|---|---|
analyzing-typosquatting-domains-with-dnstwist skills/analyzing-typosquatting-domains-with-dnstwist/SKILL.md Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and brand impersonation domains registered against your organization. Use when asked to monitor for lookalike domains, investigate a phishing domain, or assess brand-impersonation risk. | 65 65 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-campaign-attribution-evidence skills/analyzing-campaign-attribution-evidence/SKILL.md Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level. | 66 66 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-disk-image-with-autopsy skills/analyzing-disk-image-with-autopsy/SKILL.md Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence. | 63 63 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 9429fe9 | |
analyzing-network-traffic-with-wireshark skills/analyzing-network-traffic-with-wireshark/SKILL.md Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments. | 58 58 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-windows-registry-for-artifacts skills/analyzing-windows-registry-for-artifacts/SKILL.md Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system compromise. Use when investigating registry-based persistence, reconstructing user or system activity, or performing DFIR triage on a Windows image. | 67 67 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-macro-malware-in-office-documents skills/analyzing-macro-malware-in-office-documents/SKILL.md Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination. | 68 68 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-threat-actor-ttps-with-mitre-navigator skills/analyzing-threat-actor-ttps-with-mitre-navigator/SKILL.md Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group's techniques, building Navigator coverage heatmaps, or assessing technique coverage gaps against a specific threat actor. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
analyzing-network-covert-channels-in-malware skills/analyzing-network-covert-channels-in-malware/SKILL.md Detect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, steganographic HTTP, and other protocol abuse used for C2 and data exfiltration. Use when investigating suspicious DNS/ICMP/HTTP traffic patterns, hunting for hidden C2 channels in network captures, or attributing exfiltration traffic to a known tunneling toolset. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
building-incident-response-dashboard skills/building-incident-response-dashboard/SKILL.md Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
analyzing-linux-audit-logs-for-intrusion skills/analyzing-linux-audit-logs-for-intrusion/SKILL.md Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux. | 74 74 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 9429fe9 | |
analyzing-mft-for-deleted-file-recovery skills/analyzing-mft-for-deleted-file-recovery/SKILL.md Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space. Use when recovering evidence of deleted files, reconstructing NTFS file-system timelines, or detecting anti-forensic timestomping during a Windows forensic examination. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
building-automated-malware-submission-pipeline skills/building-automated-malware-submission-pipeline/SKILL.md Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integration. Use when SOC teams need to scale malware analysis beyond manual sandbox submissions for high-volume alert triage. | 64 64 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 9429fe9 | |
analyzing-malicious-url-with-urlscan skills/analyzing-malicious-url-with-urlscan/SKILL.md URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat | 54 54 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 9429fe9 | |
analyzing-windows-event-logs-in-splunk skills/analyzing-windows-event-logs-in-splunk/SKILL.md Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
analyzing-network-packets-with-scapy skills/analyzing-network-packets-with-scapy/SKILL.md Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing. | 63 63 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-malware-behavior-with-cuckoo-sandbox skills/analyzing-malware-behavior-with-cuckoo-sandbox/SKILL.md Detonate malware samples in Cuckoo Sandbox to observe runtime behavior — process creation, file system and registry changes, network communications, and API calls — and generate behavioral reports for classification and IOC extraction. Use when a sample has passed static triage and needs dynamic/behavioral analysis, when mapping a full infection chain, or when building YARA/behavioral signatures from observed sandbox activity. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-command-and-control-communication skills/analyzing-command-and-control-communication/SKILL.md Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback domains, dead drops). Use after reverse engineering reveals network traffic needing protocol analysis or when building detection signatures for a framework like Cobalt Strike, Metasploit, or Sliver. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
analyzing-ransomware-encryption-mechanisms skills/analyzing-ransomware-encryption-mechanisms/SKILL.md Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
auditing-kubernetes-cluster-rbac skills/auditing-kubernetes-cluster-rbac/SKILL.md Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 9429fe9 | |
analyzing-memory-dumps-with-volatility skills/analyzing-memory-dumps-with-volatility/SKILL.md Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation. | 64 64 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 9429fe9 | |
analyzing-threat-landscape-with-misp skills/analyzing-threat-landscape-with-misp/SKILL.md Query a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdowns, threat actor galaxy clusters, and tag trends, and generate threat landscape reports with temporal trends. Use when asked to analyze threat intelligence data, summarize top threat actors or malware families, or produce a CTI landscape report from MISP events. | 63 63 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 9429fe9 | |
analyzing-certificate-transparency-for-phishing skills/analyzing-certificate-transparency-for-phishing/SKILL.md Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization. | 59 59 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 9429fe9 | |
acquiring-disk-image-with-dd-and-dcfldd skills/acquiring-disk-image-with-dd-and-dcfldd/SKILL.md Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis. | 68 68 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 9429fe9 |