github.com/mukul975/Anthropic-Cybersecurity-Skills
| Skill | Added | Review |
|---|---|---|
building-c2-infrastructure-with-sliver-framework skills/building-c2-infrastructure-with-sliver-framework/SKILL.md Deploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulation framework) with multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard), redirectors, domain fronting, and multi-operator support for authorized red-team operations. Use when standing up resilient C2 for a red-team engagement or generating beacon/session implants that must survive blue-team detection. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 54a7988 | |
building-c2-redirector-infrastructure skills/building-c2-redirector-infrastructure/SKILL.md Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC controls like domain fronting and UA/geo filtering. Use when standing up red-team C2 that must survive blue-team triage or ensuring only profile-matching implant traffic reaches the hidden team server. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-cloud-siem-with-sentinel skills/building-cloud-siem-with-sentinel/SKILL.md Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps response playbooks. Use when establishing a centralized SOC for multi-cloud environments, migrating from a legacy SIEM, or performing petabyte-scale threat hunting; not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-detection-rules-with-sigma skills/building-detection-rules-with-sigma/SKILL.md Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends. | 69 69 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-detection-rule-with-splunk-spl skills/building-detection-rule-with-splunk-spl/SKILL.md Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-devsecops-pipeline-with-gitlab-ci skills/building-devsecops-pipeline-with-gitlab-ci/SKILL.md Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security templates. Use when building a shift-left DevSecOps pipeline in GitLab, adding automated vulnerability scanning stages to .gitlab-ci.yml, or triaging scanner findings with GitLab Duo AI before deployment. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-identity-federation-with-saml-azure-ad skills/building-identity-federation-with-saml-azure-ad/SKILL.md Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID. | 69 69 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 54a7988 | |
building-identity-governance-lifecycle-process skills/building-identity-governance-lifecycle-process/SKILL.md Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance. | 64 64 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 54a7988 | |
building-incident-response-dashboard skills/building-incident-response-dashboard/SKILL.md Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-incident-response-playbook skills/building-incident-response-playbook/SKILL.md Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL. Use when creating or maturing an IR program, documenting response runbooks for a new incident type, or designing SOAR playbooks. | 64 64 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 54a7988 | |
building-incident-timeline-with-timesketch skills/building-incident-timeline-with-timesketch/SKILL.md Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation. Use when reconstructing the sequence of events during an incident investigation or when multiple analysts need to jointly tag, annotate, and search a shared DFIR timeline. | 60 60 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 54a7988 | |
building-ioc-defanging-and-sharing-pipeline skills/building-ioc-defanging-and-sharing-pipeline/SKILL.md Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains, emails), normalizes and deduplicates them, then produces defanged renderings for safe human reading alongside canonical STIX 2.1 bundles distributed via TAXII servers, MISP, or email reports. Use when preparing indicators of compromise for safe analyst sharing or automating threat intel distribution to TAXII/MISP feeds. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-ioc-enrichment-pipeline-with-opencti skills/building-ioc-enrichment-pipeline-with-opencti/SKILL.md Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and GreyNoise, correlate indicators with known actors/campaigns, and score them for analyst prioritization. Use when deploying OpenCTI or automating enrichment and confidence scoring of newly ingested indicators. | 65 65 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-malware-incident-communication-template skills/building-malware-incident-communication-template/SKILL.md Build structured communication templates for malware incidents (ransomware, wiper, trojan, worm), covering internal stakeholder notifications, executive briefings, technical advisories for IT teams, customer notifications, and regulatory disclosures, with severity-based escalation procedures. Use when drafting or standardizing incident communications and notification workflows for a malware outbreak. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-patch-tuesday-response-process skills/building-patch-tuesday-response-process/SKILL.md Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first. | 62 62 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-phishing-reporting-button-workflow skills/building-phishing-reporting-button-workflow/SKILL.md Implement a phishing report button (Microsoft 365 built-in Report button or third-party like KnowBe4/Cofense) in email clients with a SOAR-driven automated triage workflow that classifies reported emails, extracts IOCs, takes remediation actions, and gives feedback to reporters. Use when deploying user-reported phishing intake or automating triage of the resulting reporting mailbox. | 60 60 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-ransomware-playbook-with-cisa-framework skills/building-ransomware-playbook-with-cisa-framework/SKILL.md Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Use when creating or updating a ransomware playbook, running a CISA-aligned readiness assessment, or validating response steps during a tabletop exercise. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-red-team-c2-infrastructure-with-havoc skills/building-red-team-c2-infrastructure-with-havoc/SKILL.md Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure for authorized red team operations. Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary emulation engagement. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-role-mining-for-rbac-optimization skills/building-role-mining-for-rbac-optimization/SKILL.md Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis, to discover optimal RBAC roles from existing user-permission assignments, consolidating overlapping roles and enforcing least privilege. Use when an identity program needs to reduce role explosion or redesign its RBAC role set from access data. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-soc-escalation-matrix skills/building-soc-escalation-matrix/SKILL.md Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that combine business risk, asset criticality, and data sensitivity. Use when designing or revising how a SOC triages and escalates incidents across analyst tiers. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 |