github.com/mukul975/Anthropic-Cybersecurity-Skills
| Skill | Added | Review |
|---|---|---|
building-soc-metrics-and-kpi-tracking skills/building-soc-metrics-and-kpi-tracking/SKILL.md Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-soc-playbook-for-ransomware skills/building-soc-playbook-for-ransomware/SKILL.md Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques. | 65 65 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-super-timelines-with-plaso skills/building-super-timelines-with-plaso/SKILL.md Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch. Use when reconstructing the full sequence of events on a compromised or forensically imaged host during a DFIR investigation. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 54a7988 | |
building-threat-actor-profile-from-osint skills/building-threat-actor-profile-from-osint/SKILL.md Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools like Maltego and SpiderFoot, and producing structured dossiers of motivations, capabilities, infrastructure, and TTPs. Use when performing attribution or building an adversary dossier from open-source intelligence. | 66 66 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-threat-feed-aggregation-with-misp skills/building-threat-feed-aggregation-with-misp/SKILL.md Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms. Use when standing up centralized IOC management or wiring multi-source threat feeds into a SIEM. | 63 63 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-threat-hunt-hypothesis-framework skills/building-threat-hunt-hypothesis-framework/SKILL.md Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma) and documents findings in a standardized hunt report. Use when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-threat-intelligence-enrichment-in-splunk skills/building-threat-intelligence-enrichment-in-splunk/SKILL.md Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time. | 63 63 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 | |
building-threat-intelligence-feed-integration skills/building-threat-intelligence-feed-integration/SKILL.md Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 54a7988 |