Video & Animation

analyzing-linux-system-artifacts

github.com

Examine Linux system artifacts (auth logs, cron/systemd persistence,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-malware-family-relationships-with-malpedia

github.com

Query the Malpedia API to look up malware family aliases and naming

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-linux-elf-malware

github.com

Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-linux-audit-logs-for-intrusion

github.com

Uses the Linux Audit framework (auditd) with ausearch and aureport utilities

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-linux-kernel-rootkits

github.com

Detect kernel-level rootkits in Linux memory dumps using Volatility3

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-ios-app-security-with-objection

github.com

>-

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-email-headers-for-phishing-investigation

github.com

Parse and analyze email headers (Received chain, Return-Path, Message-ID)

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-ethereum-smart-contract-vulnerabilities

github.com

Perform static and symbolic analysis of Solidity smart contracts using

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-docker-container-forensics

github.com

Investigate compromised Docker containers by analyzing images, layers,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-kubernetes-audit-logs

github.com

>-

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-golang-malware-with-ghidra

github.com

Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-heap-spray-exploitation

github.com

Detect and analyze heap spray attacks in memory dumps using Volatility3

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-indicators-of-compromise

github.com

Analyzes indicators of compromise (IOCs) including IP addresses, domains,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-disk-image-with-autopsy

github.com

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-dns-logs-for-exfiltration

github.com

Analyzes DNS query logs to detect data exfiltration via DNS tunneling,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-command-and-control-communication

github.com

Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-cyber-kill-chain

github.com

Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-cobaltstrike-malleable-c2-profiles

github.com

Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-campaign-attribution-evidence

github.com

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-certificate-transparency-for-phishing

github.com

Monitor Certificate Transparency logs using crt.sh and Certstream to

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-cloud-storage-access-patterns

github.com

Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-cobalt-strike-beacon-configuration

github.com

Extract and analyze Cobalt Strike beacon configuration from PE files

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

analyzing-browser-forensics-with-hindsight

github.com

Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→

acquiring-disk-image-with-dd-and-dcfldd

github.com

Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Skill anzeigen→