Video & Animation
analyzing-cyber-kill-chain
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-disk-image-with-autopsy
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-command-and-control-communication
Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-certificate-transparency-for-phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cloud-storage-access-patterns
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-campaign-attribution-evidence
Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cobalt-strike-beacon-configuration
Extract and analyze Cobalt Strike beacon configuration from PE files
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-browser-forensics-with-hindsight
Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-api-gateway-access-logs
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-apt-group-with-mitre-navigator
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-azure-activity-logs-for-threats
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-bootkit-and-rootkit-samples
Analyzes bootkit and advanced rootkit malware infecting the Master
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cobaltstrike-malleable-c2-profiles
Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsabusing-dpapi-for-credential-access
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillshuggingface/diffusers
Use before opening a PR, or whenever asked to self-review a diffusers contribution. Applies the same rubric as the `@claude` CI (checks the diff against references/review-rules.md, traces call paths for dead code). Reports findings grouped by severity, flagging what to fix before submitting (blocking issues + dead code) vs what to leave for the actual review. Report-only — does not edit files.
$ npx skills add huggingface/diffuserssupply-chain-security
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
$ npx skills add zhaoxuya520/reverse-skillradio-sdr
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
$ npx skills add zhaoxuya520/reverse-skillwifi-wireless
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
$ npx skills add zhaoxuya520/reverse-skillreverse-engineering
Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it when the vulnerability is already understood and the remaining task is exploitation; use pwn instead. Do not use it for pure web workflows, log or disk forensics, or standalone crypto problems unless reversing the implementation is the real blocker.
$ npx skills add zhaoxuya520/reverse-skillwindows-ad
Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.
$ npx skills add zhaoxuya520/reverse-skillpentest-tools
|
$ npx skills add zhaoxuya520/reverse-skillprotocol-reverse
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
$ npx skills add zhaoxuya520/reverse-skillthick-client
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
$ npx skills add zhaoxuya520/reverse-skillpatch-diff-exploit
|
$ npx skills add zhaoxuya520/reverse-skill