Video & Animation
auditing-cloud-with-cis-benchmarks
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking remediation for continuous compliance. Use when conducting a cloud security audit, validating CIS benchmark compliance (CIS v5 AWS, v4 Azure, v4 GCP), or setting up continuous cloud compliance monitoring.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsauditing-azure-active-directory-configuration
Auditing Microsoft Entra ID (Azure Active Directory) configuration to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-prefetch-with-python
Parse Windows Prefetch (.pf) files with the windowsprefetch Python
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-lnk-files-for-artifacts
Parse Windows LNK shortcut files to extract target paths, MAC timestamps,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-registry-for-artifacts
Extract and analyze Windows Registry hives with tools like RegRipper
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-uefi-bootkit-persistence
Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-typosquatting-domains-with-dnstwist
Generate domain permutations with dnstwist and check DNS resolution
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-usb-device-connection-history
Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-amcache-artifacts
Parses the Windows Amcache.hve registry hive with Eric Zimmerman
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-web-server-logs-for-intrusion
Parse Apache and Nginx access logs to detect SQL injection attempts,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-landscape-with-misp
Query a MISP (Malware Information Sharing Platform) instance via PyMISP
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-tls-certificate-transparency-logs
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-actor-ttps-with-mitre-attack
Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-actor-ttps-with-mitre-navigator
Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-event-logs-in-splunk
Analyzes Windows Security, System, and Sysmon event logs in Splunk to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-intelligence-feeds
Analyzes structured and unstructured threat intelligence feeds to extract
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-security-logs-with-splunk
Leverages Splunk Enterprise Security and SPL (Search Processing Language)
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-slack-space-and-file-system-artifacts
Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-supply-chain-malware-artifacts
Investigate supply chain attack artifacts including trojanized software
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-outlook-pst-for-email-forensics
Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-mft-for-deleted-file-recovery
Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-memory-forensics-with-lime-and-volatility
Performs Linux memory acquisition using LiME (Linux Memory Extractor)
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-network-covert-channels-in-malware
Detect and analyze covert communication channels used by malware, including
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-malware-sandbox-evasion-techniques
Detect sandbox and VM evasion techniques in malware samples by analyzing
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills