Video & Animation

analyzing-ransomware-payment-wallets

github.com

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-powershell-script-block-logging

github.com

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-powershell-empire-artifacts

github.com

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-prefetch-files-for-execution-history

github.com

Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-sbom-for-supply-chain-vulnerabilities

github.com

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-office365-audit-logs-for-compromise

github.com

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-ransomware-encryption-mechanisms

github.com

Analyzes encryption algorithms, key management, and file encryption

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-mft-for-deleted-file-recovery

github.com

Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-covert-channels-in-malware

github.com

Detect and analyze covert communication channels used by malware, including

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-packets-with-scapy

github.com

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-flow-data-with-netflow

github.com

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-traffic-for-incidents

github.com

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-memory-forensics-with-lime-and-volatility

github.com

Performs Linux memory acquisition using LiME (Linux Memory Extractor)

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-traffic-of-malware

github.com

Analyzes network traffic generated by malware during sandbox execution

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-network-traffic-with-wireshark

github.com

Captures and analyzes network packet data using Wireshark and tshark

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-malware-sandbox-evasion-techniques

github.com

Detect sandbox and VM evasion techniques in malware samples by analyzing

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-memory-dumps-with-volatility

github.com

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-outlook-pst-for-email-forensics

github.com

Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-indicators-of-compromise

github.com

Analyzes indicators of compromise (IOCs) including IP addresses, domains,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-ios-app-security-with-objection

github.com

>-

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-ethereum-smart-contract-vulnerabilities

github.com

Perform static and symbolic analysis of Solidity smart contracts using

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-golang-malware-with-ghidra

github.com

Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-malicious-pdf-with-peepdf

github.com

Perform static analysis of malicious PDF documents using peepdf, pdfid,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→

analyzing-malware-behavior-with-cuckoo-sandbox

github.com

Detonate malware samples in Cuckoo Sandbox to observe runtime behavior

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
스킬 보기→