Video & Animation
analyzing-lnk-file-and-jump-list-artifacts
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-linux-elf-malware
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-macro-malware-in-office-documents
Analyzes malicious VBA macros embedded in Microsoft Office documents
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-malicious-pdf-with-peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-indicators-of-compromise
Analyzes indicators of compromise (IOCs) including IP addresses, domains,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-ios-app-security-with-objection
>-
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-linux-audit-logs-for-intrusion
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-docker-container-forensics
Investigate compromised Docker containers by analyzing images, layers,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-email-headers-for-phishing-investigation
Parse and analyze email headers (Received chain, Return-Path, Message-ID)
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-ethereum-smart-contract-vulnerabilities
Perform static and symbolic analysis of Solidity smart contracts using
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-heap-spray-exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-kubernetes-audit-logs
>-
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-certificate-transparency-for-phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cobaltstrike-malleable-c2-profiles
Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-command-and-control-communication
Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cloud-storage-access-patterns
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cobalt-strike-beacon-configuration
Extract and analyze Cobalt Strike beacon configuration from PE files
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-azure-activity-logs-for-threats
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-bootkit-and-rootkit-samples
Analyzes bootkit and advanced rootkit malware infecting the Master
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-apt-group-with-mitre-navigator
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-browser-forensics-with-hindsight
Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-api-gateway-access-logs
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-android-malware-with-apktool
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills