Video & Animation

attacking-oauth-with-device-code-phishing

github.com

Run OAuth 2.0 device-code and illicit-consent phishing attacks against

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

auditing-kubernetes-cluster-rbac

github.com

Auditing Kubernetes cluster RBAC configurations to identify overly permissive

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-threat-intelligence-feeds

github.com

Analyzes structured and unstructured threat intelligence feeds to extract

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-windows-registry-for-artifacts

github.com

Extract and analyze Windows Registry hives with tools like RegRipper

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-windows-prefetch-with-python

github.com

Parse Windows Prefetch (.pf) files with the windowsprefetch Python

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-windows-amcache-artifacts

github.com

Parses the Windows Amcache.hve registry hive with Eric Zimmerman

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-web-server-logs-for-intrusion

github.com

Parse Apache and Nginx access logs to detect SQL injection attempts,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-windows-event-logs-in-splunk

github.com

Analyzes Windows Security, System, and Sysmon event logs in Splunk to

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-typosquatting-domains-with-dnstwist

github.com

Generate domain permutations with dnstwist and check DNS resolution

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-threat-landscape-with-misp

github.com

Query a MISP (Malware Information Sharing Platform) instance via PyMISP

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-tls-certificate-transparency-logs

github.com

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-uefi-bootkit-persistence

github.com

Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-supply-chain-malware-artifacts

github.com

Investigate supply chain attack artifacts including trojanized software

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-slack-space-and-file-system-artifacts

github.com

Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-threat-actor-ttps-with-mitre-attack

github.com

Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-security-logs-with-splunk

github.com

Leverages Splunk Enterprise Security and SPL (Search Processing Language)

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-windows-lnk-files-for-artifacts

github.com

Parse Windows LNK shortcut files to extract target paths, MAC timestamps,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-threat-actor-ttps-with-mitre-navigator

github.com

Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-usb-device-connection-history

github.com

Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs,

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-packed-malware-with-upx-unpacker

github.com

Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or when preparing a packed binary for disassembly in Ghidra or IDA.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-pdf-malware-with-pdfid

github.com

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-persistence-mechanisms-in-linux

github.com

Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-powershell-empire-artifacts

github.com

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→

analyzing-office365-audit-logs-for-compromise

github.com

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect

$ npx skills add mukul975/Anthropic-Cybersecurity-Skills
Ver habilidade→