Video & Animation
attacking-oauth-with-device-code-phishing
Run OAuth 2.0 device-code and illicit-consent phishing attacks against
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsauditing-kubernetes-cluster-rbac
Auditing Kubernetes cluster RBAC configurations to identify overly permissive
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-intelligence-feeds
Analyzes structured and unstructured threat intelligence feeds to extract
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-registry-for-artifacts
Extract and analyze Windows Registry hives with tools like RegRipper
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-prefetch-with-python
Parse Windows Prefetch (.pf) files with the windowsprefetch Python
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-amcache-artifacts
Parses the Windows Amcache.hve registry hive with Eric Zimmerman
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-web-server-logs-for-intrusion
Parse Apache and Nginx access logs to detect SQL injection attempts,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-event-logs-in-splunk
Analyzes Windows Security, System, and Sysmon event logs in Splunk to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-typosquatting-domains-with-dnstwist
Generate domain permutations with dnstwist and check DNS resolution
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-landscape-with-misp
Query a MISP (Malware Information Sharing Platform) instance via PyMISP
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-tls-certificate-transparency-logs
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-uefi-bootkit-persistence
Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-supply-chain-malware-artifacts
Investigate supply chain attack artifacts including trojanized software
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-slack-space-and-file-system-artifacts
Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-actor-ttps-with-mitre-attack
Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-security-logs-with-splunk
Leverages Splunk Enterprise Security and SPL (Search Processing Language)
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-windows-lnk-files-for-artifacts
Parse Windows LNK shortcut files to extract target paths, MAC timestamps,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-threat-actor-ttps-with-mitre-navigator
Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-usb-device-connection-history
Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs,
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-packed-malware-with-upx-unpacker
Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or when preparing a packed binary for disassembly in Ghidra or IDA.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-pdf-malware-with-pdfid
Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-persistence-mechanisms-in-linux
Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-powershell-empire-artifacts
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-office365-audit-logs-for-compromise
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills