Video & Animation
analyzing-android-malware-with-apktool
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-api-gateway-access-logs
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-command-and-control-communication
Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-apt-group-with-mitre-navigator
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsabusing-shadow-credentials-for-privesc
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsachieving-cmmc-level-2-compliance
>-
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsacquiring-disk-image-with-dd-and-dcfldd
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillsanalyzing-cyber-kill-chain
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
$ npx skills add mukul975/Anthropic-Cybersecurity-Skillssupply-chain-security
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
$ npx skills add zhaoxuya520/reverse-skillpwn-chain
|
$ npx skills add zhaoxuya520/reverse-skillradio-sdr
Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
$ npx skills add zhaoxuya520/reverse-skillthick-client
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
$ npx skills add zhaoxuya520/reverse-skillpentest-tools
|
$ npx skills add zhaoxuya520/reverse-skillthreat-hunting
Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
$ npx skills add zhaoxuya520/reverse-skillbilibili/ijkplayer
Android/iOS video player based on FFmpeg n3.4, with MediaCodec, VideoToolbox support.
$ npx skills add bilibili/ijkplayerprotocol-reverse
Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
$ npx skills add zhaoxuya520/reverse-skillot-ics
Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
$ npx skills add zhaoxuya520/reverse-skillthreat-intelligence
Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.
$ npx skills add zhaoxuya520/reverse-skillradare2
|
$ npx skills add zhaoxuya520/reverse-skillpatch-diff-exploit
|
$ npx skills add zhaoxuya520/reverse-skilljs-reverse
在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。
$ npx skills add zhaoxuya520/reverse-skillllm-security
Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.
$ npx skills add zhaoxuya520/reverse-skillidentity-federation
Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
$ npx skills add zhaoxuya520/reverse-skillmacos-reverse
Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
$ npx skills add zhaoxuya520/reverse-skill