Skip to content

Security & Compliance Skills

902 curated security and compliance skills for AI coding agents. Access control, vulnerability scanning, compliance audit - all license-verified.

Implementing Log Integrity With Blockchain

Build an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-log-integrity-with-blockchain

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Memory Protection With Dep Aslr

Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent memory corruption attacks. Use when hardening endpoints against buffer overflow exploits, ROP chains, and code injection. Activates for requests involving memory protection, exploit mitigation, DEP, ASLR, or CFG configuration.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-memory-protection-with-dep-aslr

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Microsegmentation With Guardicore

Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege communication between workloads across data centers and cloud.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-microsegmentation-with-guardicore

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Mimecast Targeted Attack Protection

Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-mimecast-targeted-attack-protection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Mitre Attack Coverage Mapping

Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-mitre-attack-coverage-mapping

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Mobile Application Management

Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-mobile-application-management

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing mTLS for Zero Trust Services

'Configures mutual TLS (mTLS) authentication between microservices using Python cryptography library for certificate

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-mtls-for-zero-trust-services

#github#external#license-apache-2-0Security & Compliance

Implementing Nerc Cip Compliance Controls

This skill covers implementing North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance controls for Bulk Electric System (BES) cyber systems. It addresses asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), supply chain risk management (CIP-013), and the 2025 updates including mandatory MFA for remote access and expanded low-impact asset requirements.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-nerc-cip-compliance-controls

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Access Control

Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configurations to enforce identity-based access policies, posture assessment, and automatic VLAN assignment for authorized devices.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-access-control

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Access Control With Cisco Ise

Deploy Cisco Identity Services Engine for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, and dynamic VLAN assignment for network access control.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-access-control-with-cisco-ise

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Deception With Honeypots

Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-deception-with-honeypots

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Intrusion Prevention With Suricata

Deploy and configure Suricata as a network intrusion prevention system with custom rules, Emerging Threats rulesets, and inline traffic inspection for real-time threat blocking.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-intrusion-prevention-with-suricata

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Policies For Kubernetes

Kubernetes NetworkPolicies provide pod-level network segmentation by defining ingress and egress rules that control traffic flow between pods, namespaces, and external endpoints. Combined with CNI plu

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-policies-for-kubernetes

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Segmentation For Ot

This skill covers implementing network segmentation in Operational Technology environments using VLANs, industrial firewalls, data diodes, and software-defined networking. It addresses the Purdue Model-based segmentation strategy, migration from flat networks to segmented architectures without disrupting operations, configuring OT-aware firewalls with industrial protocol deep packet inspection, and validating segmentation effectiveness through traffic analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-segmentation-for-ot

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Segmentation With Firewall Zones

Design and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-segmentation-with-firewall-zones

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Network Traffic Analysis with Arkime

Deploy and query Arkime (formerly Moloch) for full packet capture network traffic analysis. Uses the Arkime API

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-traffic-analysis-with-arkime

#github#external#license-apache-2-0Security & Compliance

Implementing Network Traffic Baselining

Build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-network-traffic-baselining

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Next Generation Firewall With Palo Alto

Configure and deploy Palo Alto Networks next-generation firewalls with App-ID, User-ID, zone-based policies, SSL decryption, and threat prevention profiles for enterprise network security.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-next-generation-firewall-with-palo-alto

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Opa Gatekeeper For Policy Enforcement

Enforce Kubernetes admission policies using OPA Gatekeeper with ConstraintTemplates, Rego rules, and the Gatekeeper policy library.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-opa-gatekeeper-for-policy-enforcement

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Ot Incident Response Playbook

Develop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-ot-incident-response-playbook

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Ot Network Traffic Analysis With Nozomi

Deploy Nozomi Networks Guardian sensors for passive OT network traffic analysis to achieve comprehensive asset visibility, real-time threat detection, and vulnerability assessment across industrial control systems without disrupting operations, leveraging behavioral anomaly detection and protocol-aware monitoring.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-ot-network-traffic-analysis-with-nozomi

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing PAM for Database Access

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-pam-for-database-access

#github#external#license-apache-2-0Security & Compliance

Implementing Passwordless Authentication With Fido2

Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentica

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-passwordless-authentication-with-fido2

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Passwordless Auth With Microsoft Entra

Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-passwordless-auth-with-microsoft-entra

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Patch Management For Ot Systems

This skill covers implementing a structured patch management program for OT/ICS environments where traditional IT patching approaches can cause process disruption or safety hazards. It addresses vendor compatibility testing, risk-based patch prioritization, staged deployment through test environments, maintenance window coordination, rollback procedures, and compensating controls when patches cannot be applied due to operational constraints or vendor restrictions.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-patch-management-for-ot-systems

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Patch Management Workflow

Patch management is the systematic process of identifying, testing, deploying, and verifying software updates to remediate vulnerabilities across an organization's IT infrastructure. An effective patc

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-patch-management-workflow

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Pci Dss Compliance Controls

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-pci-dss-compliance-controls

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Pod Security Admission Controller

Implement Kubernetes Pod Security Admission to enforce baseline and restricted security profiles at namespace level using built-in admission controller.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-pod-security-admission-controller

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Privileged Access Management With Cyberark

Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-privileged-access-management-with-cyberark

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Privileged Access Workstation

Design and implement Privileged Access Workstations (PAWs) with device hardening, just-in-time access, and integration with CyberArk or BeyondTrust for secure administrative operations.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-privileged-access-workstation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Privileged Session Monitoring

Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke logging, real-time monitoring, risk-based session analysis, and compliance audit trail generation. Activates for requests involving privileged session recording, PAM session monitoring, CyberArk PSM configuration, administrator activity monitoring, or compliance session auditing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-privileged-session-monitoring

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Proofpoint Email Security Gateway

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-proofpoint-email-security-gateway

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Purdue Model Network Segmentation

Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model to separate industrial control system networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise, enforcing strict traffic control between OT and IT domains.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-purdue-model-network-segmentation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Ransomware Backup Strategy

Designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing. Activates for requests involving ransomware backup planning, backup resilience, air-gapped backup design, or backup recovery point objective configuration.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-ransomware-backup-strategy

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Ransomware Kill Switch Detection

Detects and exploits ransomware kill switch mechanisms including mutex-based execution guards, domain-based kill switches, and registry-based termination checks. Implements proactive mutex vaccination and kill switch domain monitoring to prevent ransomware from executing. Activates for requests involving ransomware kill switch analysis, mutex vaccination, WannaCry-style domain kill switches, or malware execution guard detection.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-ransomware-kill-switch-detection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Rapid7 Insightvm For Scanning

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-rapid7-insightvm-for-scanning

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Rbac Hardening For Kubernetes

Harden Kubernetes Role-Based Access Control by implementing least-privilege policies, auditing role bindings, eliminating cluster-admin sprawl, and integrating external identity providers.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-rbac-hardening-for-kubernetes

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing RSA Key Pair Management

RSA (Rivest-Shamir-Adleman) is the most widely deployed asymmetric cryptographic algorithm, used for digital

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-rsa-key-pair-management

#github#external#license-apache-2-0Security & Compliance

Implementing Runtime Application Self Protection

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-runtime-application-self-protection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Runtime Security With Tetragon

Implement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-runtime-security-with-tetragon

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Saml Sso With Okta

Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-saml-sso-with-okta

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Scim Provisioning With Okta

Implement automated user provisioning and deprovisioning using SCIM 2.0 protocol with Okta as the identity provider.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-scim-provisioning-with-okta

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Secret Scanning With Gitleaks

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-secret-scanning-with-gitleaks

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Secrets Management With Vault

This skill covers deploying HashiCorp Vault for centralized secrets management across cloud environments, including dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes integration. It addresses eliminating hardcoded credentials from application code and CI/CD pipelines by implementing short-lived, automatically rotated secrets.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-secrets-management-with-vault

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Secrets Scanning In CI CD

Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-secrets-scanning-in-ci-cd

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Security Chaos Engineering

Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-security-chaos-engineering

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Security Information Sharing With Stix2

Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-security-information-sharing-with-stix2

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Security Monitoring With Datadog

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-security-monitoring-with-datadog

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Siem Correlation Rules For Apt

Write multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-siem-correlation-rules-for-apt

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Siem Use Cases For Detection

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. Use when SOC teams need to expand detection coverage, formalize use case lifecycle management, or build a detection library aligned to organizational threat profile.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-siem-use-cases-for-detection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Siem Use Case Tuning

Tune SIEM detection rules to reduce false positives by analyzing alert volumes, creating whitelists, adjusting thresholds, and measuring detection efficacy metrics in Splunk and Elastic

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-siem-use-case-tuning

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Sigstore For Software Signing

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic provenance for container images, binaries, and software artifacts. The practitioner configures OIDC-based identity binding, verifies signing events against the Rekor transparency log, and integrates signing workflows into CI/CD pipelines. Activates for requests involving software supply chain signing, keyless container signing, Sigstore deployment, or artifact provenance verification.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-sigstore-for-software-signing

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Soar Automation With Phantom

Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-soar-automation-with-phantom

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing SOAR Playbook for Phishing

Automate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-soar-playbook-for-phishing

#github#external#license-apache-2-0Security & Compliance

Implementing Soar Playbook With Palo Alto Xsoar

Implement automated incident response playbooks in Cortex XSOAR to orchestrate security workflows across SOC tools and reduce manual response time.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-soar-playbook-with-palo-alto-xsoar

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Stix Taxii Feed Integration

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are OASIS open standards for representing and transporting cyber threat intelligence.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-stix-taxii-feed-integration

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Supply Chain Security With In Toto

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-supply-chain-security-with-in-toto

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Syslog Centralization With Rsyslog

Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings for high-availability syslog infrastructure.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-syslog-centralization-with-rsyslog

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Taxii Server With Opentaxii

Deploy and configure an OpenTAXII server to share and consume STIX-formatted cyber threat intelligence using the TAXII 2.1 protocol for automated indicator exchange between organizations.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-taxii-server-with-opentaxii

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Threat Intelligence Lifecycle Management

Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-threat-intelligence-lifecycle-management

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Threat Modeling With Mitre Attack

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-threat-modeling-with-mitre-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Ticketing System For Incidents

Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-ticketing-system-for-incidents

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Usb Device Control Policy

Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-usb-device-control-policy

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Velociraptor For Ir Collection

Deploy and configure Velociraptor for scalable endpoint forensic artifact collection during incident response using VQL queries, hunts, and pre-built artifact packs across Windows, Linux, and macOS environments.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-velociraptor-for-ir-collection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Vulnerability Management With Greenbone

Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets, execute vulnerability scans, and parse scan reports via GMP protocol.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-vulnerability-management-with-greenbone

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Vulnerability Remediation Sla

Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities based on severity, asset criticality, and exploit availability. Effective SLA programs

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-vulnerability-remediation-sla

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Vulnerability Sla Breach Alerting

Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation workflows, and compliance reporting dashboards.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-vulnerability-sla-breach-alerting

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Web Application Logging With Modsecurity

Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-web-application-logging-with-modsecurity

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Knowledge Proof For Authentication

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identificati

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-knowledge-proof-for-authentication

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Standing Privilege with CyberArk

Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-standing-privilege-with-cyberark

#github#external#license-apache-2-0Security & Compliance

Implementing Zero Trust DNS With Nextdns

Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-dns-with-nextdns

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Trust For SaaS Applications

Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device compliance, and data protection for cloud-hosted services.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-for-saas-applications

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Trust In Cloud

This skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-in-cloud

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Trust Network Access

Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-network-access

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Trust Network Access With Zscaler

Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware access to private applications through the Zscaler Zero Trust Exchange.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-network-access-with-zscaler

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Implementing Zero Trust with BeyondCorp

Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-with-beyondcorp

#github#external#license-apache-2-0Security & Compliance

Implementing Zero Trust With Hashicorp Boundary

Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.

by mukul975/Anthropic-Cybersecurity-Skills / skills/implementing-zero-trust-with-hashicorp-boundary

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Integrating Dast With Owasp Zap In Pipeline

This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and establishing DAST quality gates in GitHub Actions and GitLab CI.

by mukul975/Anthropic-Cybersecurity-Skills / skills/integrating-dast-with-owasp-zap-in-pipeline

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Integrating Sast Into GitHub Actions Pipeline

This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected.

by mukul975/Anthropic-Cybersecurity-Skills / skills/integrating-sast-into-github-actions-pipeline

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Intercepting Mobile Traffic With Burpsuite

Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/intercepting-mobile-traffic-with-burpsuite

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Investigating Insider Threat Indicators

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

by mukul975/Anthropic-Cybersecurity-Skills / skills/investigating-insider-threat-indicators

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

by mukul975/Anthropic-Cybersecurity-Skills / skills/investigating-phishing-email-incident

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Investigating Ransomware Attack Artifacts

Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.

by mukul975/Anthropic-Cybersecurity-Skills / skills/investigating-ransomware-attack-artifacts

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Ip Clause Review

Review the IP clauses in an agreement — assignment, ownership, license grants, warranties, indemnities. Use when reviewing IP terms in employment, consulting, SOW, vendor, or licensing agreements, when asked to check the assignment language or license scope, or when an agreement with IP provisions is pasted or attached.

by anthropics/claude-for-legal / ip-legal/skills/ip-clause-review

#legal#contracts#ndaSecurity & Compliance

Iso 13485 Certification

Comprehensive toolkit for preparing ISO 13485 certification documentation for medical device Quality Management Systems. Use when users need help with ISO 13485 QMS documentation, including (1) conducting gap analysis of existing documentation, (2) creating Quality Manuals, (3) developing required procedures and work instructions, (4) preparing Medical Device Files, (5) understanding ISO 13485 requirements, or (6) identifying missing documentation for medical device certification. Also use when users mention medical device regulations, QMS certification, FDA QMSR, EU MDR, or need help with quality system documentation.

by foryourhealth111-pixel/Vibe-Skills / bundled/skills/iso-13485-certification

#broad-capability#creative#complianceSecurity & Compliance

K8s Security Policies

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.

by wshobson/agents / plugins/kubernetes-operations/skills/k8s-security-policies

#broad-capability#engineering#agent-skillsSecurity & Compliance

Kibana Audit

Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

by elastic/agent-skills / skills/kibana/kibana-audit

#elastic#elasticsearch#kibanaSecurity & Compliance

Legal Response

Generate a response to a common legal inquiry using configured templates, with built-in escalation checks for situations that shouldn't use a templated reply. Use when responding to data subject requests, litigation hold notices, vendor legal questions, NDA requests from business teams, or subpoenas.

by anthropics/knowledge-work-plugins / legal/skills/legal-response

#work-life#productivity#knowledge-workSecurity & Compliance

Legal Risk Assessment

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Use when evaluating contract risk, assessing deal exposure, classifying issues by severity, or determining whether a matter needs senior counsel or outside legal review.

by anthropics/knowledge-work-plugins / legal/skills/legal-risk-assessment

#work-life#productivity#knowledge-workSecurity & Compliance

Legal Super Skill

Comprehensive legal operations skill merging Perplexity Computer's 6 legal skills with Claude Code's writing, communications, and planning skills. Covers contract review, NDA triage, compliance (GDPR/CCPA), risk assessment, meeting briefings, canned responses, legal writing, internal communications, and structured planning. Use for contract analysis, NDA screening, compliance reviews, risk assessments, legal meeting prep, response drafting, or any legal operations work.

by get-zeked/legal-super-skill

#legal#contracts#ndaSecurity & Compliance

Llamaguard

Meta's 7-8B specialized moderation model for LLM input/output filtering. 6 safety categories - violence/hate, sexual content, weapons, substances, self-harm, criminal planning. 94-95% accuracy. Deploy with vLLM, HuggingFace, Sagemaker. Integrates with NeMo Guardrails.

by Orchestra-Research/AI-Research-SKILLs / 07-safety-alignment/llamaguard

#broad-capability#ai-research#machine-learningSecurity & Compliance

Ln 621 Security Boundary Auditor

Checks application security boundaries: secrets, injection, XSS, input validation, and sensitive env defaults. Use when auditing exploitable code paths.

by levnikolaevich/claude-code-skills / plugins/codebase-audit-suite/skills/ln-621-security-boundary-auditor

#agile-workflow#code-review#networkSecurity & Compliance

Ln 760 Security Setup

Sets up security scanning for secrets and dependency vulnerabilities. Use when adding security infrastructure to a project.

by levnikolaevich/claude-code-skills / plugins/project-bootstrap/skills/ln-760-security-setup

#agile-workflow#code-review#vulnerabilitySecurity & Compliance

Ln 761 Secret Scanner

Scans codebase for hardcoded secrets with severity classification and remediation guidance. Use when auditing a project for leaked credentials.

by levnikolaevich/claude-code-skills / plugins/project-bootstrap/skills/ln-761-secret-scanner

#agile-workflow#code-review#secretsSecurity & Compliance

Managing Cloud Identity With Okta

This skill covers implementing Okta as a centralized identity provider for cloud environments, configuring SSO integration with AWS, Azure, and GCP, deploying phishing- resistant MFA with Okta FastPass, managing lifecycle automation for user provisioning and deprovisioning, and enforcing adaptive access policies based on device posture and risk signals.

by mukul975/Anthropic-Cybersecurity-Skills / skills/managing-cloud-identity-with-okta

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Managing Intelligence Lifecycle

Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.

by mukul975/Anthropic-Cybersecurity-Skills / skills/managing-intelligence-lifecycle

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Mapping Mitre Attack Techniques

Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/mapping-mitre-attack-techniques

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

MCP Security Audit

Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP servers use pinned versions (not @latest) - Detecting unpinned dependencies in MCP server configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]

by github/awesome-copilot / skills/mcp-security-audit

#github-copilot#complianceSecurity & Compliance

Memory Forensics

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

by wshobson/agents / plugins/reverse-engineering/skills/memory-forensics

#broad-capability#engineering#agent-skillsSecurity & Compliance

Monitoring Darkweb Sources

Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.

by mukul975/Anthropic-Cybersecurity-Skills / skills/monitoring-darkweb-sources

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance