Skip to content

Security & Compliance Skills

902 curated security and compliance skills for AI coding agents. Access control, vulnerability scanning, compliance audit - all license-verified.

Performing Malware Triage With Yara

Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-malware-triage-with-yara

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Memory Forensics With Volatility3

Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-memory-forensics-with-volatility3

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Memory Forensics With Volatility3 Plugins

Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-memory-forensics-with-volatility3-plugins

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Mobile App Certificate Pinning Bypass

Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-mobile-app-certificate-pinning-bypass

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Mobile Device Forensics With Cellebrite

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-mobile-device-forensics-with-cellebrite

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Network Forensics With Wireshark

Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-forensics-with-wireshark

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Network Packet Capture Analysis

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-packet-capture-analysis

#github#external#license-apache-2-0Security & Compliance

Performing Network Traffic Analysis With Tshark

Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-traffic-analysis-with-tshark

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Network Traffic Analysis With Zeek

Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-network-traffic-analysis-with-zeek

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Nist Csf Maturity Assessment

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-nist-csf-maturity-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing OAuth Scope Minimization Review

Performs OAuth 2.0 scope minimization review to identify over-permissioned third-party application integrations, excessive API scopes, unused token grants, and risky OAuth consent patterns across identity providers and SaaS platforms. Activates for requests involving OAuth scope audit, API permission review, third-party app risk assessment, or consent grant minimization.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-oauth-scope-minimization-review

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Oil Gas Cybersecurity Assessment

This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-oil-gas-cybersecurity-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Open Source Intelligence Gathering

Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-open-source-intelligence-gathering

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing OSINT with SpiderFoot

Automate OSINT collection using SpiderFoot REST API and CLI for target profiling, module-based reconnaissance,

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-osint-with-spiderfoot

#github#external#license-apache-2-0Security & Compliance

Performing Ot Network Security Assessment

This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infrastructure.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-network-security-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Ot Vulnerability Assessment With Claroty

This skill covers performing vulnerability assessments in OT environments using the Claroty xDome platform for comprehensive asset discovery, risk scoring, vulnerability correlation, and remediation prioritization. It addresses passive vulnerability identification through traffic analysis, active safe querying of OT devices, integration with CVE databases and ICS-CERT advisories, and risk-based prioritization that accounts for operational impact and compensating controls.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-vulnerability-assessment-with-claroty

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Ot Vulnerability Scanning Safely

Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ot-vulnerability-scanning-safely

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Packet Injection Attack

Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-packet-injection-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Paste Site Monitoring for Credentials

Monitor paste sites like Pastebin and GitHub Gists for leaked credentials, API keys, and sensitive data dumps

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-paste-site-monitoring-for-credentials

#github#external#license-apache-2-0Security & Compliance

Performing Phishing Simulation With Gophish

GoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-phishing-simulation-with-gophish

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Physical Intrusion Assessment

Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-physical-intrusion-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Plc Firmware Security Analysis

This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory corruption flaws, and undocumented debug interfaces. It addresses firmware extraction from common PLC platforms (Siemens S7, Allen-Bradley, Schneider Modicon), static analysis of firmware images, dynamic analysis in emulated environments, and comparison against known-good baselines to detect tampering.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-plc-firmware-security-analysis

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Post Quantum Cryptography Migration

Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-post-quantum-cryptography-migration

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Power Grid Cybersecurity Assessment

This skill covers conducting cybersecurity assessments of electric power grid infrastructure including generation facilities, transmission substations, distribution systems, and energy management system (EMS) control centers. It addresses NERC CIP compliance verification, substation automation security, IEC 61850 protocol analysis, synchrophasor (PMU) network security, and the unique threat landscape targeting power grid operations as demonstrated by Industroyer/CrashOverride and related attacks.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-power-grid-cybersecurity-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Privacy Impact Assessment

'Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices,

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privacy-impact-assessment

#github#external#license-apache-2-0Security & Compliance

Performing Privileged Account Access Review

Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privileged-account-access-review

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Privileged Account Discovery

Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privileged-account-discovery

#github#external#license-apache-2-0Security & Compliance

Performing Privilege Escalation Assessment

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privilege-escalation-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Privilege Escalation on Linux

Linux privilege escalation involves elevating from a low-privilege user account to root access on a compromised

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-privilege-escalation-on-linux

#github#external#license-apache-2-0Security & Compliance

Performing Purple Team Atomic Testing

Executes Atomic Red Team tests mapped to MITRE ATT&CK techniques, performs coverage gap analysis across the ATT&CK matrix, and runs detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines. Activates for requests involving purple team exercises, atomic test execution, ATT&CK coverage assessment, detection engineering validation, or adversary emulation testing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-purple-team-atomic-testing

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Purple Team Exercise

Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-purple-team-exercise

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Ransomware Response

Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening. Addresses ransom negotiation considerations, backup integrity verification, and regulatory notification requirements. Activates for requests involving ransomware response, ransomware recovery, crypto-ransomware, data encryption attack, ransom payment decision, or ransomware containment.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ransomware-response

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Ransomware Tabletop Exercise

Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ransomware-tabletop-exercise

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Red Team Operations with Covenant C2

Conduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-red-team-with-covenant

#github#external#license-apache-2-0Security & Compliance

Performing Red Team Phishing With Gophish

Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-red-team-phishing-with-gophish

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing S7comm Protocol Security Analysis

Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-s7comm-protocol-security-analysis

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Scada Hmi Security Assessment

Perform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-scada-hmi-security-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Sca Dependency Scanning With Snyk

This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-sca-dependency-scanning-with-snyk

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Second Order SQL Injection

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-second-order-sql-injection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Security Headers Audit

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-security-headers-audit

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Serverless Function Security Review

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-serverless-function-security-review

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Service Account Audit

Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-service-account-audit

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Service Account Credential Rotation

Automate credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-service-account-credential-rotation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Soap Web Service Security Testing

Perform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soap-web-service-security-testing

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Soc2 Type2 Audit Preparation

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soc2-type2-audit-preparation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Soc Tabletop Exercise

Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems. Use when organizations need to validate IR playbooks, train analysts, or meet compliance requirements for incident response testing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-soc-tabletop-exercise

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Sqlite Database Forensics

Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-sqlite-database-forensics

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing SSL Certificate Lifecycle Management

SSL/TLS certificate lifecycle management encompasses the full process of requesting, issuing, deploying, monitoring,

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-certificate-lifecycle-management

#github#external#license-apache-2-0Security & Compliance

Performing SSL Stripping Attack

Simulates SSL stripping attacks using sslstrip, Bettercap, and mitmproxy in authorized environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms that protect users from downgrade attacks on encrypted connections.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-stripping-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing SSL Tls Inspection Configuration

Configure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-tls-inspection-configuration

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing SSL Tls Security Assessment

Assess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssl-tls-security-assessment

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Ssrf Vulnerability Exploitation

Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure metadata APIs (169.254.169.254), internal port scanning via HTTP, URL scheme bypass techniques, and DNS rebinding detection.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-ssrf-vulnerability-exploitation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Static Malware Analysis With Pe Studio

Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-static-malware-analysis-with-pe-studio

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Steganography Detection

Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-steganography-detection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Subdomain Enumeration With Subfinder

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-subdomain-enumeration-with-subfinder

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Supply Chain Attack Simulation

Simulate and detect software supply chain attacks including typosquatting detection via Levenshtein distance, dependency confusion testing against private registries, package hash verification with pip, and known vulnerability scanning with pip-audit.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-supply-chain-attack-simulation

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Thick Client Application Penetration Test

Conduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-thick-client-application-penetration-test

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Emulation With Atomic Red Team

Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework. Loads test definitions from YAML atomics, runs attack simulations, and validates detection coverage. Use when testing SIEM detection rules, validating EDR coverage, or conducting purple team exercises.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-emulation-with-atomic-red-team

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Hunting With Elastic Siem

Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-hunting-with-elastic-siem

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Hunting With Yara Rules

Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-hunting-with-yara-rules

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Intelligence Sharing With Misp

Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-intelligence-sharing-with-misp

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Landscape Assessment For Sector

Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack vectors, and industry-specific vulnerabilities to inform organizational risk management.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-landscape-assessment-for-sector

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Threat Modeling With Owasp Threat Dragon

Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-threat-modeling-with-owasp-threat-dragon

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Timeline Reconstruction With Plaso

Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-timeline-reconstruction-with-plaso

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing User Behavior Analytics

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-user-behavior-analytics

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Vlan Hopping Attack

Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-vlan-hopping-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Vulnerability Scanning With Nessus

Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities, misconfigurations, default credentials, and missing patches across network infrastructure, servers, and applications. The scanner correlates findings with CVE databases and CVSS scores to produce prioritized remediation guidance. Activates for requests involving vulnerability scanning, Nessus assessment, patch compliance checking, or automated vulnerability detection.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-vulnerability-scanning-with-nessus

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Application Firewall Bypass

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-firewall-bypass

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Application Penetration Test

Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses Burp Suite as the primary interception proxy alongside manual testing techniques to find flaws that automated scanners miss. Activates for requests involving web app pentest, OWASP testing, application security assessment, or web vulnerability testing.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-penetration-test

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Application Scanning With Nikto

Nikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-scanning-with-nikto

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Application Vulnerability Triage

Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-application-vulnerability-triage

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Cache Deception Attack

Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers and origin servers to cache and retrieve sensitive authenticated content.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-cache-deception-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Web Cache Poisoning Attack

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-web-cache-poisoning-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Wifi Password Cracking With Aircrack

Captures WPA/WPA2 handshakes and performs offline password cracking using aircrack-ng, hashcat, and dictionary attacks during authorized wireless security assessments to evaluate passphrase strength and wireless network security posture.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wifi-password-cracking-with-aircrack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Windows Artifact Analysis With Eric Zimmerman Tools

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Wireless Network Penetration Test

Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3 keys, detecting rogue access points, and testing wireless segmentation using Aircrack-ng and related tools.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wireless-network-penetration-test

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Wireless Security Assessment With Kismet

Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak encryption, and unauthorized clients through passive RF monitoring.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-wireless-security-assessment-with-kismet

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Performing Yara Rule Development For Detection

Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral indicators in executable files while minimizing false positives.

by mukul975/Anthropic-Cybersecurity-Skills / skills/performing-yara-rule-development-for-detection

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Phi Deidentifier

Remove or mask PHI/PII from healthcare data using HIPAA Safe Harbor method. Use when creating test datasets, anonymizing for research, or preparing data for non-production environments.

by prshahbs/healthcare-claude-skills / .claude/skills/phi-deidentifier

#healthcare#hipaa#fhirSecurity & Compliance

Power BI Security and Row-Level Security Best Practices

Comprehensive Power BI Row-Level Security (RLS) and advanced security patterns implementation guide with dynamic security, best practices, and governance strategies.

by github/awesome-copilot / instructions/power-bi-security-rls-best-practices.instructions.md

#github-copilot#application#securitySecurity & Compliance

Prioritizing Vulnerabilities With Cvss Scoring

The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity. CVSS v4.0 (r

by mukul975/Anthropic-Cybersecurity-Skills / skills/prioritizing-vulnerabilities-with-cvss-scoring

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Privacy Data Security

Design and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations. Use when the user asks about privacy notices, the Safeguards Rule, identity theft prevention programs, breach notification obligations, vendor security due diligence, incident response planning, data classification, or state privacy law compliance. Also trigger when users mention 'customer data was exposed', 'do we need to notify clients of a breach', 'cybersecurity exam prep', 'cloud vendor risk assessment', 'encrypting client data', 'BYOD security policy', 'Red Flags Rule', 'NY DFS 500 requirements', or ask how to handle a cybersecurity incident.

by JoelLewis/finance_skills / plugins/compliance/skills/privacy-data-security

#finance#personal-finance#wealth-managementSecurity & Compliance

Privacy Policy

Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when creating a privacy policy, updating data protection documentation, or preparing for compliance.

by phuryn/pm-skills / pm-toolkit/skills/privacy-policy

#work-life#productivity#product-managementSecurity & Compliance

Probe

Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For dynamic security testing, pentesting, or runtime vulnerability validation. Complements Sentinel static analysis.

by simota/agent-skills / probe

#broad-capability#development#securitySecurity & Compliance

Processing Stix Taxii Feeds

Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native schemas and routing them to appropriate consuming systems. Use when onboarding new TAXII collection endpoints, automating bi-directional intelligence sharing with ISACs, or building pipeline validation for malformed STIX bundles. Activates for requests involving OASIS STIX, TAXII server configuration, MISP TAXII, or Cortex XSOAR feed integrations.

by mukul975/Anthropic-Cybersecurity-Skills / skills/processing-stix-taxii-feeds

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Profiling Threat Actor Groups

Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries. Activates for requests involving MITRE ATT&CK Groups, Mandiant APT profiles, CrowdStrike adversary naming, or sector-specific threat briefings.

by mukul975/Anthropic-Cybersecurity-Skills / skills/profiling-threat-actor-groups

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Prompt Guard

Meta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ TPR, <1% FPR. Fast (<2ms GPU). Multilingual (8 languages). Deploy with HuggingFace or batch processing for RAG security.

by Orchestra-Research/AI-Research-SKILLs / 07-safety-alignment/prompt-guard

#broad-capability#ai-research#machine-learningSecurity & Compliance

Protect MCP Setup

Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool execution, or compliance-ready evidence of agent actions.

by wshobson/agents / plugins/protect-mcp/skills/protect-mcp-setup

#broad-capability#engineering#agent-skillsSecurity & Compliance

Protocol Reverse Engineering

Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.

by wshobson/agents / plugins/reverse-engineering/skills/protocol-reverse-engineering

#broad-capability#engineering#agent-skillsSecurity & Compliance

Qms Audit Expert

ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external audits, or managing an audit program.

by alirezarezvani/claude-skills / ra-qm-team/skills/qms-audit-expert

#complianceSecurity & Compliance

Quality Manager Qms Iso13485

ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design, documentation control, internal auditing, CAPA management, and certification support. Use when working with medical device quality systems, preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or building audit preparation programs. Useful for quality management, audit preparation, regulatory compliance, medical device documentation, and corrective action workflows.

by alirezarezvani/claude-skills / ra-qm-team/skills/quality-manager-qms-iso13485

#complianceSecurity & Compliance

Reconciliation

Design and operate reconciliation processes across portfolio management, custodian, and clearing systems. Use when building a daily position, cash, or transaction reconciliation process, investigating discrepancies between internal records and custodian records, diagnosing recurring break patterns from corporate actions or pricing differences, setting tolerance thresholds for position, cash, or market value matching, implementing three-way reconciliation, designing break investigation workflows with aging and escalation, normalizing multi-custodian feeds from Schwab, Fidelity, or Pershing, reconciling cost basis or accrued income, or preparing for examinations on books and records accuracy.

by JoelLewis/finance_skills / plugins/client-operations/skills/reconciliation

#finance#personal-finance#wealth-managementSecurity & Compliance

Recovering Deleted Files With Photorec

Recover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine regardless of file system damage.

by mukul975/Anthropic-Cybersecurity-Skills / skills/recovering-deleted-files-with-photorec

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Recovering From Ransomware Attack

Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.

by mukul975/Anthropic-Cybersecurity-Skills / skills/recovering-from-ransomware-attack

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Remediating S3 Bucket Misconfiguration

This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda.

by mukul975/Anthropic-Cybersecurity-Skills / skills/remediating-s3-bucket-misconfiguration

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Repomix Safe Mixer

Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.

by daymade/claude-code-skills / repomix-safe-mixer

#broad-capability#research#documentsSecurity & Compliance

Researchers Security

Researches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subject involves cybersecurity incidents or threat actors.

by bitwize-music-studio/claude-ai-music-skills / skills/researchers-security

#broad-capability#music#audio-generationSecurity & Compliance

Reverse Engineering Android Malware With Jadx

Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-android-malware-with-jadx

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Reverse Engineering Dotnet Malware With Dnspy

Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-dotnet-malware-with-dnspy

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance

Reverse Engineering iOS App With Frida

Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.

by mukul975/Anthropic-Cybersecurity-Skills / skills/reverse-engineering-ios-app-with-frida

#mukul-cybersecurity-skills#security#cybersecuritySecurity & Compliance